Vulnfeed

Created By
infai-tech19 days ago
An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
Overview

Introduction

VulnFeed monitors your project's dependencies for security vulnerabilities — native to Claude Code.

What it does:

  • Reads your lockfile (package-lock.json, requirements.txt, go.sum, Cargo.lock, Gemfile.lock, composer.lock, yarn.lock, Pipfile.lock, pnpm-lock.yaml)
  • Queries NVD + GitHub Advisory Database for known CVEs
  • Enriches with EPSS (Exploit Prediction Scoring System) scores to filter noise
  • Recommends exact fix versions from package registries
  • Monitors projects continuously — get alerts when new CVEs drop

9 tools:

  • scan_project — auto-detect and scan all lockfiles in a directory
  • scan_lockfile — scan a specific lockfile
  • check_package — check a single package for vulns
  • lookup_cve — detailed CVE info with EPSS + fix versions
  • monitor_project — register for continuous monitoring
  • check_alerts — new vulns since last scan
  • update_deps — update snapshot after upgrading packages
  • list_monitored — see all monitored projects
  • unmonitor_project — remove from monitoring

Free tier: 10 scans/day, 1 monitored project. No signup required. Paid: $14/mo via Polar.sh. Unlimited scans + projects.

Homepage

https://vulnfeed.novadyne.ai

Purchase URL

https://buy.polar.sh/polar_cl_l2u7OfEs3L3NaMKsCQByy271MbERK5JO6ePqR0mRfBj

Transport

stdio (local install), SSE (remote)

Tool count

9

Supported ecosystems

npm, PyPI, Go, crates.io, RubyGems, Packagist (9 lockfile formats)

Server Config

{
  "mcpServers": {
    "vulnfeed": {
      "command": "uvx",
      "args": [
        "vulnfeed-mcp"
      ]
    }
  }
}
Project Info
Created At
19 days ago
Updated At
19 days ago
Author Name
infai-tech
Star
-
Language
-
License
-
Category

Recommend Servers

View All
//beforeyouship — LLM Cost Modeling From Your Editor
@Indiegoing

Query realistic LLM cost models without leaving your editor. beforeyouship models the **true monthly cost** of an LLM app architecture — retries, prompt caching, batch discounts, infra overhead, and 3×/10× growth — across GPT-5.x, Claude, Gemini, DeepSeek, and more. Not a token calculator: a planning tool for the design phase, before you commit to a stack. **No API key needed to try it** — demo mode covers the six free-tier models. A Pro key from [beforeyouship.dev](https://beforeyouship.dev) unlocks the full 18-model catalog. ## What you can ask - "How much will a RAG chatbot cost at 10,000 requests/day?" - "Compare Claude Haiku vs Gemini Flash pricing for my workload" - "What's the cheapest model for a multi-step agent at scale?" - "Show me current per-token prices for Anthropic models" ## Tools ### `estimate_cost` Full cost model for an architecture at a given usage level. Returns Naive / Realistic / Worst Case monthly cost per model, 3×/10× growth scenarios, and an opinionated recommendation with reasoning. ### `get_model_prices` Current per-1M-token pricing — input, output, cached input, batch — with context windows and staleness metadata. ### `list_archetypes` Seven preset architecture patterns (simple chatbot, chatbot with history, RAG pipeline, multi-model router, coding assistant, document processor, multi-step agent) used as starting points for estimates. ## Setup **Claude Code:** ​```bash claude mcp add --transport http beforeyouship https://beforeyouship.dev/api/mcp ​``` **Cursor / other clients** — add a remote server: ​```json { "mcpServers": { "beforeyouship": { "type": "streamable-http", "url": "https://beforeyouship.dev/api/mcp" } } } ​``` Add an `Authorization: Bearer bys_...` header with a Pro key for the full catalog. ## Try it > Estimate the monthly cost of a RAG pipeline at 10,000 requests/day

10 hours ago