Vulnfeed

Created By
infai-tech20 days ago
An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
Overview

Introduction

VulnFeed monitors your project's dependencies for security vulnerabilities — native to Claude Code.

What it does:

  • Reads your lockfile (package-lock.json, requirements.txt, go.sum, Cargo.lock, Gemfile.lock, composer.lock, yarn.lock, Pipfile.lock, pnpm-lock.yaml)
  • Queries NVD + GitHub Advisory Database for known CVEs
  • Enriches with EPSS (Exploit Prediction Scoring System) scores to filter noise
  • Recommends exact fix versions from package registries
  • Monitors projects continuously — get alerts when new CVEs drop

9 tools:

  • scan_project — auto-detect and scan all lockfiles in a directory
  • scan_lockfile — scan a specific lockfile
  • check_package — check a single package for vulns
  • lookup_cve — detailed CVE info with EPSS + fix versions
  • monitor_project — register for continuous monitoring
  • check_alerts — new vulns since last scan
  • update_deps — update snapshot after upgrading packages
  • list_monitored — see all monitored projects
  • unmonitor_project — remove from monitoring

Free tier: 10 scans/day, 1 monitored project. No signup required. Paid: $14/mo via Polar.sh. Unlimited scans + projects.

Homepage

https://vulnfeed.novadyne.ai

Purchase URL

https://buy.polar.sh/polar_cl_l2u7OfEs3L3NaMKsCQByy271MbERK5JO6ePqR0mRfBj

Transport

stdio (local install), SSE (remote)

Tool count

9

Supported ecosystems

npm, PyPI, Go, crates.io, RubyGems, Packagist (9 lockfile formats)

Server Config

{
  "mcpServers": {
    "vulnfeed": {
      "command": "uvx",
      "args": [
        "vulnfeed-mcp"
      ]
    }
  }
}
Project Info
Created At
20 days ago
Updated At
20 days ago
Author Name
infai-tech
Star
-
Language
-
License
-
Category

Recommend Servers

View All
Mnemom

a day ago
Trainzilla Mcp

2 hours ago