infai-tech/vulnfeed-mcp
by Various
Dependency vulnerability monitoring MCP server — knows your lockfile, prioritizes by EPSS, recommends fix versions.
MCP
infai-tech/vulnfeed-mcp
Added 8 June 2026
Overview
Vulnfeed MCP is a server that monitors dependency vulnerabilities by reading your lockfile. It prioritizes threats using EPSS scores and suggests fix versions. It integrates with MCP-compatible tools to surface actionable security data.
Best for
Best for
Developers who want automated, prioritized vulnerability alerts in their MCP workflow.
Use cases
- Scan lockfiles for known vulnerabilities during CI/CD
- Prioritize dependency fixes by EPSS exploit likelihood
- Get recommended upgrade versions for vulnerable packages
How to use
Install
uvx vulnfeed-mcp Tools exposed
scan_projectscan_lockfilecheck_packagelookup_cvemonitor_projectcheck_alertsupdate_depslist_monitoredunmonitor_project
Tested with
Claude Desktop, Claude Code
Notes
Vulnfeed MCP is a server that monitors dependency vulnerabilities by reading your lockfile. It prioritizes threats using EPSS scores and suggests fix versions. It integrates with MCP-compatible tools to surface actionable security data.
0 stars on GitHub. Last updated 2026-05-28. Licensed MIT.
Use cases
- Scan lockfiles for known vulnerabilities during CI/CD
- Prioritize dependency fixes by EPSS exploit likelihood
- Get recommended upgrade versions for vulnerable packages
Pros
- Uses EPSS scoring to focus on exploitable vulnerabilities
- Directly suggests fix versions, reducing manual research
- Lightweight Python server that works with MCP clients
Cons
- No stars or community traction yet, maturity unclear
- Requires MCP-compatible tooling to be useful
- Limited to lockfile-based scanning, no runtime monitoring
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- Uses EPSS scoring to focus on exploitable vulnerabilities
- Directly suggests fix versions, reducing manual research
- Lightweight Python server that works with MCP clients
Cons
- No stars or community traction yet, maturity unclear
- Requires MCP-compatible tooling to be useful
- Limited to lockfile-based scanning, no runtime monitoring
Pairs with
Other entries in the index that connect to this one. Click through to see the chain.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
