The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Security Intel MCP listing page.
Vulnerability intelligence for AI agents — as MCP tools your agent can call mid-task. No API keys.
| Tool | What it does | Source |
|---|---|---|
cve_lookup | CVE summary: description, CVSS score & severity, CWE, references | NVD (NIST) |
package_vulnerabilities | Known vulnerabilities for a package/version | OSV.dev |
audit_dependencies | Audit a whole package.json (or dependency list) in one call | OSV.dev |
No API keys required for any tool.
Or point any MCP client at https://security.datakoot.com/mcp.
Paste this into a terminal:
You get the full NVD record for Log4Shell (CVE-2021-44228) — severity, CVSS vector, affected products — no API key, nothing to sign up for.
Or point any MCP client at the URL and just ask your agent, in plain language:
Vulnerability data comes from the National Vulnerability Database (NIST — US public domain) and OSV.dev (CC-BY 4.0), the same open source used by scanners like Trivy and Grype.
Part of Datakoot — keyless intelligence APIs for AI agents.