Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Search CVEs. Remediate vulnerabilities with AI agents. Sourced facts stay sourced, remediation stays bounded, and every plan carries verification, rollback, and stop conditions β the live site's contract, and this repo's.
security-recipes.ai is an Eleventy site for sourced CVE intelligence and evidence-gated vulnerability remediation that AI agents can consume without inheriting deployment or production authority.
The project is intentionally narrow:
It is not a scanner, ticketing system, SOAR platform, deployment tool, or custom security toolkit. Existing security tools should produce the findings; this site helps agents use the right remediation context and stop at the right time.
Start with the live CVE Database for an exact vulnerability or the AI Vulnerability Remediation Playbooks for the evidence-to-patch workflow. Agent-specific guides cover Codex, Claude Code, Cursor, GitHub Copilot, Devin, Shiba Studio, Hermes Desktop, and OpenClaw. The Visual Guide shows the complete path from source qualification and search discovery to a bounded plan, proof, rollback, and human review. For the distinct problem of securing an agent system's identities, tools, connectors, context, memory, runtime, and recovery controls, use AI Agent Security.


The complete catalog remains searchable, while public canonical CVE pages stay
limited to reviewed or evidence-qualified records. Those pages ship unique
search metadata, server-rendered core facts and affected-version evidence, one
remediation authority (stable reviewed guidance first, otherwise complete
source-linked AI enrichment), a short approval-gated AI implementation prompt,
canonical URLs, breadcrumbs, and Article/TechArticle structured data. The CVE database
describes the catalog as a Dataset; the remediation pillar exposes its visible
seven-step workflow as a HowTo. Year-partitioned CVE sitemaps contain only
indexable canonical routes, and the build fails when sitemap parity, canonical
ownership, crawl reachability, metadata limits, or same-origin links drift.
Indexability is also withheld from mass-templated recipe children. The 72
development code-hygiene recipes and 39 generated compliance-framework recipes
remain browsable from their canonical hubs with noindex,follow while they
share a common method. A bounded rendered-body similarity gate prevents a child
from re-entering sitemaps until its evidence, examples, and tests are materially
distinct. The hubs remain indexable and carry the shared discovery context.
After an SEO-bearing release, the public revision must match the merge commit before sitemap submission or URL inspection. The Caddy deployment guide documents the DNS-verified Search Console handoff, priority live-URL checks, sitemap submission, indexing requests, and query monitoring. Submission is a discovery hint; it does not guarantee indexing or a particular ranking.
The remediation pillar also records a public repository example for
CVE-2026-13149 in brace-expansion.
It ties the dependency-only change to the
reviewed pull request,
tests, advisory evidence, and recovery path while explicitly separating the
same PR's unrelated Fail2Ban work.
| CVE search to canonical record | CVE evidence to bounded agent plan |
|---|---|
![]() | ![]() |
| Proof and human review | Read-only MCP context |
![]() | ![]() |
AI coding agents can help close security findings when their work is bounded: one finding, one recipe, one reviewed output.
security-recipes.ai helps teams answer:
stable Markdown pages override
that conservative baseline.noindex,follow until differentiated.noindex,follow while their bodies share a
generated template.mcp_server.py for recipe search,
retrieval, and opt-in upstream MCP context.No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/security-recipes)<a href="https://allmcps.com/mcp/security-recipes"><img src="https://allmcps.com/api/badge/security-recipes?style=directory" alt="Security Recipes on AllMCPs" /></a>