
EchelonGraph CVE & Exposure MCP Server
by echelongraphio.echelongraph/echelongraph-mcpv2.7.1
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.
context tax
queued
security
queued
cold start
queued
freshness
Active4d ago
Install EchelonGraph CVE & Exposure MCP server
Install in Claude Code
claude mcp add echelongraph -- npx -y echelongraph-mcpInstall in Cursor
{
"mcpServers": {
"echelongraph": {
"command": "npx",
"args": [
"-y",
"echelongraph-mcp"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"echelongraph": {
"command": "npx",
"args": [
"-y",
"echelongraph-mcp"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"echelongraph": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"echelongraph-mcp"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"echelongraph": {
"command": "npx",
"args": [
"-y",
"echelongraph-mcp"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ECHELONGRAPH_API_BASE | — | — | Override the API base URL (self-host or proxy). |
| ECHELONGRAPH_API_TIMEOUT_MS | — | — | Per-request timeout in milliseconds. A slower answer is reported as a failed lookup, not as empty data. |
Remote endpoints
- streamable-http
https://mcp.echelongraph.io/mcp
Freshness
Active — last maintenance signal 4d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-06 · 4d ago · GitHub
Latest release
2026-10-06 · 4d ago · GitHub · v2.7.1
Package published
no data · npm/PyPI
Registry entry updated
2026-10-06 · 4d ago · official registry · v2.7.1
FAQ
›How do I install the EchelonGraph CVE & Exposure MCP server in Claude Code?
Run: claude mcp add echelongraph -- npx -y echelongraph-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does EchelonGraph CVE & Exposure require an API key?
No required environment variables are declared in its published metadata.
›Can I use EchelonGraph CVE & Exposure as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is EchelonGraph CVE & Exposure in the official MCP registry?
Yes, as io.echelongraph/echelongraph-mcp.
Alternatives to EchelonGraph CVE & Exposure
Other security MCP servers.