VulnFeed MCP Server
by infai-techio.github.infai-tech/vulnfeedv0.3.3
Scans dependency lockfiles for vulnerabilities, prioritizes them by EPSS exploit probability and recommends fix versions, with monitoring and alerting.
context tax
queued
security
queued
cold start
queued
freshness
Active14d ago
Install VulnFeed MCP server
Install in Claude Code
claude mcp add vulnfeed -e VULNFEED_API_KEY='<vulnfeed-api-key>' -- uvx vulnfeed-mcpInstall in Cursor
{
"mcpServers": {
"vulnfeed": {
"command": "uvx",
"args": [
"vulnfeed-mcp"
],
"env": {
"VULNFEED_API_KEY": "<vulnfeed-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"vulnfeed": {
"command": "uvx",
"args": [
"vulnfeed-mcp"
],
"env": {
"VULNFEED_API_KEY": "<vulnfeed-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"vulnfeed": {
"type": "stdio",
"command": "uvx",
"args": [
"vulnfeed-mcp"
],
"env": {
"VULNFEED_API_KEY": "<vulnfeed-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"vulnfeed": {
"command": "uvx",
"args": [
"vulnfeed-mcp"
],
"env": {
"VULNFEED_API_KEY": "<vulnfeed-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| VULNFEED_API_KEY | — | yes | Polar.sh license key for paid tier (optional — free tier works without it) |
Freshness
Active — last maintenance signal 14d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-25 · 14d ago · GitHub
Latest release
2026-05-27 · 5mo ago · GitHub · v0.3.1
Package published
no data · npm/PyPI
Registry entry updated
2026-05-28 · 5mo ago · official registry · v0.3.3
FAQ
›How do I install the VulnFeed MCP server in Claude Code?
Run: claude mcp add vulnfeed -e VULNFEED_API_KEY='<vulnfeed-api-key>' -- uvx vulnfeed-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does VulnFeed require an API key?
Yes. It expects VULNFEED_API_KEY, of which 1 is a secret.
›Can I use VulnFeed as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is VulnFeed in the official MCP registry?
Yes, as io.github.infai-tech/vulnfeed.
Alternatives to VulnFeed
Other monitoring & observability MCP servers.