Skip to content
mcp/skillhub

Vulnicheck MCP Server

by andrasfeio.github.andrasfe/vulnicheckv0.1.0

HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

11Dockerremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Stale8mo ago

Install Vulnicheck MCP server

No published package or hosted endpoint yet — see the repository README for build-from-source instructions.

Configuration

VariableRequiredSecretDescription
NVD_API_KEY—yesAPI key for NIST National Vulnerability Database (increases rate limit from 5 to 50 requests per 30 seconds)
GITHUB_TOKEN—yesGitHub token for Advisory Database access (increases rate limit to 5000 requests per hour)
OPENAI_API_KEY—yesOpenAI API key for LLM-based risk assessment in MCP passthrough operations
ANTHROPIC_API_KEY—yesAnthropic API key for LLM-based risk assessment (alternative to OpenAI)
MCP_PORT——Port for MCP HTTP server (default: 3000)
CACHE_TTL——Cache time-to-live in seconds for vulnerability data (default: 900)
VULNICHECK_HTTP_ONLY——Enable HTTP-only mode with MCP client delegation (true/false, default: auto-detect)

Freshness

Stale — last maintenance signal 8mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-02-22 · 8mo ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2025-09-19 · 13mo ago · official registry · v0.1.0

FAQ

›Does Vulnicheck require an API key?

Yes. It expects NVD_API_KEY, GITHUB_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, of which 4 are secrets.

›Can I use Vulnicheck as a remote (hosted) MCP server?

Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.

›Is Vulnicheck in the official MCP registry?

Yes, as io.github.andrasfe/vulnicheck.

Alternatives to Vulnicheck

Other security MCP servers.

View all