Vulnicheck MCP Server
by andrasfeio.github.andrasfe/vulnicheckv0.1.0
HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
context tax
queued
security
queued
cold start
queued
freshness
Stale8mo ago
Install Vulnicheck MCP server
No published package or hosted endpoint yet — see the repository README for build-from-source instructions.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| NVD_API_KEY | — | yes | API key for NIST National Vulnerability Database (increases rate limit from 5 to 50 requests per 30 seconds) |
| GITHUB_TOKEN | — | yes | GitHub token for Advisory Database access (increases rate limit to 5000 requests per hour) |
| OPENAI_API_KEY | — | yes | OpenAI API key for LLM-based risk assessment in MCP passthrough operations |
| ANTHROPIC_API_KEY | — | yes | Anthropic API key for LLM-based risk assessment (alternative to OpenAI) |
| MCP_PORT | — | — | Port for MCP HTTP server (default: 3000) |
| CACHE_TTL | — | — | Cache time-to-live in seconds for vulnerability data (default: 900) |
| VULNICHECK_HTTP_ONLY | — | — | Enable HTTP-only mode with MCP client delegation (true/false, default: auto-detect) |
Freshness
Stale — last maintenance signal 8mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-02-22 · 8mo ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2025-09-19 · 13mo ago · official registry · v0.1.0
FAQ
›Does Vulnicheck require an API key?
Yes. It expects NVD_API_KEY, GITHUB_TOKEN, OPENAI_API_KEY, ANTHROPIC_API_KEY, of which 4 are secrets.
›Can I use Vulnicheck as a remote (hosted) MCP server?
Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.
›Is Vulnicheck in the official MCP registry?
Yes, as io.github.andrasfe/vulnicheck.
Alternatives to Vulnicheck
Other security MCP servers.