io.github.andrasfe/vulnicheck
HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.
Own this server? Screen its description →
NVD_API_KEYAPI key for NIST National Vulnerability Database (increases rate limit from 5 to 50 requests per 30 seconds)
GITHUB_TOKENGitHub token for Advisory Database access (increases rate limit to 5000 requests per hour)
OPENAI_API_KEYOpenAI API key for LLM-based risk assessment in MCP passthrough operations
ANTHROPIC_API_KEYAnthropic API key for LLM-based risk assessment (alternative to OpenAI)
MCP_PORTPort for MCP HTTP server (default: 3000)
CACHE_TTLCache time-to-live in seconds for vulnerability data (default: 900)
VULNICHECK_HTTP_ONLYEnable HTTP-only mode with MCP client delegation (true/false, default: auto-detect)
87 keyless tools of live, verifiable data for AI: weather, hazards, space, CVEs. Ed25519-signed.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Draft cited RFP and security questionnaire answers from your knowledge base, with human review