Back to Browse

Vulnfeed MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.

About

Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.

Security Report

4.2
Use Caution4.2High Risk

VulnFeed is a well-designed vulnerability scanning MCP server with appropriate permissions matching its purpose. Authentication is optional (free tier) or via API key (paid tier). The code is generally clean with proper input validation for file operations and network calls. However, there are minor security concerns: the WORKER_URL can be overridden via environment variables without validation, API keys are passed in Authorization headers (standard practice but worth noting), and some lockfile parsers use regex that could be more robust. The server's permissions (file_read, network_http, env_vars) align well with its stated purpose of scanning dependencies. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

5 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Polar.sh license key for paid tier (optional — free tier works without it)Required

Environment variable: VULNFEED_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-infai-tech-vulnfeed": {
      "env": {
        "VULNFEED_API_KEY": "your-vulnfeed-api-key-here"
      },
      "args": [
        "vulnfeed-mcp"
      ],
      "command": "uvx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!