Security engineer
Two read-only servers cover the questions a security engineer asks before a patch meeting: how bad a CVE id is, and whether a named package release has a known advisory.
Tasks these servers can do
How bad is CVE-2021-44228?
Call check_cve on CVE Risk Check (https://cve.openkrill.app/mcp). A priority (exploited, likely, routine or unknown), the CVSS score, CISA Known Exploited Vulnerabilities status, the EPSS probability, and the as-of dates. It does not know which hosts you run.
Install steps: ChatGPT, Claude, Cursor, Pi.
Which of these CVE ids should I patch first?
Call check_cves on CVE Risk Check (https://cve.openkrill.app/mcp). Up to 10 ids, most urgent first, with a count per priority. An id the National Vulnerability Database could not be asked about is marked deferred, not safe.
Install steps: ChatGPT, Claude, Cursor, Pi.
Is lodash 4.17.15 vulnerable?
Call check_package on Package Health Check (https://packages.openkrill.app/mcp). Known advisories from OSV.dev for that npm or PyPI release, plus license, deprecation and the last release date. It does not scan your lockfile unless you paste a package.json into check_package_json.
Install steps: ChatGPT, Claude, Cursor, Pi.
What they will not do
Neither server scans a network, confirms that your build is affected, or gives exploit steps. Package names you send are public lookups. CVE ids are public lookups. For end-of-life dates of a runtime, use Dev Facts Check instead.
Where to start
Each link above is a client-specific install page with one call that was checked against the live server. The plain-text list of every server is llms.txt. The words MCP, tool and streamable HTTP are defined in the MCP glossary.