Agent Tools / Roles / Security engineer

Security engineer

Two read-only servers cover the questions a security engineer asks before a patch meeting: how bad a CVE id is, and whether a named package release has a known advisory.

Tasks these servers can do

How bad is CVE-2021-44228?

Call check_cve on CVE Risk Check (https://cve.openkrill.app/mcp). A priority (exploited, likely, routine or unknown), the CVSS score, CISA Known Exploited Vulnerabilities status, the EPSS probability, and the as-of dates. It does not know which hosts you run.

Install steps: ChatGPT, Claude, Cursor, Pi.

Which of these CVE ids should I patch first?

Call check_cves on CVE Risk Check (https://cve.openkrill.app/mcp). Up to 10 ids, most urgent first, with a count per priority. An id the National Vulnerability Database could not be asked about is marked deferred, not safe.

Install steps: ChatGPT, Claude, Cursor, Pi.

Is lodash 4.17.15 vulnerable?

Call check_package on Package Health Check (https://packages.openkrill.app/mcp). Known advisories from OSV.dev for that npm or PyPI release, plus license, deprecation and the last release date. It does not scan your lockfile unless you paste a package.json into check_package_json.

Install steps: ChatGPT, Claude, Cursor, Pi.

What they will not do

Neither server scans a network, confirms that your build is affected, or gives exploit steps. Package names you send are public lookups. CVE ids are public lookups. For end-of-life dates of a runtime, use Dev Facts Check instead.

Where to start

Each link above is a client-specific install page with one call that was checked against the live server. The plain-text list of every server is llms.txt. The words MCP, tool and streamable HTTP are defined in the MCP glossary.

Source: the plugin listings linked above. As of 2026-10-01.