Agent Tools / MCP install guides / CVE Risk Check in Claude

CVE Risk Check in Claude

CVE severity and exploit risk. The MCP server is https://cve.openkrill.app/mcp. No key. The steps below are only for Claude. A call to check_cve was checked against that server on 2026-10-01.

What this server answers

Triage a security vulnerability by its CVE id: how severe it is, whether it is being exploited, and how likely exploitation is.

Ask "how bad is CVE-2021-44228?", "which of these CVEs should I patch first?" or "what did CISA add to its exploited list this month?".

CVE Risk Check reads two free public sources. The National Vulnerability Database (NVD) gives the description, the CVSS score and severity, the publication date, a link to a patch or vendor advisory when one is tagged, and whether the CISA Known Exploited Vulnerabilities (KEV) catalog lists the CVE, with CISA's due date and required action. FIRST's EPSS gives the modelled probability that the CVE is exploited in the next 30 days.

Each CVE gets a priority: "exploited" when CISA lists it, "likely" when its EPSS score is 0.1 or more, otherwise "routine", or "unknown" when EPSS could not be read. A batch of up to 10 CVEs comes back sorted with the most urgent first.

Every answer names its sources and the date the NVD record and the EPSS score are from. NVD limits requests without a key, so records are cached for a few hours; a recent change to a CVE can take that long to appear, and when NVD asks this service to slow down the answer says so and when to retry.

It looks up CVE ids. It does not scan your systems, find which packages or versions are affected (use Package Health Check for that), confirm that you are vulnerable, or tell you how to exploit anything. The ids you ask about are not stored; the only lasting record is a daily count of calls per tool.

What it can do

Tools

Add CVE Risk Check in Claude

Claude connects to a remote MCP server as a custom connector. The connection is made from Anthropic's cloud, not from your laptop, so the server must be on the public internet. CVE Risk Check is. These steps were checked against Claude's custom-connector article (updated 2026-08-11) and the Claude Code MCP docs on 2026-10-01.

On a Pro or Max plan:

  1. Open Customize, then Connectors.
  2. Select the plus button, then Add custom connector.
  3. Paste https://cve.openkrill.app/mcp. Leave Advanced settings empty: this server does not need an OAuth client id or secret.
  4. Select Add. The connector is yours. Anthropic has not reviewed it, and it is not a Directory listing.
  5. In a conversation, open the plus button, then Connectors, and enable CVE Risk Check. Ask: How bad is CVE-2021-44228?

On Team and Enterprise, an Owner adds the connector first at Organization settings, then Connectors, then Add, then Custom, then Web, and pastes the same URL. Members then connect it from Customize. A Free plan can add one custom connector.

In Claude Code, add it from the project directory:

claude mcp add --transport http cve https://cve.openkrill.app/mcp

That writes a local or user config. A JSON entry needs "type": "http" (or streamable-http) plus the url. An entry with a url and no type is skipped. Confirm with claude mcp get cve. The tools you should see are check_cve, check_cves, list_recent_kev.

Enable the connector only in conversations that need it. Claude can call the tools while you work, including during research, so turn off any tool you do not want invoked. CVE Risk Check does not write to your accounts. It still receives the arguments of each call. Read the privacy page before you paste anything that is not public.

A call checked on 2026-10-01

CVE-2021-44228 is Log4Shell, listed by CISA, so priority, CVSS and KEV can be checked against the public record. The request below was posted to https://cve.openkrill.app/mcp as tools/call. HTTP 200. Source: the CVE Risk Check server, read 2026-10-01.

{
  "method": "tools/call",
  "params": {
    "name": "check_cve",
    "arguments": {
      "cve": "CVE-2021-44228"
    }
  }
}

Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.

Same server, other clients

Roles that use CVE Risk Check

Terms used on this page

Source: plugin listing for cve in this repository, and a live tools/call on 2026-10-01. As of 2026-10-01.