cve-cache
Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
Open source Open in the app JSON README (API)
About
Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
Details
- Kind
- MCP servers
- Topic
- Developer tools
- Publisher
- weiseer
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 0.1.1
- Last push
- 2026-06-01T09:28:33Z
- Repository state
- ativo
- Language
- JavaScript
- Added
- 2026-08-29 04:01:39
- Updated
- 2026-08-29 04:01:39
- Origin id
io.github.weiseer/cve-cache
README
# @weiseer/cve-cache-mcp
> Recent CVE + GHSA cache as a stdio MCP server.
Probe **P-005** by [weiseer](https://github.com/weiseer).
## What it does
Cached, structured snapshot of recent CVE + GitHub Security Advisory records — for AI agents auditing dependencies or screening new packages.
Your agent can:
- `lookup_cve` — full record for one CVE/GHSA ID
- `find_for_package` — all CVEs affecting a package by ecosystem (npm/PyPI/Cargo/Maven/Go)
- `list_recent_critical` — recent high-severity CVEs (default: 7-day, CVSS ≥ 7)
- `severity_summary` — counts by severity bucket
## Why use this instead of your agent querying NVD itself
| | Agent DIY | cve-cache |
|---|---|---|
| Source query | NVD JSON feeds + GHSA GraphQL | 1 MCP call |
| Token cost (NVD records are large) | $0.05-0.20 | $0 free / $0.00005 paid |
| Latency | 2-10 seconds | <100ms |
| Cross-ecosystem normalization | Per-source schema | Pre-normalized |
## Install
```bash
npm install -g @weiseer/cve-cache-mcp
```
## Use with Claude Desktop / Cursor / Cline / Continue / Windsurf
```json
{
"mcpServers": {
"cve-cache": {
"command": "npx",
"args": ["-y", "@weiseer/cve-cache-mcp"]
}
}
}
```
## License
Apache-2.0. Catalog data: derived from public CVE/NVD/GHSA feeds (CC0/public domain).