npm @attestd/mcpstdioMITupdated 2mo ago
Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.
O que dá para fazer com attestd mcp?
@attestd/mcp
Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.
Official Model Context Protocol (MCP) server for Attestd. Exposes CVE risk and supply-chain checks as tools for Claude Code, Claude Desktop, and any MCP-compatible client.
Get a free API key · Full docs
- stdio transport: run via
npx -y @attestd/mcpwith no global install. check_package_vulnerability: wrapsGET /v1/checkusing@attestd/sdk.check_batch_vulnerabilities: checks up to 100 packages in one call. Use for lockfile and manifest audits.list_covered_products: returns Attestd-covered products. With an API key, returns live data fromGET /v1/products. Without a key, returns the static bundled infrastructure list.get_cve_details: returns CVSS, EPSS, KEV status, and affected products for a single CVE id.
Prerequisites
- Node.js 18+
- An Attestd API key from the portal. Required for
check_package_vulnerability,check_batch_vulnerabilities,get_cve_details, and livelist_covered_products.
Claude Code / MCP config
Add to ~/.claude/mcp.json or project .mcp.json:
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": ["-y", "@attestd/mcp"],
"env": {
"ATTESTD_API_KEY": "your-api-key-here"
}
}
}
}
Optional: override the API base URL (e.g. dev):
"env": {
"ATTESTD_API_KEY": "your-api-key-here",
"ATTESTD_BASE_URL": "https://dev.api.attestd.io"
}
Tools
check_package_vulnerability
| Argument | Type | Description |
|---|---|---|
product |
string | Product slug (nginx, postgresql, litellm, …) |
version |
string | Exact version (1.20.0) |
Returns JSON with:
| Field | Meaning |
|---|---|
outsideCoverage |
true if the product is not covered. Unknown risk, not safe. |
riskState |
critical | high | elevated | low | none | null when outside coverage |
activelyExploited |
CISA KEV signal |
remoteExploitable |
true if any matching CVE is remotely exploitable |
authenticationRequired |
true only when all matching CVEs require authentication |
patchAvailable / fixedVersion |
Patch guidance |
confidence |
Synthesis confidence 0.0–1.0 |
cveIds |
CVE IDs contributing to the risk assessment |
typosquat |
Package name integrity: typosquat or AI-hallucinated name (kind, resembles, likely_intended) |
message |
Explanation when outsideCoverage is true |
supplyChainCompromised / supplyChainDescription |
PyPI/npm supply-chain signal |
On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
check_batch_vulnerabilities
| Argument | Type | Description |
|---|---|---|
items |
array | Array of { product, version } objects. Maximum 100 per call. Each item costs one API call. |
Quota is checked upfront. If the batch would exceed your monthly quota, a 429 is returned before any calls are billed.
Returns JSON with count and results. Supported items include the same fields as check_package_vulnerability minus typosquat. Outside-coverage items return only product, version, outsideCoverage: true, and riskState: null.
list_covered_products
No arguments. With an API key, returns live JSON from GET /v1/products:
| Field | Meaning |
|---|---|
source |
"live" when fetched from the API |
total |
Combined count of CVE products and supply chain packages |
cveProducts |
CVE infrastructure slugs with display names |
supplyChainPackages |
Monitored PyPI/npm packages |
Without an API key, returns the static bundled list:
| Field | Meaning |
|---|---|
source |
"static" |
count |
Number of bundled infrastructure products |
products |
Array of { slug, display } entries |
get_cve_details
| Argument | Type | Description |
|---|---|---|
cve_id |
string | CVE identifier, e.g. CVE-2021-44228 |
Returns JSON with:
| Field | Meaning |
|---|---|
found |
true when the CVE is in Attestd's database; false on 404 (not an error) |
cveId |
CVE identifier |
description |
NVD description text |
cvssScore / cvssVector |
CVSS base score and vector |
activelyExploited |
CISA KEV signal |
remoteExploitable |
Remotely exploitable |
authenticationRequired |
Authentication required for exploitation |
affectedProducts |
Attestd product slugs affected by this CVE |
epssScore / epssPercentile |
EPSS probability and percentile |
sourcePublishedAt / lastCheckedAt |
ISO timestamps |
When the CVE is not found, returns { "found": false, "cveId": "..." } without isError. On invalid/missing API key or rate limit, returns isError: true with a JSON error string.
Verify locally
npm run build
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.js
License
MIT. See LICENSE.
Instalação
Adicione attestd mcp ao seu cliente. Escolha o que você usa.
claude mcp add mcp -- npx -y @attestd/mcpcodex mcp add mcp -- npx -y @attestd/mcpamp mcp add mcp -- npx -y @attestd/mcp{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"mcp","command":"npx","args":["-y","@attestd/mcp"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"mcp": {
"type": "local",
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"mcp": {
"command": {
"path": "npx",
"args": [
"-y",
"@attestd/mcp"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y @attestd/mcpRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
Pontuação
39 / 100
Incompleta
- Documentação25/25
- Manutenção16/25
- Confiança16/20
- Capacidade0/15
- Instalação12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 53 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Histórico de versões
| Versões | Publicada |
|---|---|
| 0.2.1Mais recente | 7 de jul. de 2026 |