Metadata-Version: 2.4
Name: vuln-intel-mcp
Version: 0.1.0
Summary: Local MCP server for CVE remediation intelligence from public sources (NVD, CISA KEV, FIRST EPSS). Your model does the reasoning — no API keys, no external LLM calls, no data leaves your machine.
Project-URL: Homepage, https://clawofrohan.com/vuln-intel
Project-URL: Source, https://github.com/rohanrajnist/vuln-intel-mcp
Author: Rohan Raj
License-Expression: MIT
License-File: LICENSE
Keywords: cisa-kev,cve,epss,mcp,nvd,security,servicenow,threat-intelligence,vulnerability
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Security
Requires-Python: >=3.10
Requires-Dist: httpx>=0.27
Requires-Dist: mcp>=1.2.0
Description-Content-Type: text/markdown

# vuln-intel-mcp

A local **MCP server** that gives any AI agent — Claude Desktop, Claude Code, Cline, Cursor, or your own — CVE remediation intelligence from public sources: **NVD**, **CISA KEV**, and **FIRST EPSS**.

**Your model does the reasoning. This server does not.**

That is the whole point: the server only does the token-free work — fetching public vulnerability data over HTTP and computing an objective priority. It **never calls an LLM, needs no API key, and sends nothing anywhere except read-only requests to public vulnerability databases.** The remediation write-up and the ServiceNow note are produced by *your* model, in *your* session, from the structured facts the tools return. No one's API tokens are consumed but your own.

Built by [Rohan Raj](https://clawofrohan.com/vuln-intel). A hosted demo with AI synthesis and a live cost ledger runs at **clawofrohan.com/vuln-intel**.

---

## Install & connect

You need Python 3.10+. The easiest runner is [`uv`](https://docs.astral.sh/uv/) (`uvx` downloads and runs on demand — nothing to install permanently).

### Claude Code

```bash
claude mcp add vuln-intel -- uvx vuln-intel-mcp
```

### Claude Desktop

Edit `claude_desktop_config.json` (Settings → Developer → Edit Config):

```json
{
  "mcpServers": {
    "vuln-intel": {
      "command": "uvx",
      "args": ["vuln-intel-mcp"]
    }
  }
}
```

### Cline / Cursor / any MCP client

Same shape — command `uvx`, args `["vuln-intel-mcp"]`. Or if you installed it with `pip install vuln-intel-mcp`, use command `vuln-intel-mcp` with no args.

Restart the client, and ask it something like *"Should I patch CVE-2024-3400?"* or *"What's the exploit status of Log4Shell?"*

---

## Tools

| Tool | What it returns (token-free) | What your model does with it |
|------|------------------------------|------------------------------|
| `cve_lookup` | NVD facts, CVSS, CWEs, affected products, fix versions from CPE data, EPSS probability, CISA KEV status, and a computed **P1–P4** priority | Writes fix versions, remediation steps, workarounds, and a ServiceNow VR note |
| `cve_search` | Candidate CVEs for a free-form product/keyword query (NVD keyword search) | Picks the right CVE, then calls `cve_lookup` |
| `cve_exploit_intel` | Public exploit signals — KEV exploited/ransomware flags, EPSS score, and public GitHub repos referencing the CVE (often PoC/exploit code) | Judges weaponization and urgency |

---

## Optional environment variables

All optional — the server works with none. These raise **your own** public-API rate limits:

- `NVD_API_KEY` — a free [NVD API key](https://nvd.nist.gov/developers/request-an-api-key) for higher NVD throughput.
- `GITHUB_TOKEN` — a GitHub token for more GitHub repo searches in `cve_exploit_intel`.

---

## Privacy

- No telemetry. No account. No key required.
- Outbound requests go only to `services.nvd.nist.gov`, `api.first.org`, `cisa.gov`, and (for exploit intel) `api.github.com`.
- The CVE ids and search terms you look up are sent to those public services, exactly as if you visited them in a browser.

## License

MIT © Rohan Raj
