
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
security-mcp
Advanced tools
MCP server: zero-key cybersecurity toolkit. Audit any site's security, check if a CVE is actively exploited, look up attack techniques in plain English.
mcp-name: io.github.pratham-jain33/security-mcp
The zero-key cybersecurity toolkit for your AI assistant. No API keys, no signups, no configuration. Install it, ask Claude a security question, get an answer.
Three tools:
T1566 or a keyword like phishing; get what it is, how attackers use it, how to spot it, and how to defend. The technique data ships with the package, so this works fully offline.Defensive only. This server audits and explains; it does not scan ports, exploit anything, or do anything offensive.
Requires Python 3.10+.
uvx security-mcp
Or with pip:
pip install security-mcp
Claude Desktop config:
{
"mcpServers": {
"shield": {
"command": "uvx",
"args": ["security-mcp"]
}
}
}
audit_site fetches the site's homepage over HTTPS and reads its response headers, opens a TLS connection to inspect the certificate dates and issuer, and looks up SPF/DMARC/DKIM records over DNS (falling back to DNS-over-HTTPS where direct DNS is blocked). Each check carries a penalty; the penalties add up to a score, and the score maps to a grade. A failed certificate check fails the whole audit.
check_cve validates the CVE ID format, then asks two free public sources: the CISA KEV catalog (a JSON feed of vulnerabilities confirmed to be exploited in the wild, cached in memory for an hour) and the FIRST EPSS API (a 0–100% probability of exploitation in the next 30 days). The verdict combines both.
lookup_attack searches a compact bundle of the public MITRE ATT&CK catalog (697 techniques, trimmed from MITRE's CTI feed and shipped inside the package). ID lookups are exact; keyword searches rank name matches above description matches.
python -m venv .venv
.venv/bin/pip install -e . pytest
.venv/bin/python -m pytest tests/ -q # unit tests (mocked network)
SHIELD_LIVE=1 .venv/bin/python -m pytest tests/ -q -k live # real network smoke tests
MIT
FAQs
MCP server: zero-key cybersecurity toolkit. Audit any site's security, check if a CVE is actively exploited, look up attack techniques in plain English.
We found that security-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.