🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

vdb-mcp

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

vdb-mcp

MCP server for VDB — AI-aware vulnerability database (packages, MCP servers, models). Check packages for CVEs and slopsquatting before installing.

pipPyPI
Version
0.1.2
Weekly downloads
38
-89.97%
Maintainers
1
Weekly downloads
 

vdb-mcp

mcp-name: kr.ai.vdb/vdb

MCP (Model Context Protocol) server for VDB — the AI-aware vulnerability database. Lets Claude Desktop, Claude Code, Cursor, Cline, Continue, and any MCP client check packages while generating code: known CVEs, slopsquatting (LLM-hallucinated package names an attacker may have registered), CISA KEV status, MCP-server trust profiles, and more.

Quick start

uvx vdb-mcp          # or: pipx run vdb-mcp

Claude Desktop (claude_desktop_config.json) / Cursor (.cursor/mcp.json):

{
  "mcpServers": {
    "vdb": { "command": "uvx", "args": ["vdb-mcp"] }
  }
}

That's it — the server talks to the hosted instance at https://vdb.ai.kr by default. Anonymous use gets a free per-IP trial; add an API key for unmetered access (free at https://vdb.ai.kr/signup):

{
  "mcpServers": {
    "vdb": {
      "command": "uvx",
      "args": ["vdb-mcp"],
      "env": { "VDB_API_TOKEN": "vdb_..." }
    }
  }
}

Tools

ToolWhat it does
vdb_check_packageCheck one package (purl + optional version) for vulnerabilities, slop risk, KEV
vdb_check_packagesBulk slopsquatting / risk check for a list of packages
vdb_lookupFetch one advisory by ID (CVE-…, GHSA-…, VDB-SLOP-…)
vdb_searchFree-text search over the vulnerability corpus
vdb_check_mcp_serverTrust tier + permission scopes of a community MCP server
vdb_list_slopsquattingCurrent slopsquatting candidates per ecosystem

Environment

VariableDefaultMeaning
VDB_API_URLhttps://vdb.ai.krVDB instance to query (set for self-hosted)
VDB_API_TOKEN(empty)vdb_… API key — unmetered, per-account quota
MCP_MODEstdiostdio or sse (long-running HTTP server)
MCP_PORT7700SSE port

Why

LLMs hallucinate package names; attackers register them (slopsquatting). LLMs also happily recommend packages with known RCEs. VDB gives your agent a guardrail: one tool call before npm install / pip install. See https://vdb.ai.kr/connect for the one-line prompt variant that needs no MCP at all.

License

Elastic License 2.0 — free to use, including inside commercial organizations and CI. The only restrictions: you may not offer this software to third parties as a hosted or managed service, or resell it as a product. Commercial licensing beyond that: dev@egdee.com. API usage is governed by the VDB service terms regardless of how you call it.

Keywords

cve

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts