CVE Risk Check
app.openkrillv1.0.0Updated Oct 3, 2026
Triage a CVE: how severe it is, whether it is exploited, and how likely exploitation is.
Overview
AI-generated overview
Lets an assistant triage a CVE by severity, known exploitation, and likelihood of exploitation.
- What it does
- This remote MCP server provides CVE risk triage. Given a vulnerability identifier, it reports how severe the CVE is, whether it is already being exploited, and how likely exploitation is. The manifest lists no individual tools, so the exact tool names and inputs are not documented here.
- When to use it
- Useful when an assistant needs a quick risk read on a specific CVE during vulnerability review, patch prioritization, or security triage. It is a lightweight lookup rather than a full vulnerability management platform.
- Requirements
- A remote streamable HTTP endpoint at cve.openkrill.app. No authentication, environment variables, or headers are declared, and no local package or runtime is needed. Network access to the endpoint is required.
Before you install
The manifest declares no authentication, so requests to the endpoint are unauthenticated; avoid sending sensitive internal data in queries. CVE identifiers and any context you include are sent to a third-party service. The accuracy and freshness of severity and exploitation data depend on that service, so verify results against authoritative sources before acting.
Installation
In SourceWeft
- Open CVE Risk Check in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"cve": {
"type": "http",
"url": "https://cve.openkrill.app/mcp"
}
}
}Tools
0Tool metadata has not been indexed yet.
Version history
1- v1.0.0LatestOct 3, 2026

