Vulnrable

com.vulnrablev1.0.0Updated Oct 7, 2026

Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.

VerifiedStreamable HTTPWeb executableSecurity & Monitoring

Overview

AI-generated overview

Provides security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS vulnerability data.

What it does
Vulnrable is a remote MCP server that supplies security grades for MCP servers and for npm and PyPI packages. According to its description, those grades are ranked using CISA KEV (Known Exploited Vulnerabilities) and EPSS (Exploit Prediction Scoring System) data. No individual tools are listed in the manifest, so the exact operations exposed to an assistant are not documented here.
When to use it
Consider it when an assistant needs to check or compare the security posture of an MCP server or a package before adopting it, for example during dependency review or vendor evaluation. It is less relevant if you only need general vulnerability scanning of your own code.
Requirements
It is a remote streamable HTTP endpoint at no local runtime, package, environment variables, or headers are declared. The manifest declares no authentication, so no credentials appear to be required. Network access to the endpoint is needed.
Before you install
The manifest declares no authentication, so requests to the endpoint are unauthenticated and anything sent to it leaves your machine. The server's own trustworthiness and the accuracy of its grades are not established by the input. No tools are listed, so what data it returns or records cannot be verified in advance.

Installation

In SourceWeft

  1. Open Vulnrable in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "vulnrable": {
      "type": "http",
      "url": "https://vulnrable.com/api/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 7, 2026