
Government Contracts
io.github.martc03v1.0.0更新於 Oct 6, 2026
SAM.gov contracts and USAspending awards. 4 procurement tools.
概覽
讓助理查詢 SAM.gov 合約機會與 USAspending 聯邦支出獎項資料。
- 功能
- 提供四個採購相關工具,涵蓋 SAM.gov 合約資料與 USAspending 獎項紀錄。登錄描述指出它透過四個採購工具提供 SAM.gov 合約與 USAspending 獎項;清單中未列出個別工具名稱或參數。它以託管遠端端點方式運作,助理直接查詢,不必在本機啟動程序。
- 適用情境
- 適合助理需要尋找聯邦合約機會、查看獎項歷史,或在不離開對話的情況下研究政府採購與供應商支出時使用。
- 執行需求
- 需要連線至提供者託管的遠端 MCP 端點;清單未宣告任何套件、環境變數、標頭或身分驗證。需要網路連線。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Government Contracts,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"gov-contracts": {
"type": "http",
"url": "https://gov-contracts-mcp.apify.actor/mcp"
}
}
}README
Cybersecurity Vulnerability Intelligence MCP Server
Unified vulnerability intelligence from 4 government data sources in a single MCP server. Get enriched CVE lookups with CVSS scores, active exploitation status, exploitation probability, and ATT&CK techniques in one call.
Tools
vuln_lookup_cve — Enriched CVE Lookup
The killer feature. Look up any CVE and get intelligence from all 4 sources in a single call.
- Input:
{ cveId: "CVE-2021-44228" } - Returns: NVD details + CVSS score + KEV exploitation status + EPSS probability + ATT&CK techniques
vuln_search — Search CVEs
Search the NVD by keyword, severity, and date range. Optionally filter to only actively exploited (KEV) vulnerabilities.
- Input:
{ keyword: "apache log4j", severity: "CRITICAL", hasKev: true, limit: 20 }
vuln_kev_latest — Recently Exploited Vulnerabilities
Get vulnerabilities recently added to CISA's Known Exploited Vulnerabilities catalog.
- Input:
{ days: 7, limit: 20 }
vuln_kev_due_soon — Upcoming Remediation Deadlines
Get KEV entries with remediation deadlines approaching. Critical for federal compliance.
- Input:
{ days: 14, limit: 20 }
vuln_epss_top — Highest Exploitation Probability
Get CVEs most likely to be exploited in the next 30 days based on EPSS machine learning model.
- Input:
{ threshold: 0.7, limit: 20 }
vuln_trending — Newly Published Critical CVEs
Get recently published high/critical severity CVEs from the NVD.
- Input:
{ days: 3, severity: "CRITICAL", limit: 20 }
vuln_by_vendor — Vendor Vulnerability Assessment
Search CVEs for a specific vendor/product. Cross-references with CISA KEV to flag actively exploited issues.
- Input:
{ vendor: "microsoft", product: "windows", limit: 20 }
Use Cases
- Vulnerability triage: Look up a CVE and instantly know if it's actively exploited, its EPSS score, and what ATT&CK techniques apply
- Patch prioritization: Combine KEV status + EPSS scores to prioritize remediation
- Compliance tracking: Monitor upcoming CISA KEV remediation deadlines
- Threat intelligence: Track trending CVEs and newly weaponized vulnerabilities
- Vendor risk assessment: Assess a vendor's vulnerability exposure and active exploitation status
Quick Start
Glama (hosted)
Install from Glama.ai.
Apify (hosted)
Claude Desktop / Claude Code
Local (stdio)
Environment Variables
Caching
Architecture
- Protocol: MCP over stdio (Glama/local) or Streamable HTTP (Apify)
- Runtime: Node.js 18+, TypeScript
- Data: Direct API calls to free government data sources, zero cost
- Caching: In-memory with configurable TTLs
Other Servers in This Repo
This repository contains 13 MCP servers for US government data. See each server's README for details.
A REST API gateway with 45 endpoints is also available at govdata-api.netlify.app.
Attribution
- NVD: This product uses data from the NVD API but is not endorsed or certified by the NVD.
- EPSS: Data provided by FIRST.org (https://www.first.org/epss/).
- ATT&CK: Registered trademark of The MITRE Corporation. Licensed under Apache 2.0.
- KEV: CISA Known Exploited Vulnerabilities Catalog, US Government public domain.
Custom MCP Server Development
Need a custom MCP server for your business? Visit mcpdev.netlify.app or email [email protected].
License
MIT
來源:README.md,提交 26427e2
工具
0版本歷史
1- v1.0.0最新Sep 16, 2026


