Security Intel MCP — by Datakoot
MCP serverSecurityFind out whether the software libraries in a project have known security flaws. Once added, your AI can look up reported vulnerabilities by CVE ID and audit a project's dependency manifest for reported issues. It works without any API keys.
Available today. Use it from your connected AI after setup.
No other account needed.
After adding it, share a CVE ID or your project's dependency file with your AI and ask it to check for known vulnerabilities.
Then ask your AI: use the cve lookup tool from Security Intel MCP
What your AI can do with it
- Look up the details of a known vulnerability using its CVE ID
- Audit a dependency manifest to find libraries with reported security issues
- Check a project's listed dependencies for known vulnerabilities before you rely on them
- Run these checks without setting up any API keys
Install Security Intel MCP — by Datakoot
The server’s own address, for the clients that take one directly. Or connect ahel onceand every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.
Claude Code
claude mcp add --transport http --scope user security-intel-mcp-by-datakoot 'https://security.datakoot.com/mcp'Run it once in your project, then open /mcp to approve any sign-in the server asks for.
Claude Desktop
https://security.datakoot.com/mcpAdd a custom connector in Settings, paste this address, and approve the sign-in.
Cursor
cursor://anysphere.cursor-deeplink/mcp/install?name=security-intel-mcp-by-datakoot&config=eyJ1cmwiOiJodHRwczovL3NlY3VyaXR5LmRhdGFrb290LmNvbS9tY3AifQ==Open the link and Cursor adds the server at that address.
ChatGPT
https://security.datakoot.com/mcpIn Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.
Codex
codex mcp add security-intel-mcp-by-datakoot --url 'https://security.datakoot.com/mcp'Run it once, then sign in with codex mcp login security-intel-mcp-by-datakoot if the server asks for an account.
From the project's README
As published by datakoot/security-intel-mcp in README.md.
Vulnerability intelligence for AI agents — as MCP tools your agent can call mid-task. No API keys.
Tools
| Tool | What it does | Source |
|---|---|---|
cve_lookup | CVE summary: description, CVSS score & severity, CWE, references | NVD (NIST) |
package_vulnerabilities | Known vulnerabilities for a package/version | OSV.dev |
audit_dependencies | Audit a whole package.json (or dependency list) in one call | OSV.dev |
No API keys required for any tool.
Quick start
claude mcp add --transport http security-intel https://security.datakoot.com/mcp
Or point any MCP client at https://security.datakoot.com/mcp.
Try it in 10 seconds — no key, no signup
Paste this into a terminal:
curl -s https://security.datakoot.com/mcp \
-H 'content-type: application/json' \
-H 'accept: application/json, text/event-stream' \
-d '{"jsonrpc": "2.0", "id": 1, "method": "tools/call", "params": {"name": "cve_lookup", "arguments": {"cve_id": "CVE-2021-44228"}}}'
You get the full NVD record for Log4Shell (CVE-2021-44228) — severity, CVSS vector, affected products — no API key, nothing to sign up for.
Or point any MCP client at the URL and just ask your agent, in plain language:
- "Is CVE-2021-44228 something I need to worry about?"
- "Audit my package.json for known vulnerabilities before I deploy."
Data & attribution
Vulnerability data comes from the National Vulnerability Database (NIST — US public domain) and OSV.dev (CC-BY 4.0), the same open source used by scanners like Trivy and Grype.
Part of Datakoot — keyless intelligence APIs for AI agents.
Tools it offers (5)
What this server listed when ahel dialed its public endpoint in Sep 2026, with no key and no account of yours. The names are the server’s own.
cve_lookupknown_exploitedepss_scorepackage_vulnerabilitiesaudit_dependencies
Signals
- Last commit
- Sep 2026
Advanced
- Delivery
- cve-vulnerability-lookup MCP server → your ahel connector (mcp.ahel.ai) → your AI.
- Item type
- mcp-server
- Key
com-datakoot-cve-vulnerability-lookup- Source
- github.com/datakoot/security-intel-mcp
- Hosted endpoint
https://security.datakoot.com/mcp