Security Intel MCP — by Datakoot

MCP serverSecurity

Find out whether the software libraries in a project have known security flaws. Once added, your AI can look up reported vulnerabilities by CVE ID and audit a project's dependency manifest for reported issues. It works without any API keys.

Available today. Use it from your connected AI after setup.

After adding it, share a CVE ID or your project's dependency file with your AI and ask it to check for known vulnerabilities.

Then ask your AI: use the cve lookup tool from Security Intel MCP

What your AI can do with it

  • Look up the details of a known vulnerability using its CVE ID
  • Audit a dependency manifest to find libraries with reported security issues
  • Check a project's listed dependencies for known vulnerabilities before you rely on them
  • Run these checks without setting up any API keys

Install Security Intel MCP — by Datakoot

The server’s own address, for the clients that take one directly. Or connect ahel onceand every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user security-intel-mcp-by-datakoot 'https://security.datakoot.com/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://security.datakoot.com/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=security-intel-mcp-by-datakoot&config=eyJ1cmwiOiJodHRwczovL3NlY3VyaXR5LmRhdGFrb290LmNvbS9tY3AifQ==

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://security.datakoot.com/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add security-intel-mcp-by-datakoot --url 'https://security.datakoot.com/mcp'

    Run it once, then sign in with codex mcp login security-intel-mcp-by-datakoot if the server asks for an account.

From the project's README

As published by datakoot/security-intel-mcp in README.md.

Vulnerability intelligence for AI agents — as MCP tools your agent can call mid-task. No API keys.

Tools

ToolWhat it doesSource
cve_lookupCVE summary: description, CVSS score & severity, CWE, referencesNVD (NIST)
package_vulnerabilitiesKnown vulnerabilities for a package/versionOSV.dev
audit_dependenciesAudit a whole package.json (or dependency list) in one callOSV.dev

No API keys required for any tool.

Quick start

claude mcp add --transport http security-intel https://security.datakoot.com/mcp

Or point any MCP client at https://security.datakoot.com/mcp.

Try it in 10 seconds — no key, no signup

Paste this into a terminal:

curl -s https://security.datakoot.com/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc": "2.0", "id": 1, "method": "tools/call", "params": {"name": "cve_lookup", "arguments": {"cve_id": "CVE-2021-44228"}}}'

You get the full NVD record for Log4Shell (CVE-2021-44228) — severity, CVSS vector, affected products — no API key, nothing to sign up for.

Or point any MCP client at the URL and just ask your agent, in plain language:

  • "Is CVE-2021-44228 something I need to worry about?"
  • "Audit my package.json for known vulnerabilities before I deploy."

Data & attribution

Vulnerability data comes from the National Vulnerability Database (NIST — US public domain) and OSV.dev (CC-BY 4.0), the same open source used by scanners like Trivy and Grype.

Part of Datakoot — keyless intelligence APIs for AI agents.

Tools it offers (5)

What this server listed when ahel dialed its public endpoint in Sep 2026, with no key and no account of yours. The names are the server’s own.

  • cve_lookup
  • known_exploited
  • epss_score
  • package_vulnerabilities
  • audit_dependencies

Signals

Last commit
Sep 2026
Advanced
Delivery
cve-vulnerability-lookup MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
com-datakoot-cve-vulnerability-lookup
Source
github.com/datakoot/security-intel-mcp
Hosted endpoint
https://security.datakoot.com/mcp