Skip to main content

security-mcp

The zero-key cybersecurity toolkit for your AI assistant. No API keys, no signups, no configuration. Install it, ask Claude a security question, get an answer.

Three tools:

  • audit_site — grade any website's security from A+ to F. Checks HTTP security headers (HSTS, CSP, X-Frame-Options and more), the SSL/TLS certificate (valid, issuer, days until expiry), and DNS email-auth records (SPF, DMARC, DKIM). Every finding comes with a plain-English explanation.
  • check_cve — is this vulnerability actively exploited right now, and how likely is it to be exploited soon? Reads CISA's Known Exploited Vulnerabilities catalog and the FIRST EPSS score. Both are free public feeds.
  • lookup_attack — MITRE ATT&CK techniques in plain English. Give a technique ID like T1566 or a keyword like phishing; get what it is, how attackers use it, how to spot it, and how to defend. The technique data ships with the package, so this works fully offline.

Defensive only. This server audits and explains; it does not scan ports, exploit anything, or do anything offensive.

Install

Requires Python 3.10+.

uvx security-mcp

Or with pip:

pip install security-mcp

Claude Desktop config:

{
  "mcpServers": {
    "shield": {
      "command": "uvx",
      "args": ["security-mcp"]
    }
  }
}

Try it

  • "Audit the security of example.com"
  • "Is CVE-2021-44228 being exploited right now?"
  • "What is T1566 and how do I defend against it?"

How it works

audit_site fetches the site's homepage over HTTPS and reads its response headers, opens a TLS connection to inspect the certificate dates and issuer, and looks up SPF/DMARC/DKIM records over DNS (falling back to DNS-over-HTTPS where direct DNS is blocked). Each check carries a penalty; the penalties add up to a score, and the score maps to a grade. A failed certificate check fails the whole audit.

check_cve validates the CVE ID format, then asks two free public sources: the CISA KEV catalog (a JSON feed of vulnerabilities confirmed to be exploited in the wild, cached in memory for an hour) and the FIRST EPSS API (a 0–100% probability of exploitation in the next 30 days). The verdict combines both.

lookup_attack searches a compact bundle of the public MITRE ATT&CK catalog (697 techniques, trimmed from MITRE's CTI feed and shipped inside the package). ID lookups are exact; keyword searches rank name matches above description matches.

Development

python -m venv .venv
.venv/bin/pip install -e . pytest
.venv/bin/python -m pytest tests/ -q            # unit tests (mocked network)
SHIELD_LIVE=1 .venv/bin/python -m pytest tests/ -q -k live  # real network smoke tests

License

MIT

Release files for security-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for security-mcp 0.1.0
File Size Uploaded
security_mcp-0.1.0.tar.gz 301.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for security-mcp 0.1.0
File Interpreter ABI Platform
security_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 600.0 kB

Release files / security_mcp-0.1.0.tar.gz

Download URL security_mcp-0.1.0.tar.gz
Size 301.6 kB
Tags Source
SHA-256 checksum
How to use checksums
b87e2e74376ea77f1d8cbb251d8824fe60cb553ad1d0dc613601a8ef44b3cf42
BLAKE2b-256 checksum
How to use checksums
55b5d8324b3e74345d53512225f23dc47624559357514565db2c69ef0abb8a6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / security_mcp-0.1.0-py3-none-any.whl

Download URL security_mcp-0.1.0-py3-none-any.whl
Size 298.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
adc193a250d6d0ee893e0d0731c615bc695f43883b5b53231dfebedbddbf89aa
BLAKE2b-256 checksum
How to use checksums
5c78710936bcff3bff20fc0656d3a8ef8d790d7573c4c872588183462cb6fb16
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page