VulnFeed — Dependency Vulnerability Monitoring for Claude Code
An MCP server that scans your project dependencies for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions.
Free tier — 10 scans/day, 1 monitored project, no signup required.
Homepage: vulnfeed.novadyne.ai
Install
uvx vulnfeed-mcp
MCP client config
Add to your MCP client config (~/.claude/settings.json for Claude Code, claude_desktop_config.json for Claude Desktop):
Free tier (no signup, no API key):
{
"mcpServers": {
"vulnfeed": {
"command": "uvx",
"args": ["vulnfeed-mcp"]
}
}
}
Paid ($14/mo, unlimited scans + projects):
{
"mcpServers": {
"vulnfeed": {
"command": "uvx",
"args": ["vulnfeed-mcp"],
"env": {
"VULNFEED_API_KEY": "YOUR_LICENSE_KEY_HERE"
}
}
}
}
Get a license key at vulnfeed.novadyne.ai.
x402 micropayments
VulnFeed also accepts x402 micropayments — AI agents can pay per scan with USDC on Base, no API key or signup needed. When the free tier limit is reached, the API returns HTTP 402 with payment requirements that x402-compatible clients handle automatically.
- $0.01 per scan
- $0.002 per CVE lookup
- $0.50 per project per 30 days of hourly webhook monitoring (renewable; the webhook receives an
expiringevent with the renew URL a day before)
Tools
Scanning
| Tool | Description |
|---|---|
scan_project |
Auto-detect and scan all lockfiles in a directory |
scan_lockfile |
Scan a specific lockfile |
check_package |
Check a single package for vulnerabilities |
lookup_cve |
Detailed CVE info with EPSS + fix versions |
Monitoring
| Tool | Description |
|---|---|
monitor_project |
Register for continuous monitoring (optional webhook_url for push alerts) |
check_alerts |
New vulns since last scan |
set_webhook |
Set, rotate or remove a project's webhook |
update_deps |
Update snapshot after upgrading packages |
list_monitored |
See all monitored projects |
unmonitor_project |
Remove from monitoring |
Supported lockfiles
package-lock.json(npm)yarn.lock(Yarn)pnpm-lock.yaml(pnpm)requirements.txt(pip)Pipfile.lock(Pipenv)go.sum/go.mod(Go)Cargo.lock(Rust)Gemfile.lock(Ruby)composer.lock(PHP)
How it works
- Parses your lockfile to extract dependency names + versions
- Queries OSV.dev (NVD + GitHub Advisories) for known CVEs
- Enriches with EPSS exploit probability scores
- Filters noise — suppresses low-EPSS, non-critical CVEs by default
- Sorts by exploitability — most likely to be exploited first
- Returns fix version recommendations from package registries
Smart filtering
By default, VulnFeed suppresses low-priority CVEs (EPSS < 10% AND CVSS < 9.0). This cuts noise by ~80%.
Pass show_all=True to any scan tool to see everything.
Continuous monitoring
monitor_project— takes a baseline snapshot of current deps + known vulnscheck_alerts— diffs against baseline, surfaces only new vulns- Either run
check_alertsperiodically, or passwebhook_urland let VulnFeed do it
With a webhook (a paid feature: a license key, or for agents x402 at $0.50 per project per 30-day term), VulnFeed re-scans the project every hour and POSTs new findings to your URL:
{
"event": "vulnfeed.new_vulns",
"delivery_id": "…", "project_id": "…", "project_name": "…", "sent_at": "…",
"count": 1,
"new_vulns": [{ "id": "GHSA-…", "package": "express", "version": "4.18.2", "severity": "HIGH",
"epss": { "score": 0.42 }, "fix_version": "4.19.2", "summary": "…" }],
"alerts_url": "https://vulnfeed-api.novadyne.ai/vulnscan/alerts?project=…"
}
Every delivery carries X-VulnFeed-Signature: sha256=<hex>, the HMAC-SHA256 of the raw body under
the webhook_secret returned once when the webhook was set. Verify it. Failed deliveries are retried
on later sweeps for about a day, then dropped and counted. Rotate or remove the webhook with
set_webhook.
License
MIT
Release files for vulnfeed-mcp 0.3.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vulnfeed_mcp-0.3.8.tar.gz | 14.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vulnfeed_mcp-0.3.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 28.3 kB
Release files / vulnfeed_mcp-0.3.8.tar.gz
| Download URL | vulnfeed_mcp-0.3.8.tar.gz |
|---|---|
| Size | 14.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2d776793d4174cc6572200fc7dd9a5e632ff3b7fd050d38c6ef073c9c479e1a5
|
|
BLAKE2b-256 checksum How to use checksums |
4a8995971984573bc099fb32c78e77c0e1531a99c3f7413bf592228e35a7c333
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.5
|
Release files / vulnfeed_mcp-0.3.8-py3-none-any.whl
| Download URL | vulnfeed_mcp-0.3.8-py3-none-any.whl |
|---|---|
| Size | 13.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8ae370ddd1ed35985749463f04a5486e6f698df69160e5f5890af29ca38462c4
|
|
BLAKE2b-256 checksum How to use checksums |
2b408494133536acb0f5ae30b4e6a8f94abe7567390792e75a3f16e181457bd7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.5
|