Odel
attestd mcp

attestd mcp

Local
@attestd-ioTypeScriptMITUpdated 1mo ago

CVE and supply chain checks for MCP clients. Covers infrastructure, PyPI, and npm packages.

@attestd/mcp

npm version smithery badge

Attestd checks whether a dependency version has exploitable CVEs or a confirmed supply-chain compromise. One API call returns a structured risk response.

Official Model Context Protocol (MCP) server for Attestd. Exposes CVE risk and supply-chain checks as tools for Claude Code, Claude Desktop, and any MCP-compatible client.

Get a free API key · Full docs

  • stdio transport: run via npx -y @attestd/mcp with no global install.
  • check_package_vulnerability: wraps GET /v1/check using @attestd/sdk.
  • check_batch_vulnerabilities: checks up to 100 packages in one call. Use for lockfile and manifest audits.
  • list_covered_products: returns Attestd-covered products. With an API key, returns live data from GET /v1/products. Without a key, returns the static bundled infrastructure list.
  • get_cve_details: returns CVSS, EPSS, KEV status, and affected products for a single CVE id.

Prerequisites

  • Node.js 18+
  • An Attestd API key from the portal. Required for check_package_vulnerability, check_batch_vulnerabilities, get_cve_details, and live list_covered_products.

Claude Code / MCP config

Add to ~/.claude/mcp.json or project .mcp.json:

{
  "mcpServers": {
    "attestd": {
      "command": "npx",
      "args": ["-y", "@attestd/mcp"],
      "env": {
        "ATTESTD_API_KEY": "your-api-key-here"
      }
    }
  }
}

Optional: override the API base URL (e.g. dev):

"env": {
  "ATTESTD_API_KEY": "your-api-key-here",
  "ATTESTD_BASE_URL": "https://dev.api.attestd.io"
}

Tools

check_package_vulnerability

ArgumentTypeDescription
productstringProduct slug (nginx, postgresql, litellm, …)
versionstringExact version (1.20.0)

Returns JSON with:

FieldMeaning
outsideCoveragetrue if the product is not covered. Unknown risk, not safe.
riskStatecritical | high | elevated | low | none | null when outside coverage
activelyExploitedCISA KEV signal
remoteExploitabletrue if any matching CVE is remotely exploitable
authenticationRequiredtrue only when all matching CVEs require authentication
patchAvailable / fixedVersionPatch guidance
confidenceSynthesis confidence 0.0–1.0
cveIdsCVE IDs contributing to the risk assessment
typosquatPackage name integrity: typosquat or AI-hallucinated name (kind, resembles, likely_intended)
messageExplanation when outsideCoverage is true
supplyChainCompromised / supplyChainDescriptionPyPI/npm supply-chain signal

On invalid/missing API key or rate limit, returns isError: true with a JSON error string.

check_batch_vulnerabilities

ArgumentTypeDescription
itemsarrayArray of { product, version } objects. Maximum 100 per call. Each item costs one API call.

Quota is checked upfront. If the batch would exceed your monthly quota, a 429 is returned before any calls are billed.

Returns JSON with count and results. Supported items include the same fields as check_package_vulnerability minus typosquat. Outside-coverage items return only product, version, outsideCoverage: true, and riskState: null.

list_covered_products

No arguments. With an API key, returns live JSON from GET /v1/products:

FieldMeaning
source"live" when fetched from the API
totalCombined count of CVE products and supply chain packages
cveProductsCVE infrastructure slugs with display names
supplyChainPackagesMonitored PyPI/npm packages

Without an API key, returns the static bundled list:

FieldMeaning
source"static"
countNumber of bundled infrastructure products
productsArray of { slug, display } entries

get_cve_details

ArgumentTypeDescription
cve_idstringCVE identifier, e.g. CVE-2021-44228

Returns JSON with:

FieldMeaning
foundtrue when the CVE is in Attestd's database; false on 404 (not an error)
cveIdCVE identifier
descriptionNVD description text
cvssScore / cvssVectorCVSS base score and vector
activelyExploitedCISA KEV signal
remoteExploitableRemotely exploitable
authenticationRequiredAuthentication required for exploitation
affectedProductsAttestd product slugs affected by this CVE
epssScore / epssPercentileEPSS probability and percentile
sourcePublishedAt / lastCheckedAtISO timestamps

When the CVE is not found, returns { "found": false, "cveId": "..." } without isError. On invalid/missing API key or rate limit, returns isError: true with a JSON error string.

Verify locally

npm run build
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | node dist/index.js

License

MIT. See LICENSE.