mcpserver.lol
registry/sectora
Connection check verified live · 27h ago

sectora

Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.

Tools 14
GitHub stars
Installs / wk
Licence
Transport streamable-http
Last checked 27h ago

Tools & capabilities

14 tools

Read from the running server on 27h ago.

assess_dependency name*version*ecosystem*
Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity,…
assess_tech_risk technologies*
Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only.
get_kev_recent days
Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.
get_my_posture domain*
Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TL…
get_scan scan_id*
Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key.
get_threat_stats
Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.
get_trending_cves limit
Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.
get_weaponization_score cve_id*
Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID.
list_my_findings limitdomainstatusseverity
List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries;…
list_my_scans limitstatus
List the API key owner's recent scans with summary counts. Requires API key.
lookup_cve cve_id*
Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE…
lookup_ip_reputation ip*
Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both).
scan_url url*confirmprofile
Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calli…
search_cves query*is_kevseverityhas_exploit
Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text.