Connect your account, then chat with AI to run tools.
Run Trivy on your machine via Desktop, enrich with NVD + CISA KEV + EPSS, and bucket container CVEs into exploit priority, patch today, and defer — with a reason on every row.
Vulnerability Intelligence is used here only to identify this integration; MCPBundles is not affiliated with or endorsed by Vulnerability Intelligence or its owner.
Built for
Security Engineers, DevOps Teams, MSPs, Container Platform Owners
Scan node:20-slim (balanced)
Runs a local Trivy scan on a real Debian-based Node image and shows HIGH-tier fixes in patch_today.
Scan node:20-slim with policy_preset balanced. Summarize patch_today vs defer and explain one bucket_reason.
Python base — permissive patches
Connect Vulnerability Intelligence to any MCP client in minutes
You’ll sign in to MCPBundles when your client connects.
https://mcp.mcpbundles.com/bundle/vulnerability-intelligenceSign in once, then chat here with saved access — one connection to many servers, with a history of what your AI ran.
MCPBundles publishes this directory for MCP discovery. Except where we host or operate an offering, third-party services run under their own terms. Product and company names on this page are used in a descriptive, identifying way (including under nominative fair use where applicable); they remain the property of their owners. Nothing here grants you rights in those marks, and nothing here is an offer to sell a third party's services. Terms
You’ll sign in to MCPBundles when your client connects.
https://mcp.mcpbundles.com/bundle/vulnerability-intelligenceSign in once, then chat here with saved access — one connection to many servers, with a history of what your AI ran.
Opens MCPBundles Studio with this server selected. After sign-in, chat and run tools from the same thread.
Browse all toolsContrasts policy presets on a slim API base — MEDIUM pip CVEs surface only under permissive_patches.
Scan python:3.13-slim with policy_preset permissive_patches. How many patch_today rows appear vs balanced?
Why is CRITICAL in defer?
Shows EPSS + fix-available gating — high CVSS does not auto-page.
Scan python:3.13-slim and explain why notable_deferred_critical CVEs stayed in defer despite CRITICAL scanner severity.
Analyze one CVE
Single-CVE cross-source analysis for the regreSSHion case study.
Analyze CVE-2024-6387 across NVD, KEV, and EPSS and compare CVSS rank vs composite exploit priority.
Do I have to paste Trivy JSON?
No. With MCPBundles Desktop connected, pass `target` on `scan_triage` and Trivy runs on your machine. Paste JSON only when Desktop is offline.
What do exploit_priority, patch_today, and defer mean?
Exploit priority = CISA KEV or EPSS above your threshold. Patch today = vendor fix available and composite tier meets your policy minimum. Defer = everything else, including scary CVSS with low EPSS and no fix.
Why would a CRITICAL CVE land in defer?
Scanner severity is not the same as exploit likelihood. Old libc/tar rows often show CRITICAL CVSS with sub-5% EPSS and no vendor fix — the policy explains each defer with bucket_reason.
Domain knowledge for Vulnerability Intelligence — workflow patterns, data models, and gotchas for your AI agent.
Combines NIST NVD, CISA KEV, and FIRST.org EPSS into composite risk scores and container scan triage.
With MCPBundles Desktop connected and a Container Scan credential bound:
You can still paste Trivy/Grype JSON via scan_output when Desktop is unavailable.
Also listed on
Start here
Showing 32 of 34
Showing 32 of 34 tools from the public preview. Connect the server to inspect the full live tool list.
Compare Cvss Vs Composite
compare_cvss_vs_compositeCompare scanner CVSS ranking vs composite exploit-priority ranking for the same scan. Shows overlap and flipped priorities. When the workspace panel is open, results update the panel automatically — do not call this tool again only to refresh the UI.
Open in StudioNo. With MCPBundles Desktop connected, pass `target` on `scan_triage` and Trivy runs on your machine. Paste JSON only when Desktop is offline.
Exploit priority = CISA KEV or EPSS above your threshold. Patch today = vendor fix available and composite tier meets your policy minimum. Defer = everything else, including scary CVSS with low EPSS and no fix.
Scanner severity is not the same as exploit likelihood. Old libc/tar rows often show CRITICAL CVSS with sub-5% EPSS and no vendor fix — the policy explains each defer with bucket_reason.
Balanced requires HIGH+ tier before patch_today when a fix exists. Permissive_patches lowers the bar to MEDIUM+, which surfaces pip/npm fixes on slim Python bases that balanced would defer.
Add the MCPBundles server URL to your MCP client configuration (Claude Desktop, Cursor, VS Code, etc.). The URL format is: https://mcp.mcpbundles.com/bundle/vulnerability-intelligence. Authentication is handled automatically.
Vulnerability Intelligence provides 34 tools that can be called by AI agents, along with a SKILL.md that gives your AI agent domain knowledge about when and how to use them.
Vulnerability Intelligence uses No auth required or API Key. Container Scan requires credentials. Connect via MCPBundles and authentication is handled automatically.
© 2026 ThinkChain Inc. All rights reserved.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.
Other MCP servers in this category from the directory index