Mmcp.market

Exploitwatch MCP server

by exploitwatch-kappa.vercel.app·app.vercel.exploitwatch-kappa/exploitwatch·v1.0.0

Check dependencies against CISA's real Known Exploited Vulnerabilities feed.

C69/100grade C
What users say
No reviews yet
Be the first
Safety scan
C69/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed Exploitwatch yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Exploitwatch tools (1)

write = sends, deletes, buys or posts
  • check_kevFree

    Check a comma-separated list of software dependency/product names (e.g. 'lodash, openssl, apache struts') against CISA's real, public Known Exploited Vulnerabilities (KEV) catalog. Returns any current matches with the CVE ID, description, date added, and known ransomware use -- grounded in CISA's live feed, not a guess. Useful for triaging whether a project's dependencies include anything under active exploitation right now.

Public scan report

scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it

1 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 429ms20/20
  • Tool poisoning1 tool descriptions checked15/15
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http exploitwatch https://exploitwatch-kappa.vercel.app/api/mcp
Add to Cursor

Exploitwatch: common questions

Is Exploitwatch MCP server safe?
With care: it is graded C, so read the findings first (69/100). Read the Exploitwatch safety report
How do I install Exploitwatch?
It runs remotely at exploitwatch-kappa.vercel.app. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Exploitwatch need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Exploitwatch maintained?
The latest release is v1.0.0.
Is Exploitwatch up?
100% of our last 4 checks got an answer. We check remote servers about four times a day.

More from exploitwatch-kappa.vercel.app