vulnfeedby Novadyne

Know when your dependencies are vulnerable.

An MCP server that reads your lockfile, checks OSV.dev (GitHub Advisories plus each ecosystem's security database), and tells you what actually matters — prioritized by real-world exploit probability, with exact fix versions.

Free tier — 10 scans/day, no signup. $14/mo for unlimited.

Building an agent instead of shipping code yourself? VulnFeed is also a keyless, pay-per-call CVE & EPSS feed over x402 — your agent hits a 402, pays a few cents in USDC, and gets structured, exploit-ranked results. No account, no API key, no subscription. Agent API →

> Scan my project for vulnerabilities
Using: scan_project(".")

Scanning package-lock.json... 3 affected packages, 29 vulnerabilities

lodash@4.17.20
  CVE-2021-23337 | Severity: HIGH (8.1) | EPSS: 21.3% (medium) | Fix: upgrade to 4.18.0
  Command injection in lodash

28 low-priority CVEs suppressed (EPSS < 10%, CVSS < 9) — show_all=True to see them

Top priority: lodash — 1 of 29 findings has a real chance of being exploited. Upgrade to 4.18.0.

Why not just ask Claude to check?

It knows your deps

Reads your package-lock.json, requirements.txt, or go.sum and filters to only the CVEs that hit your actual dependency tree. No noise from packages you don't use.

EPSS prioritization

Most CVEs are noise. EPSS (Exploit Prediction Scoring System) scores each one by real-world exploitability. VulnFeed surfaces the ones likely to be used in real attacks.

Fix recommendations

Not just "you're vulnerable" but upgrade lodash 4.17.20 → 4.18.0. The fix version comes from the advisories' own affected-version ranges: the first release that closes every advisory for that CVE.

Continuous monitoring

Register your project once and check back any time with check_alerts (free for one project). With a license key — or $0.50 per project per 30 days over x402 — add a webhook: VulnFeed re-scans hourly and POSTs new findings to your URL, HMAC-signed. New CVE published at 3am? Your CI hook knows before your morning session does.

10 tools, one install

Scan a lockfile, check a package, look up a CVE, monitor a project, set a webhook, check alerts, update deps, list projects. Everything a security workflow needs. (Single-CVE lookup and webhooks need a license key or x402.)

Zero upstream cost

Data sources are OSV.dev (which aggregates GitHub Advisories and the ecosystem security databases) and FIRST.org's EPSS — all free, public APIs. No vendor lock-in, no data broker middlemen. Your $14 pays for the intelligence layer, not data access.

How it compares

Free MCP servers Snyk / Socket VulnFeed
CVE lookup ✓ ✓ ✓
Knows your deps — ✓ ✓
EPSS prioritization — ✓ ✓
Fix recommendations — ✓ ✓
Continuous monitoring — ✓ ✓
MCP-native ✓ — ✓
Free tier ✓ — ✓ (10 scans/day)
x402 micropayments — — ✓ ($0.01/scan)
Price (paid) Free $25-49/dev/mo $14/mo flat

Setup in 2 minutes

Free tier — no signup, no API key

10 scans/day, 1 monitored project (pull-based via check_alerts). Single-CVE lookup and webhooks need a license key or x402. Just add this to your MCP config:

{
  "mcpServers": {
    "vulnfeed": {
      "command": "uvx",
      "args": ["vulnfeed-mcp"]
    }
  }
}

Works in Claude Code, Claude Desktop, Cursor, VS Code, and Windsurf.

Restart your client. Ask it to scan my project for vulnerabilities. That's it.

Unlimited — $14/mo

Unlimited scans, unlimited monitored projects, CVE lookup, and hourly webhook monitoring. Add your license key:

{
  "mcpServers": {
    "vulnfeed": {
      "command": "uvx",
      "args": ["vulnfeed-mcp"],
      "env": {
        "VULNFEED_API_KEY": "YOUR_LICENSE_KEY_HERE"
      }
    }
  }
}

Get your license key — flat rate, not per-seat, not per-repo.

Pay-per-scan — x402 micropayments

AI agents can pay per request with USDC on Base — no account, no API key, no subscription. Your agent gets a 402 response, pays $0.01, and gets results. Works with any x402-compatible client.

# Agent sends request, gets HTTP 402 with payment details
# x402 client library handles payment automatically
# $0.01 per scan · $0.002 per CVE lookup · $0.50 per project / 30 days of hourly webhook monitoring

# Discovery endpoint:
curl https://vulnfeed-api.novadyne.ai/.well-known/x402

Uses the x402 protocol — USDC on Base via Coinbase facilitator. No middleman, instant settlement. View pricing & endpoints.

Deep dive: a pay-per-call CVE & EPSS MCP server priced via x402 — how agents buy vulnerability data without an account.

Common questions

Is there a paid x402 vulnerability feed API?

Yes. VulnFeed serves CVE and EPSS vulnerability data as pay-per-call x402 endpoints: $0.002 USDC per CVE lookup and $0.01 per dependency scan, settled on Base. There is no account, API key, or subscription — an x402-compatible client receives the HTTP 402 payment requirements and pays per request. Endpoints are listed at the x402 discovery endpoint.

How do I get EPSS exploit-prediction scores via an API or MCP server?

EPSS (Exploit Prediction Scoring System) scores are published by FIRST.org and updated daily. VulnFeed attaches a live EPSS score to every finding in a scan — free, no key — through its MCP server (uvx vulnfeed-mcp) and its API. Full single-CVE lookups need a license key or $0.002 per call over x402.

What MCP server gives an AI agent live CVE and vulnerability data?

vulnfeed-mcp (PyPI, MIT) is an MCP server that feeds an AI agent live vulnerability data: it scans dependency lockfiles across six package ecosystems (npm, PyPI, Go, crates.io, RubyGems, Packagist), looks up individual CVEs with severity and fix versions, and ranks findings by EPSS exploit probability rather than CVSS alone. The free tier is keyless — 10 scans/day with no signup.

Do I need an account or API key to use VulnFeed?

No. The free tier (10 scans/day) needs no signup or key. Beyond that, agents can pay per call with x402 micropayments — still keyless — or you can get unlimited scans for a flat $14/mo license.

Start monitoring your dependencies.