vulnerability-db (AppThreat/vulnerability-db) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 15 tools. No publisher has claimed this listing.
Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
AppThreat
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
PYTHONIOENCODINGIf unset on Windows, VDB reconfigures standard streams to UTF-8.VDB_AGE_DAYSDays before the MCP server considers the local database stale and attempts an app-only ORAS download. Non-numeric values are passed through to the freshness check, so prefer an integer string.VDB_TEST_KEEP_HOMEVDB_HOMEwhich is downloading an image into , fetching and refreshing shards,VDB_SHARD_FANOUTMulti-shard fan-out strategy. sequential runs the canonical per-shard search path; attach UNION-ALLs attached shard indexes for the index sweep. Both are gated by the multi-shard match-set gate.NVD_START_YEARApplication ecosystem advisories are not filtered by year.VDB_CACHECache directory. If $VDB_CACHE/vuln-list.zip exists it is used instead of downloading.GITHUB_PAGE_COUNTNumber of GitHub advisory GraphQL pages to fetch during a full refresh.VDB_IGNORE_ALPINEExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.GITHUB_GRAPHQL_URLAlternate GitHub GraphQL endpoint, for testing or enterprise proxies.NPM_PAGE_COUNTNumber of npm advisory pages to fetch where npm ingestion is used.VDB_SHARDS_DIRstore-dir overrides the shard store location (default $),VDB_AUTO_FETCHtrue to let searches fetch missing shards on demand, or callVDB_APP_ECOSYSTEM_START_YEARis unset by default so library advisories areVDB_IGNORE_OSSkip the OSV operating-system feeds added by default. Use app-only workflows for the smallest app database.VDB_IGNORE_ALMALINUXExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_REDHATExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_DEBIANExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_ROCKYLINUXExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_MAGEIAExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_ALPAQUITAExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_MINIMOSExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_IGNORE_UBUNTUExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.VDB_INCLUDE_SUSEForce-include distro paths from LINUX_DISTRO_VULN_LIST_PATHS, such as VDB_INCLUDE_ALPINE=true. VDB_INCLUDE_SUSE=true and VDB_INCLUDE_OPENSUSE=true are separate: they enable the OSV SUSE and openSUSE feeds, the only source of SUSE family data, which are off by default. They have the heaviest errata fan-out of any feed, so they stay opt-in for local builds; the published OS databases enable both.VDB_INCLUDE_OPENSUSEForce-include distro paths from LINUX_DISTRO_VULN_LIST_PATHS, such as VDB_INCLUDE_ALPINE=true. VDB_INCLUDE_SUSE=true and VDB_INCLUDE_OPENSUSE=true are separate: they enable the OSV SUSE and openSUSE feeds, the only source of SUSE family data, which are off by default. They have the heaviest errata fan-out of any feed, so they stay opt-in for local builds; the published OS databases enable both.VDB_IGNORE_AZURE_LINUXExclude distro-specific data. Static OSV toggles are VDB_IGNORE_ALMALINUX, VDB_IGNORE_ALPINE, VDB_IGNORE_REDHAT, VDB_IGNORE_DEBIAN, VDB_IGNORE_ROCKYLINUX, VDB_IGNORE_MAGEIA, VDB_IGNORE_ALPAQUITA, VDB_IGNORE_MINIMOS, VDB_IGNORE_UBUNTU and VDB_IGNORE_AZURE_LINUX; vuln-list also supports the distro keys in LINUX_DISTRO_VULN_LIST_PATHS. SUSE and openSUSE are opt-in instead. Debian, Ubuntu, Red Hat, SUSE, openSUSE and Azure Linux data comes from the OSV feeds only.OSV_INCLUDE_FUZZLinux and OSS-Fuzz OSV feeds are excluded by default; set =trueVDB_IGNORE_LINUX_KERNELSkip pkg:generic/linux records. The kernel feed dominates the database (around 130k rows) with commit-sha version ranges that semantic-version lookups cannot match.VDB_INCLUDE_LINUX_KERNELOpt back in to storing Linux kernel CVEs. Overrides VDB_IGNORE_LINUX_KERNEL.VDB_INCLUDE_METADATAinclude-metadata is equivalent to =true. Builds printVDB_QUIETSuppress logo, logs and cache progress output. Equivalent to --quiet.VDB_SQLITE_IMMUTABLEprocess runs, set =true.VDB_PROGRESS_INTERVALMinimum records between progress messages. Invalid values fall back to 10000; minimum 1.VDB_MAX_AFFECTED_PER_BLOBMaximum affected entries merged into one source blob per CVE; further entries spill into more blobs so blob size and per-row hydration cost stay flat as CVE fan-out grows. 0 disables merging; invalid values fall back to 32.VDB_ZSTD_BINcompression.zstd) or a zstd binary on PATH ( points at oneVDB_SQLITE_CACHE_SIZEValue passed to PRAGMA cache_size. The default is about 64 MiB using SQLite's negative-KiB convention.VDB_SQLITE_JOURNAL_MODEValue passed to PRAGMA journal_mode. Valid: DELETE, TRUNCATE, PERSIST, MEMORY, WAL, OFF.VDB_SQLITE_SYNCHRONOUSValue passed to PRAGMA synchronous. Valid: OFF, NORMAL, FULL, EXTRA, or 0 to 3.VDB_TEMP_DIRSet to a partition with room. An app+OS build needs significantGITHUB_TOKENToken for the GitHub GraphQL API. Avoid printing this value in logs.Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
15/15 tools missing one or more hints — search_by_purl_like (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_by_any (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_by_cpe_like (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +12 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/appthreat/vulnerability-db)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check