71
/ 100
19 days ago
glama

touful-vuln-search-mcp

Unified vulnerability search MCP server for penetration testing agents, integrating 5 data sources (NVD, OSV, EPSS, CISA KEV, Exploit-DB+GitHub) and 10 MCP tools for CVE query, keyword search, batch query, EPSS scoring, KEV checking, exploit search, and comprehensive assessment with Chinese output.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 2 credentials: NVD_API_KEY, GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretNVD_API_KEYyour_nvd_api_key_here # 必需,从 https://nvd.nist.gov/developers 申请
🔐 secretGITHUB_TOKENyour_github_token_here # 可选,提高 GitHub 搜索限额
configHTTP_PROXY=socks5://127.0.0.1:7890 # 可选,网络受限时启用
configALL_PROXY
configHTTPS_PROXY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/touful-touful-vuln-search-mcp-qopzva)](https://m8ven.ai/mcp/touful-touful-vuln-search-mcp-qopzva)
commit: 61cdf1cd96ea2a4e8eabdf9aaceda4fd9c23856d
code hash: 543c25c3ef67072a8911da3a947bb56a03521e33b75ee049aef68af31cc20f88
verified: 7/12/2026, 8:35:30 AM
view raw JSON →