MCPLow riskUnclaimed
attestd-mcp
CVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm).
attestd-ioattestd-io/attestd-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.attestd-io/attestd-mcp",
"description": "CVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm).",
"repository": {
"url": "https://github.com/attestd-io/attestd-mcp",
"source": "github"
},
"version": "0.3.1",
"packages": [
{
"registryType": "npm",
"identifier": "@attestd/mcp",
"version": "0.3.1",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Attestd API key (atst_...). Required for check_package_vulnerability, check_batch_vulnerabilities, get_cve_details, and live list_covered_products. Get one at https://api.attestd.io/portal",
"format": "string",
"isSecret": true,
"name": "ATTESTD_API_KEY"
},
{
"description": "Optional API base URL override. Defaults to https://api.attestd.io",
"format": "string",
"name": "ATTESTD_BASE_URL"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:@attestd/mcp@0.3.1Runs install scripts—None
NetworkNoneNone
Needs credentials
ATTESTD_API_KEYATTESTD_API_KEYOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.3.1latestOct 7, 2026
attestd-mcpOpen in Codeg