MCP低风险未认领

attestd-mcp

CVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm).

attestd-ioattestd-io/attestd-mcp更新于 2026年9月26日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.attestd-io/attestd-mcp",
  "description": "CVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm).",
  "repository": {
    "url": "https://github.com/attestd-io/attestd-mcp",
    "source": "github"
  },
  "version": "0.3.1",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@attestd/mcp",
      "version": "0.3.1",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Attestd API key (atst_...). Required for check_package_vulnerability, check_batch_vulnerabilities, get_cve_details, and live list_covered_products. Get one at https://api.attestd.io/portal",
          "format": "string",
          "isSecret": true,
          "name": "ATTESTD_API_KEY"
        },
        {
          "description": "Optional API base URL override. Defaults to https://api.attestd.io",
          "format": "string",
          "name": "ATTESTD_BASE_URL"
        }
      ]
    }
  ]
}

权限

声明检测
运行代码—node
安装—npm:@attestd/mcp@0.3.1
安装时运行脚本—无
网络无无
需要的凭据ATTESTD_API_KEYATTESTD_API_KEY
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #10.3.1最新2026年10月7日