Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.
An MCP server that scans your project dependencies for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. Free tier — 10 scans/day, 1 monitored project, no signup required. Homepage: vulnfeed.novadyne.ai Add to your MCP client config ( for Claude Code, for Claude Desktop): Free tier (no signup, no API key): Paid ($14/mo, unlimited scans + projects):…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 0 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
An MCP server that scans your project dependencies for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. Free tier — 10 scans/day, 1 monitored project, no signup required. Homepage: vulnfeed.novadyne.ai Add to your MCP client config ( for Claude Code, for Claude Desktop): Free tier (no signup, no API key): Paid ($14/mo, unlimited scans + projects): Get a license key at vulnfeed.novadyne.ai. VulnFeed also accepts x402 micropayments — AI agents can…
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.