pipeworx-nvdNVD MCP — wraps the NIST National Vulnerability Database API (free, no auth)
Install via ClawdBot CLI:
clawdbot install brucegutman/pipeworx-nvdGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://pipeworx.io/packs/nvdAudited Apr 17, 2026 · audit v1.0
Generated May 12, 2026
Integrate the NVD MCP into a continuous integration pipeline to automatically search for CVEs related to project dependencies. When a new dependency is added or updated, the tool checks for known vulnerabilities, helping development teams remediate issues before deployment.
Security operations center analysts use the recent_cves tool to stay updated on the latest publicly disclosed vulnerabilities. This enables rapid triage and prioritization of patching efforts for critical infrastructure.
Procurement teams evaluate third-party software vendors by searching for CVEs associated with their products. The get_cve tool provides detailed information on severity and impact, aiding risk-based decision making.
Compliance officers use the NVD MCP to generate reports on vulnerabilities affecting systems in scope for regulations like PCI DSS or HIPAA. The tool helps demonstrate due diligence in vulnerability management.
Instructors and students use the search_cves tool to explore real-world vulnerability data during cybersecurity courses. It provides hands-on experience with CVE research without requiring API keys.
Offer the basic NVD MCP tool for free to attract users, then charge for premium features like advanced filtering, historical trend analysis, or integration with SIEM platforms.
Embed the NVD MCP into a broader managed vulnerability management service. The free tool acts as a lead generator, with paid tiers including automated patching recommendations and 24/7 monitoring.
License the MCP integration to IDE or CI/CD tool vendors who bundle it as a premium feature. Vendors pay per-seat or per-usage to include NVD data directly in their platforms.
💬 Integration Tip
For a quick start, simply add the provided MCP server configuration to your MCP client like Claude Desktop or Cursor; no API key is needed.
Scored May 12, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...