ZBS Index What actually exists in applied AI, with the source next to it

mcp server

sectora

Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.

Description as published by the maintainer. Source

  • version 1.1.0
  • slowing
  • security

slowing — Registry entry last updated 2026-04-26. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.

What this server can do

14 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.

assess_dependency(name, version, ecosystem)
Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible. Required: name, version, ecosystem.
assess_tech_risk(technologies)
Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only. Required: technologies.
get_kev_recent(days)
Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog.
get_my_posture(domain)
Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key. Required: domain.
get_scan(scan_id)
Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key. Required: scan_id.
get_threat_stats
Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required.
get_trending_cves(limit)
Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability.
get_weaponization_score(cve_id)
Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID. Required: cve_id.
list_my_findings(limit, domain, status, severity)
List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key.
list_my_scans(limit, status)
List the API key owner's recent scans with summary counts. Requires API key.
lookup_cve(cve_id)
Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID. Required: cve_id.
lookup_ip_reputation(ip)
Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both). Required: ip.
scan_url(url, confirm, profile)
Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user. Requires API key. Required: url.
search_cves(query, is_kev, severity, has_exploit)
Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text. Required: query.

Last successful function declaration observed on . Source: https://mcp.sectora.io/mcp. We list what the server declared; we do not call any of these functions.

Endpoint status observed on . Source: https://mcp.sectora.io/mcp.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
Latest published version 1.1.0 Latest version string the maintainer published to the registry. as of fetch Model Context Protocol
Registry record last updated 2026-04-26 When the registry record was last updated by its maintainer. point in time Model Context Protocol
First listed in the MCP Registry 2026-04-26 Date this server was first published to the official MCP Registry. Not a usage or quality measure. point in time Model Context Protocol
mcp tools declared 14 tools Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. as of probe mcp.sectora.io
mcp endpoint status ok The server listed 14 functions when asked. as of probe mcp.sectora.io

Where to get it

This record as data

Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.

GET /api/v1/entries/mcp_server.json

Sources

  1. Tools declared by the MCP server at https://mcp.sectora.io/mcp — mcp.sectora.io, observed , trust tier 1.
  2. Official MCP Registry — Model Context Protocol, observed , trust tier 1.