Back to Browse

Cisa Kev MCP Server

Developer ToolsUse Caution2.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...

About

CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...

Security Report

2.2
Use Caution2.2Critical Risk

This MCP server exhibits several concerning patterns that warrant caution. The codebase includes network calls to an external metering endpoint (proofof.ai) to check API usage and tier limits, which could enable data exfiltration or surveillance. Additionally, the server uses an undocumented shared authentication module loaded from a hardcoded home directory path, creating a supply-chain-like risk. While the tool implementations themselves are stubs (low functional risk), the monetization/metering infrastructure and auth delegation patterns pose moderate security and privacy concerns. The scoring reflects these structural issues despite low code complexity. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed ยท 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-csoai-org-cisa-kev-mcp": {
      "args": [
        "cisa-kev-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MCP Scorecard: 90/100

Cisa Kev MCP

mcp-name: io.github.CSOAI-ORG/cisa-kev-mcp

CISA KEV Known Exploited Vulnerabilities MCP

MEOK AI Labs EU AI Act License PyPI

CISA Known Exploited Vulnerabilities MCP

Buy Starter โ€” ยฃ29/mo

Signed attestations + unlimited audits + email support. ๐Ÿ‘‰ Subscribe at meok.ai โ€” instant HMAC signing key + Stripe-managed billing.

Free tier remains MIT-licensed and zero-config. Upgrade only when you need signed compliance artefacts for audit.

CISA Known Exploited Vulnerabilities MCP. BOD 22-01 + EPSS overlay. MIT


๐Ÿš€ Quick Start

# Install via pip
pip install cisa_kev_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install cisa-kev-mcp --client claude

โœจ Features

  • MCP protocol compliant
  • Easy installation
  • Well-documented API
  • Production-ready
  • Active maintenance

๐Ÿ“– Documentation

๐Ÿ›ก๏ธ Compliance

This MCP server is built with EU AI Act compliance built-in:

  • Free: 10 calls/day. No API key required.

  • Pro ยฃ79/mo: unlimited + signed attestations. Subscribe

  • Enterprise ยฃ1,499/mo: white-label + on-premise + SLA. hello@meok.ai

  • โœ… Article 9 โ€” Risk Management System

  • โœ… Article 13 โ€” Transparency & Instructions for Use

  • โœ… Article 15 โ€” Bias Detection & Testing

  • โœ… Article 26 โ€” FRIA Support (where applicable)

  • โœ… Article 50 โ€” AI Content Watermarking (where applicable)

Need help getting compliant? Book a free 15-min diagnostic โ†’

๐Ÿข Enterprise

Need custom development, SLA guarantees, or white-label deployment?

  • Pro: $99/mo โ€” Full MCP suite + EU AI Act tracking
  • Enterprise: $499/mo โ€” Custom dev + SLA + Dedicated support

View Pricing โ†’ | Contact Sales โ†’

๐Ÿค Part of the MEOK Ecosystem

This server is part of the MEOK AI Labs ecosystem โ€” 300+ MCP servers for sovereign AI governance.

DomainPurpose
councilof.aiEU AI Act compliance marketplace
safetyof.aiAI safety & monitoring
meok.aiSovereign AI platform
cobolbridge.aiLegacy modernization

๐Ÿ“œ License

MIT ยฉ CSOAI-ORG


๐Ÿ’ธ Try MEOK in 30 seconds โ€” instant buy ladder

TierPriceWhat you getStripe
Smoke testยฃ1Signed sample MCP-Hardening report + Article 50 PDFhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Quick Kitยฃ9EU AI Act Article 50 implementation guide (C2PA + EU-Icon)https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Founder Callยฃ2930-min 1-on-1 with the founderhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t

Refundable. UK Stripe โ€” VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "cisa-kev-mcp": {
      "command": "uvx",
      "args": ["cisa-kev-mcp"]
    }
  }
}

Or: pip install cisa-kev-mcp then run the cisa-kev-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use query_kev_catalog to โ€ฆ"
  • "Use check_remediation_deadline to โ€ฆ"
  • "Use export_kev_sbom to โ€ฆ"

Reviews

No reviews yet

Be the first to review this server!