Check Package Vulnerabilities From an AI Agent
Before an agent installs or recommends a dependency, it can check whether that package has known vulnerabilities — using Security Intel, a keyless MCP server backed by the NVD and OSV.
How
- Ask your agent to audit a
package.json— it callsaudit_dependenciesand flags every package with a known CVE. - Or check one package with
package_vulnerabilities, or a specific CVE withcve_lookup.
claude mcp add --transport http security-intel https://security.datakoot.com/mcpPricing
Free on every server — 100 keyless calls a day, no signup. Pro is $15/mo and includes 50,000 calls a month with no daily limit — one key unlocks all nine Datakoot servers. Go over and you drop to free-tier speed or top up, never cut off. See full pricing →