CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
pipeworx-io avatar

nvd

pipeworx-io/mcp-nvd
HTTPregistry active
Summary

Wraps the NIST National Vulnerability Database API so you can query CVE records, security vulnerabilities, and vendor advisories directly from your AI workflow. No authentication required. Part of the Pipeworx gateway ecosystem, which means you can either connect to this specific NVD endpoint or use the full gateway to access 250+ data sources through a single connection. Includes an ask_pipeworx tool that lets you ask questions in plain English rather than calling structured APIs directly. Useful when you're doing security research, tracking CVEs in your dependencies, or need to pull vulnerability data into documentation or incident reports without leaving your editor.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

NVD — National Vulnerability Database

NIST's National Vulnerability Database. Every CVE (Common Vulnerabilities and Exposures) ever published — software vulnerabilities, severity scores (CVSS), affected products (CPEs), references. The authoritative source for "is this software version vulnerable?" Free, no auth (light rate limit; key recommended).

Part of Pipeworx — an MCP gateway connecting AI agents to 1476+ live data sources.

Why this matters for AI agents

For security analysis, supply-chain risk assessment, or "what CVEs affect dependency X?" the NVD is the source. Where commercial vulnerability databases add curation, the NVD is the raw federal record. Pair with USPTO patents for security IP, SEC EDGAR for breach disclosures.

Common flows:

  • CVE lookup. Find specific CVE by ID for full record.
  • Search by product / version. "What CVEs affect Apache Log4j 2.x?" → keyword + CPE filter.
  • Recent CVEs by severity. Critical and high-severity disclosures published recently.
  • CVSS scoring. Each CVE has CVSS v2, v3.0, and v3.1 scores; agents should use v3.x for current analysis.

Auth

NVD's REST API is free; an unauthenticated client gets ~5 requests per 30s. Get a free API key at https://nvd.nist.gov/developers/request-an-api-key for ~50 requests per 30s. Pass via _apiKey.

Severity classes (CVSS v3)

ScoreClass
0.1–3.9Low
4.0–6.9Medium
7.0–8.9High
9.0–10.0Critical

For agent triage, "High and Critical, last 90 days" is the common attention slice.

Common pitfalls

  • CPE matching is fiddly. CPE (Common Platform Enumeration) is the controlled vocabulary for "this CVE affects this product version." Software names in CPE often differ from how marketing names them. Use NVD's CPE search to find the right CPE before searching CVEs.
  • CVE coverage isn't complete. Some bugs are quietly patched without CVE assignment. Conversely, not every CVE is exploitable in practice. Triage by environment.
  • Severity scoring is not exploitability. A Critical CVSS score on a feature you don't use is irrelevant; a Medium CVSS on something exposed to the internet is worse than the score implies. Pair with EPSS (Exploit Prediction Scoring System) when available.
  • Reserved vs published. Reserved CVEs ("RESERVED") are placeholders awaiting public disclosure. The actual content lives in description once published. Filter vulnStatus for what's actually known.
  • References lag. Patches and exploit-detection signatures often appear before the NVD record updates. For real-time vulnerability response, layer GitHub Security Advisories or vendor channels on top.
  • Modified vs published date. The "modified" date often reflects re-scoring or reference updates, not new findings. For "what was disclosed this week," sort by publishedDate.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "nvd": {
      "url": "https://gateway.pipeworx.io/nvd/mcp"
    }
  }
}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/nvd/mcp returns the tools in the table above plus the shared Pipeworx meta-tools — ask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover — via ask_pipeworx, which routes across the whole catalog — without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Both URLs reach the same gateway and the same 1476+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:

ask_pipeworx({ question: "your question about Nvd data" })

The gateway picks the right tool and fills the arguments automatically.

More

  • Docs and guides
  • pipeworx.io

License

MIT

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Categories
DatabasesSecurity & Pentesting
Registryactive
TransportHTTP
UpdatedApr 3, 2026
View on GitHub

More from pipeworx-io

  • Odds Api
  • Omdb
  • openalex
  • Opendosm My
  • Owid
  • Paperswithcode
  • Paypal
  • Permid
  • puumed
  • Quickbooks
  • Rdap
  • Rebrickable
  • Reddit
  • Rfc Editor
  • rickmorty
  • Roblox
  • Rss2json
  • Rxnorm
  • spacenews
  • Sports
  • Stripe_connect
  • swapi
  • swisstransport
  • tle

Related Databases MCP Servers

View all →
pipeworx-io avatar
Opencellid

io.github.pipeworx-io/opencellid

OpenCellID MCP — cell tower geolocation database (free with key)
pipeworx-io avatar
Openchargemap

io.github.pipeworx-io/openchargemap

Open Charge Map MCP — global EV charging station database (openchargemap.io).
pipeworx-io avatar
Openfoodfacts

io.github.pipeworx-io/openfoodfacts

Open Food Facts — collaborative food product database
pipeworx-io avatar
Osv Dev

io.github.pipeworx-io/osv-dev

OSV.dev — Google's open-source vulnerability database
pipeworx-io avatar
Overpass

io.github.pipeworx-io/overpass

OpenStreetMap Overpass MCP — programmatic queries against the OSM database
pipeworx-io avatar
Paleobiodb

io.github.pipeworx-io/paleobiodb

Paleobiology Database (PBDB) MCP — the global fossil record. Keyless.