什么是 Environmental Compliance?
整合 EPA 空气质量监测与 HUD 法拍房数据,提供 3 个 MCP 工具用于环境和住房数据查询。
README
Cybersecurity Vulnerability Intelligence MCP Server
Unified vulnerability intelligence from 4 government data sources in a single MCP server. Get enriched CVE lookups with CVSS scores, active exploitation status, exploitation probability, and ATT&CK techniques in one call.
| Source | What It Provides | Update Frequency |
|---|---|---|
| NIST NVD 2.0 | CVE details, CVSS scores, descriptions, references, CWE classifications | Continuous |
| CISA KEV | Actively exploited vulnerabilities catalog, remediation deadlines | Daily |
| FIRST.org EPSS | Exploitation probability scores (0-1) predicting likelihood of exploitation in next 30 days | Daily |
| MITRE ATT&CK | Adversary techniques mapped to CVEs | Quarterly |
Tools
vuln_lookup_cve — Enriched CVE Lookup
The killer feature. Look up any CVE and get intelligence from all 4 sources in a single call.
- Input:
{ cveId: "CVE-2021-44228" } - Returns: NVD details + CVSS score + KEV exploitation status + EPSS probability + ATT&CK techniques
vuln_search — Search CVEs
Search the NVD by keyword, severity, and date range. Optionally filter to only actively exploited (KEV) vulnerabilities.
- Input:
{ keyword: "apache log4j", severity: "CRITICAL", hasKev: true, limit: 20 }
vuln_kev_latest — Recently Exploited Vulnerabilities
Get vulnerabilities recently added to CISA's Known Exploited Vulnerabilities catalog.
- Input:
{ days: 7, limit: 20 }
vuln_kev_due_soon — Upcoming Remediation Deadlines
Get KEV entries with remediation deadlines approaching. Critical for federal compliance.
- Input:
{ days: 14, limit: 20 }
vuln_epss_top — Highest Exploitation Probability
Get CVEs most likely to be exploited in the next 30 days based on EPSS machine learning model.
- Input:
{ threshold: 0.7, limit: 20 }
vuln_trending — Newly Published Critical CVEs
Get recently published high/critical severity CVEs from the NVD.
- Input:
{ days: 3, severity: "CRITICAL", limit: 20 }
vuln_by_vendor — Vendor Vulnerability Assessment
Search CVEs for a specific vendor/product. Cross-references with CISA KEV to flag actively exploited issues.
- Input:
{ vendor: "microsoft", product: "windows", limit: 20 }
Use Cases
- Vulnerability triage: Look up a CVE and instantly know if it's actively exploited, its EPSS score, and what ATT&CK techniques apply
- Patch prioritization: Combine KEV status + EPSS scores to prioritize remediation
- Compliance tracking: Monitor upcoming CISA KEV remediation deadlines
- Threat intelligence: Track trending CVEs and newly weaponized vulnerabilities
- Vendor risk assessment: Assess a vendor's vulnerability exposure and active exploitation status
Quick Start
Glama (hosted)
Install from Glama.ai.
Apify (hosted)
{
"mcpServers": {
"cybersecurity": {
"url": "https://cybersecurity-vuln-mcp.apify.actor/mcp"
}
}
}
Claude Desktop / Claude Code
{
"mcpServers": {
"cybersecurity": {
"command": "node",
"args": ["path/to/servers/cybersecurity-vuln-mcp/dist/stdio.js"],
"env": {
"NVD_API_KEY": "your-key-here"
}
}
}
}
Local (stdio)
git clone https://github.com/martc03/gov-mcp-servers.git
cd gov-mcp-servers/servers/cybersecurity-vuln-mcp
npm install && npm run build
node dist/stdio.js
Environment Variables
| Variable | Required | Description |
|---|---|---|
NVD_API_KEY | No | NVD API key for higher rate limits (50 req/30s vs 5 req/30s). Register here. |
Caching
| Data Source | TTL | Notes |
|---|---|---|
| NVD CVE lookups | 1 hour | Per-CVE |
| CISA KEV catalog | 2 hours | Full catalog |
| EPSS scores | 24 hours | Per-CVE |
| ATT&CK mappings | Static | Bundled with server |
Architecture
- Protocol: MCP over stdio (Glama/local) or Streamable HTTP (Apify)
- Runtime: Node.js 18+, TypeScript
- Data: Direct API calls to free government data sources, zero cost
- Caching: In-memory with configurable TTLs
Other Servers in This Repo
This repository contains 13 MCP servers for US government data. See each server's README for details.
| Server | Tools | Data Sources |
|---|---|---|
| us-safety-recalls-mcp | 4 | NHTSA recalls, FDA recalls |
| natural-disaster-intel-mcp | 4 | FEMA disasters, NOAA weather, USGS earthquakes |
| federal-financial-intel-mcp | 4 | SEC EDGAR, CFPB complaints, BLS employment |
| immigration-travel-mcp | 3 | Visa bulletins, border wait times |
| environmental-compliance-mcp | 3 | EPA air quality, HUD foreclosures |
| gov-contracts-mcp | 4 | SAM.gov contracts, USAspending |
| court-records-mcp | 4 | PACER, federal court records |
| public-health-mcp | 4 | NIH clinical trials, FDA adverse events |
| business-entity-mcp | 4 | SEC company search, SBA resources |
| regulatory-monitor-mcp | 4 | Federal Register, regulations.gov |
| grant-finder-mcp | 4 | Grants.gov, USAspending |
| competitive-intel-mcp | 4 | SEC filings, patent data, trade data |
A REST API gateway with 45 endpoints is also available at govdata-api.netlify.app.
Attribution
- NVD: This product uses data from the NVD API but is not endorsed or certified by the NVD.
- EPSS: Data provided by FIRST.org (https://www.first.org/epss/).
- ATT&CK: Registered trademark of The MITRE Corporation. Licensed under Apache 2.0.
- KEV: CISA Known Exploited Vulnerabilities Catalog, US Government public domain.
Custom MCP Server Development
Need a custom MCP server for your business? Visit mcpdev.netlify.app or email codee.mcpdev@gmail.com.
License
MIT
常见问题
Environmental Compliance 是什么?
整合 EPA 空气质量监测与 HUD 法拍房数据,提供 3 个 MCP 工具用于环境和住房数据查询。
相关 Skills
环境密钥管理
by alirezarezvani
统一梳理dev/staging/prod的.env和密钥流程,自动生成.env.example、校验必填变量、扫描Git历史泄漏,并联动Vault、AWS SSM、1Password、Doppler完成轮换。
✎ 统一管理环境变量、密钥与配置,减少泄露和部署混乱,安全治理与团队协作一起做好,DevOps 场景很省心。
可观测性设计
by alirezarezvani
面向生产系统规划可落地的可观测性体系,串起指标、日志、链路追踪与 SLI/SLO、错误预算、告警和仪表盘设计,适合搭建监控平台与优化故障响应。
✎ 把监控、日志、链路追踪串起来,帮助团队从设计阶段构建可观测性,排障更快、系统演进更稳。
更新日志
by alirezarezvani
基于 Conventional Commits 自动解析提交记录、判断语义化版本升级并生成规范 changelog,适合在 CI、发版前检查提交格式并批量输出可审计发布说明。
✎ 自动生成和管理更新日志与发布说明,帮团队把版本变更说清楚;聚焦版本化与流程自动化,省时又更规范。
相关 MCP Server
kubefwd
编辑精选by txn2
kubefwd 是让 AI 帮你批量转发 Kubernetes 服务到本地的开发神器。
✎ 微服务开发者最头疼的本地调试问题,它一键搞定——自动分配 IP 避免端口冲突,还能用自然语言查询状态。但依赖 AI 工作流,纯命令行爱好者可能觉得不够直接。
Cloudflare
编辑精选by Cloudflare
Cloudflare MCP Server 是让你用自然语言管理 Workers、KV 和 R2 等云资源的工具。
✎ 这个工具解决了开发者频繁切换控制台和文档的痛点,特别适合那些在 Cloudflare 上部署无服务器应用、需要快速调试或管理配置的团队。不过,由于它依赖多个子服务器,初次设置可能有点繁琐,建议先从 Workers Bindings 这类核心功能入手。
Terraform
编辑精选by hashicorp
Terraform MCP Server 是让 AI 助手直接操作 Terraform Registry 和 HCP Terraform 的桥梁。
✎ 如果你经常在 Terraform 里翻文档找模块配置,这个服务器能省不少时间——直接问 Claude 就能生成准确的代码片段。最适合管理多云基础设施的团队,但注意它目前只适合本地使用,别在生产环境里暴露 HTTP 端点。