Skip to content

Releases: zavora-ai/mcp-security-advisory

v1.1.0

24 May 10:45

Choose a tag to compare

What's New

  • HealthCheck — implements adk_mcp_sdk::HealthCheck trait for registry monitoring
  • mcp-server.toml — manifest declaring tools, risk classes, and credential bindings
  • Structured tracingtracing-subscriber with env-filter (RUST_LOG)
  • Rust edition 2024 — upgraded from 2021

Registry Compliance

This release makes the server fully compliant with the ADK MCP Registry contract.

v1.0.0 — Security Advisory MCP

24 May 02:33

Choose a tag to compare

6 MCP tools for vulnerability management. Queries OSV.dev (covers GitHub Advisory DB, RustSec, NVD).

Tools

  • search_advisories — search by package/ecosystem/keyword
  • get_advisory — full details by CVE/GHSA/RUSTSEC/OSV ID
  • map_vulnerability_to_dependency — scan lockfiles against advisories
  • rank_security_risk — weighted risk scoring (severity × exposure)
  • generate_patch_plan — upgrade path + rollout order
  • export_security_evidence — compliance/audit bundles

Verified

  • 14 advisories found for hyper on crates.io
  • Risk scoring: 5.5/10 (medium) for direct + internet-exposed
  • Patch plan: upgrade to 0.14.10

Install

cargo install mcp-security-advisory

No API key needed.