VulnFeed
▸ What it does
VulnFeed is a Model Context Protocol (MCP) server that scans project lockfiles (npm, PyPI, Go, Rust, Ruby, PHP, Maven, NuGet, Pub, Composer, Elixir) for known vulnerabilities and prioritizes findings by EPSS (Exploit Prediction Scoring System) real-world exploit probability. It provides exact fix version recommendations and continuous monitoring capabilities. Built specifically for AI agent integration with support for both subscription ($14/mo) and x402 micropayment (USDC on Base) billing models.
▸ How to use it
Free tier (10 scans/day, no signup): Add to MCP config with `uvx vulnfeed-mcp` command and ask Claude/Cursor to 'scan my project for vulnerabilities.' Paid tier: Add `VULNFEED_API_KEY` environment variable (Polar.sh license key) for unlimited scans. x402 payment: Agents on Base send USDC at $0.01 per scan via 402 HTTP mechanism. The tool provides 9 skills: scan_project, scan_lockfile, check_package, lookup_cve, monitor_project, check_alerts, update_deps, list_monitored, unmonitor_project. Integrates with Claude Code, Claude Desktop, Cursor, VS Code, and Windsurf.
▸ Evidence basis
Live website fully operational and detailed. Working product: The website demonstrates a complete, functional MCP server with concrete examples (scanning 847 packages in package-lock.json, showing real CVE results like GHSA-29mw-wpgm-hmr9 in express with 73.2% EPSS score). Agent card JSON confirms 9 actual implemented skills with descriptions. x402 endpoint is live with ownership proofs and price ($0.01/scan). Clear technical differentiation vs competitors (Snyk/Socket): EPSS prioritization (only surfaces exploitable CVEs), MCP-native implementation, free tier with no signup, x402 micropayments for agents. Multi-language lockfile support spans major ecosystems (npm, pip, go, cargo, maven, nuget, pub, composer, mix). ERC-8004 registration is properly formatted with payment address (0xBEccE6dd...) and reputation trust model declared. Data sources (NVD, GitHub Advisory DB, FIRST.org EPSS) are credible and free. Setup is documented as 2-minute integration for both free and paid tiers with working examples.
▸ Risks
1) Early-stage infrastructure risk: Company 'Novadyne' is less established than Snyk/Socket, and agent-worker subdomain (infai-tech-corporation.workers.dev) suggests Cloudflare Workers backend—operational dependency on third-party infrastructure. 2) CVE data freshness claims (3am-3:15am index update) are unverified; actual SLA not documented. 3) EPSS scoring—while from FIRST.org (credible)—is re-exposed without transparent methodology notes for agent users. 4) Micropayment model ($0.01/scan via x402) may accumulate quickly for high-volume agents; pricing not clearly compared to flat $14/mo at scale. 5) No published audit, customer testimonials, or production usage metrics visible on website. 6) Free tier (10 scans/day) is limited; conversion funnel to paid/x402 unproven. 7) MCP v0.3.5 is still evolving; compatibility risk if spec changes. 8) No explicit security policy (no bug bounty, no security.txt) visible on domain.
▸ Raw data
- Chain
- base
- Token ID
- 55862
- Token URI
- https://agent-worker.infai-tech-corporation.workers.dev/.well-known/agent-registration.json
- First seen
- 6/19/2026, 6:01:26 PM