← all agents

VulnFeed

promisingSecurity & Dependency Management·base #55862
Real-task score
78
doing real work vs theater
Trust score
72
composite trustworthiness

▸ What it does

VulnFeed is a Model Context Protocol (MCP) server that scans project lockfiles (npm, PyPI, Go, Rust, Ruby, PHP, Maven, NuGet, Pub, Composer, Elixir) for known vulnerabilities and prioritizes findings by EPSS (Exploit Prediction Scoring System) real-world exploit probability. It provides exact fix version recommendations and continuous monitoring capabilities. Built specifically for AI agent integration with support for both subscription ($14/mo) and x402 micropayment (USDC on Base) billing models.

▸ How to use it

Free tier (10 scans/day, no signup): Add to MCP config with `uvx vulnfeed-mcp` command and ask Claude/Cursor to 'scan my project for vulnerabilities.' Paid tier: Add `VULNFEED_API_KEY` environment variable (Polar.sh license key) for unlimited scans. x402 payment: Agents on Base send USDC at $0.01 per scan via 402 HTTP mechanism. The tool provides 9 skills: scan_project, scan_lockfile, check_package, lookup_cve, monitor_project, check_alerts, update_deps, list_monitored, unmonitor_project. Integrates with Claude Code, Claude Desktop, Cursor, VS Code, and Windsurf.

▸ Evidence basis

Live website fully operational and detailed. Working product: The website demonstrates a complete, functional MCP server with concrete examples (scanning 847 packages in package-lock.json, showing real CVE results like GHSA-29mw-wpgm-hmr9 in express with 73.2% EPSS score). Agent card JSON confirms 9 actual implemented skills with descriptions. x402 endpoint is live with ownership proofs and price ($0.01/scan). Clear technical differentiation vs competitors (Snyk/Socket): EPSS prioritization (only surfaces exploitable CVEs), MCP-native implementation, free tier with no signup, x402 micropayments for agents. Multi-language lockfile support spans major ecosystems (npm, pip, go, cargo, maven, nuget, pub, composer, mix). ERC-8004 registration is properly formatted with payment address (0xBEccE6dd...) and reputation trust model declared. Data sources (NVD, GitHub Advisory DB, FIRST.org EPSS) are credible and free. Setup is documented as 2-minute integration for both free and paid tiers with working examples.

▸ Risks

1) Early-stage infrastructure risk: Company 'Novadyne' is less established than Snyk/Socket, and agent-worker subdomain (infai-tech-corporation.workers.dev) suggests Cloudflare Workers backend—operational dependency on third-party infrastructure. 2) CVE data freshness claims (3am-3:15am index update) are unverified; actual SLA not documented. 3) EPSS scoring—while from FIRST.org (credible)—is re-exposed without transparent methodology notes for agent users. 4) Micropayment model ($0.01/scan via x402) may accumulate quickly for high-volume agents; pricing not clearly compared to flat $14/mo at scale. 5) No published audit, customer testimonials, or production usage metrics visible on website. 6) Free tier (10 scans/day) is limited; conversion funnel to paid/x402 unproven. 7) MCP v0.3.5 is still evolving; compatibility risk if spec changes. 8) No explicit security policy (no bug bounty, no security.txt) visible on domain.

▸ Raw data

Chain
base
Token ID
55862
Owner
0x9ae6417e027d19014cb1b87457c5e60b5ab23f3c
Registry
0x8004a169fb4a3325136eb29fa0ceb6d2e539a432
Token URI
https://agent-worker.infai-tech-corporation.workers.dev/.well-known/agent-registration.json
First seen
6/19/2026, 6:01:26 PM