
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
Listed on
First seen 2 Oct 2026. One server, whatever directories list it: each directory listing keeps its own page and history.
1
Directories
Collected by InvokeRank
14
Tools
From an anonymous probe
-
ToolBench grade
Not graded by Arcade
-
GitHub stars
No repository data
Tools
| Tool | Description | Behaviour |
|---|---|---|
| assess_dependency | Check a single package@version for known vulnerabilities via OSV.dev (npm, PyPI, Go, Maven, NuGet, RubyGems, Packagist, crates.io, etc.). Returns advisories with CVE IDs, severity, fixed versions, and references. Free tier eligible. | Not declared |
| assess_tech_risk | Assess security risk for a list of technologies. Returns known CVEs affecting each technology with severity breakdown. Input: comma-separated technology names only. | Not declared |
| get_kev_recent | Get recently added entries to the CISA Known Exploited Vulnerabilities (KEV) catalog. | Not declared |
| get_my_posture | Get Shield WAF posture score and breakdown for a domain registered under this account. Returns 0-100 score, letter grade, per-component breakdown (origin lock, virtual patching, TLS, etc.), and edge_health (whether Shield is actually intercepting traffic). Requires API key. | Not declared |
| get_scan | Get a scan with all its findings (full detail: title, description, evidence, remediation, CVSS). Requires API key. | Not declared |
| get_threat_stats | Get statistics about the Sectora threat intelligence database including counts of EPSS scores, KEV entries, Nuclei templates, and exploits. No input required. | Not declared |
| get_trending_cves | Get currently trending CVEs based on recent KEV additions, high EPSS scores, and exploit availability. | Not declared |
| get_weaponization_score | Get the weaponization score (0-100) for a CVE. Factors in EPSS, KEV status, exploit availability, Nuclei templates, and CVSS. Input must be a valid CVE ID. | Not declared |
| list_my_findings | List the API key owner's open security findings across all scans. Use this to answer "what's my current exposure?" Filter by severity, status, or domain. Returns finding summaries; call get_scan for full detail. Requires API key. | Not declared |
| list_my_scans | List the API key owner's recent scans with summary counts. Requires API key. | Not declared |
| lookup_cve | Get full threat intelligence enrichment for a CVE including EPSS score, CISA KEV status, public exploits, Nuclei templates, risk level, and risk factors. Input must be a valid CVE ID. | Not declared |
| lookup_ip_reputation | Look up community IP reputation from Sectora Shield WAF network. Shows if an IP has been reported for attacks. Accepts IPv4 or IPv6 (the Shield network sees both). | Not declared |
| scan_url | Kick off a DAST security scan against a public URL the API key owner controls. Two-step flow: first call returns a preview (target, profile, ETA, quota remaining); confirm by calling again with confirm:true to actually start the scan. Returns scan_id; poll status with get_scan. Domain must be verified in the Sectora account. Daily quota: 25 scans/24h per user, plus the plan's monthly scan limit. Requires an API key with the scans:create scope. | Not declared |
| search_cves | Search for CVEs by keyword, severity, or other filters. Query must be alphanumeric text. | Not declared |
| Directory | Listing | Tier | First seen |
|---|---|---|---|
| Official MCP Registry | io.github.megabrainee/sectora | - | 2 Oct 2026 |