C
cve-intelligence
/query_package
query package
CVEs affecting one open-source package, by purl (pkg:npm/lodash) or ecosystem + name (Maven names are group:artifact). Returns the CVE list KEV-first with each
liveverifiedunknown~5s typical
mcpprobedcve-intelligence
$0.0020
per call
plus $0.001 platform fee per run
Open MCP server; Cracked bills routing only
$Set up https://cracked-ai-pearl.vercel.app/SKILL.md, then use Cracked to run mcp-com-cve-security-cve-intelligence /query_package for me.
Input
| Field | Type | Description |
|---|---|---|
| purl | string | Package URL, e.g. pkg:npm/lodash or pkg:maven/org.apache.logging.log4j/log4j-core |
| ecosystem | string | OSV ecosystem (npm, PyPI, Maven, Go, crates.io, Packagist, RubyGems, NuGet, …) or purl typ |
| name | string | Package name, verbatim (e.g. @babel/core, org.jenkins-ci.main:jenkins-core) |
Call it
curl
curl https://cracked-ai-pearl.vercel.app/v1/run \
-H "Authorization: Bearer ck_live_..." -H "content-type: application/json" \
-d '{"provider":"mcp-com-cve-security-cve-intelligence","endpoint":"/query_package","input":{}}'cli
npx cracked-ai run -p mcp-com-cve-security-cve-intelligence -e /query_package -i '{}'mcp
run_tool({ provider: "mcp-com-cve-security-cve-intelligence", endpoint: "/query_package", input: {} })Try it
Runs against your signed-in workspace balance. Sign in if you have not.