debsecan-mcp
Debian Security Analyzer MCP Server
Decision gist · record as of 2026-08-14
Yes, if you run Debian and want to integrate vulnerability scanning into an AI assistant or CLI workflow. The package is actively maintained, has low install friction, and no known vulnerabilities. However, note that this is the final release under the debsecan-mcp name—migrate to the renamed debvulns package for future updates.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11+, a Debian-based distribution, and network access to download vulnerability data from Debian Security Tracker and CISA.
- Low friction install with six runtime dependencies.
- Active maintenance as of 33 days ago.
License · maintenance · safety
(unclear)
last release 2026-07-12 (33 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 119,210 downloads/mo, #12,082 on PyPI
Alternatives
Verify before relying
# Install
pip install debsecan-mcp
# Run MCP server (default stdio mode)
debsecan-mcp
# Or use the CLI tool
debvulns --severity high --format json- Whether the package works on non-Debian systems or only Debian-based distributions
- Performance characteristics when scanning systems with large numbers of installed packages
- Whether cached vulnerability data persists across system reboots or requires re-download
What it is and what it does
debsecan-mcp is a Model Context Protocol server that integrates vulnerability scanning into AI assistants and development tools. It discovers installed packages on a Debian system, fetches vulnerability data from the Debian Security Tracker, and enriches the results with EPSS (Exploit Prediction Scoring System) scores from CISA to help prioritize which vulnerabilities pose the greatest risk. The package runs as an MCP server over stdio, SSE, or HTTP transports, making it usable with Claude Desktop, VSCode, or other MCP-compatible clients.
The package also includes a standalone CLI tool called debvulns for command-line vulnerability scanning without running the server. It caches downloaded vulnerability and EPSS data locally (with automatic refresh after 24 hours) and supports filtering by severity, custom output formats (JSON or CSV), and sorting options. However, this package has been renamed to debvulns as of version 0.1.5, which is the final release under the debsecan-mcp name.
Use it for
- Integrate vulnerability scanning into Claude Desktop or VSCode to get real-time security alerts for installed packages
- Run debvulns CLI to generate a CSV report of high-severity vulnerabilities on a Debian system for compliance auditing
- Query specific CVEs via the research_cves tool to get EPSS scores and exploitability details before patching decisions
- Set up an HTTP-based MCP server to expose Debian security scanning to remote AI assistants in containerized environments
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you run Debian and want to integrate vulnerability scanning into an AI assistant or CLI workflow.
The package is actively maintained, has low install friction, and no known vulnerabilities. However, note that this is the final release under the debsecan-mcp name—migrate to the renamed debvulns package for future updates.
Install
debsecan-mcp on PyPI
Before you install
Low friction install with six runtime dependencies. Active maintenance as of 33 days ago. Note: this package has been renamed to debvulns; version 0.1.5 is the final release under the debsecan-mcp name.
Requires Python 3.11+, a Debian-based distribution, and network access to download vulnerability data from Debian Security Tracker and CISA.
Quickstart
# Install
pip install debsecan-mcp
# Run MCP server (default stdio mode)
debsecan-mcp
# Or use the CLI tool
debvulns --severity high --format json
Verify before relying
- Whether the package works on non-Debian systems or only Debian-based distributions
- Performance characteristics when scanning systems with large numbers of installed packages
- Whether cached vulnerability data persists across system reboots or requires re-download
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packageshttpxmcppydanticpython-debianpython-dotenvruff |
| Maintenance | Actively maintained 33 days since the last release |
| First released | |
| Downloads | 119,210 / month, #12,082 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: debsecan_mcp-0.1.5-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “debian vulnerability scanner”
- debsecan-mcpAn MCP server that scans Debian systems for known security…
- python-gvmPython library that abstracts the Greenbone Management Protocol (GMP)…
- pip-auditpip-audit scans Python environments and requirements files for…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also postgres-mcp · excel-mcp-server · cisco-ai-mcp-scanner · snowflake-labs-mcp · cvss · arcade-mcp-server · mcp-server-odoo · ca9 · uv-secure · cwe2