VS Code extension for dependency CVE scanning
github.com·21h·
Discuss: r/devops
Flag this post

VulScan-MCP

Security vulnerability scanner for VS Code

Automatically scan your project dependencies for CVEs and get step-by-step remediation instructions - all powered by the Model Context Protocol (MCP).


What Is This?

VulScan-MCP is a VS Code extension that:

  • 🔍 Scans your dependencies for security vulnerabilities (CVEs only)
  • 🌐 Fetches real-time data from NVD (National Vulnerability Database) and OSV (Open Source Vulnerabilities)
  • 📋 Provides clear, step-by-step fix instructions
  • ⚠️ Important: This tool finds security vulnerabilities - it does NOT check for deprecated packages, outdated versions, or general package health
  • 🛡️ Never auto-applies fixes - always guides you safely
  • 🖥️ Works on Windows, macOS, and Linux

Just ask Copilot *“Check for …

Similar Posts

Loading similar posts...