Skip to main content
ClaudeWave
stevologic avatar
stevologic

security-recipes.ai

View on GitHub

Turn security findings into bounded agent work: one recipe, scoped context, required proof, and a human-reviewed result.

MCP ServersOfficial Registry1 stars0 forksPythonApache-2.0Updated today
ClaudeWave Trust Score
87/100
Trusted
Passed
  • Open-source license (Apache-2.0)
  • Actively maintained (<30d)
  • Clear description
  • Documented (README)
Last scanned: 8/27/2026
Install in Claude Code / Claude Desktop
Method: UVX (Python) · security-recipes.ai
Claude Code CLI
claude mcp add security-recipes-ai -- uvx security-recipes.ai
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "security-recipes-ai": {
      "command": "uvx",
      "args": ["security-recipes.ai"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Package name inferred from the repository name. Verify it exists on PyPI, or clone https://github.com/stevologic/security-recipes.ai and follow its README.
Use cases

MCP Servers overview

<div align="center">

<img src=".github/readme/hero.svg" alt="security-recipes.ai — Search CVEs. Remediate vulnerabilities with AI agents. Sourced NVD + CISA KEV intelligence, evidence-gated canonical records, and bounded remediation plans." width="100%" />

[![Live site](https://img.shields.io/badge/Live-security--recipes.ai-2dd4bf.svg?style=flat-square&labelColor=020506)](https://security-recipes.ai/)
[![CVE Database](https://img.shields.io/badge/CVE_Database-260k%2B_records-2dd4bf.svg?style=flat-square&labelColor=020506)](https://security-recipes.ai/cve-database/)
[![MCP server](https://img.shields.io/badge/MCP-%2Fmcp-5eead4.svg?style=flat-square&labelColor=020506)](https://security-recipes.ai/mcp-servers/)
[![Security health action](https://img.shields.io/badge/CI-Security_Health_Action-5eead4.svg?style=flat-square&labelColor=020506)](https://security-recipes.ai/docs/security-health-action/)
[![llms.txt](https://img.shields.io/badge/agents-llms.txt-67e8f9.svg?style=flat-square&labelColor=020506)](https://security-recipes.ai/llms.txt)

</div>

# security-recipes.ai

**Search CVEs. Remediate vulnerabilities with AI agents.** Sourced facts stay
sourced, remediation stays bounded, and every plan carries verification,
rollback, and stop conditions — the live site's contract, and this repo's.

[security-recipes.ai](https://security-recipes.ai/) is an Eleventy site for
sourced CVE intelligence and evidence-gated vulnerability remediation that AI
agents can consume without inheriting deployment or production authority.

The project is intentionally narrow:

- a complete rolling Medium/High/Critical CVE database,
- evidence-qualified canonical CVE remediation records,
- practical security remediation recipes,
- prompt and rules-file examples,
- agent setup guides,
- MCP integration patterns,
- an optional read-only MCP server for recipe search and approved upstream MCP
  context,
- a [reusable GitHub Action](https://security-recipes.ai/docs/security-health-action/)
  that turns this guidance into toggleable CI health checks.

It is not a scanner, ticketing system, SOAR platform, deployment tool, or custom
security toolkit. Existing security tools should produce the findings; this
site helps agents use the right remediation context and stop at the right time.

Start with the live [CVE Database](https://security-recipes.ai/cve-database/)
for an exact vulnerability or the
[AI Vulnerability Remediation Playbooks](https://security-recipes.ai/security-remediation/)
for the evidence-to-patch workflow. Agent-specific guides cover
[Codex](https://security-recipes.ai/codex/),
[Claude Code](https://security-recipes.ai/claude/),
[Cursor](https://security-recipes.ai/cursor/),
[GitHub Copilot](https://security-recipes.ai/github_copilot/),
[Devin](https://security-recipes.ai/devin/),
[Shiba Studio](https://security-recipes.ai/agents/#shiba-studio),
[Hermes Desktop](https://security-recipes.ai/agents/#hermes-desktop), and
[OpenClaw](https://security-recipes.ai/agents/#openclaw).
The [Visual Guide](https://security-recipes.ai/how-to-use/) shows the complete
path from source qualification and search discovery to a bounded plan, proof,
rollback, and human review.
For the distinct problem of securing an agent system's identities, tools,
connectors, context, memory, runtime, and recovery controls, use
[AI Agent Security](https://security-recipes.ai/agentic-security/).

## Current product and workflow

![Security Recipes CVE database and AI vulnerability remediation interface](static/images/og-card.png)

### Qualified search discovery

![A source catalog passes an evidence gate before a canonical CVE page reaches search discovery and a reviewed remediation workflow](static/images/how-to-use/canonical-cve-search-discovery.webp)

The complete catalog remains searchable, while public canonical CVE pages stay
limited to reviewed or evidence-qualified records. Those pages ship unique
search metadata, server-rendered core facts and affected-version evidence, one
remediation authority (stable reviewed guidance first, otherwise complete
source-linked AI enrichment), a short approval-gated AI implementation prompt,
canonical URLs, breadcrumbs, and `Article`/`TechArticle` structured data. The CVE database
describes the catalog as a `Dataset`; the remediation pillar exposes its visible
seven-step workflow as a `HowTo`. Year-partitioned CVE sitemaps contain only
indexable canonical routes, and the build fails when sitemap parity, canonical
ownership, crawl reachability, metadata limits, or same-origin links drift.

Indexability is also withheld from mass-templated recipe children. The 72
development code-hygiene recipes and 39 generated compliance-framework recipes
remain browsable from their canonical hubs with `noindex,follow` while they
share a common method. A bounded rendered-body similarity gate prevents a child
from re-entering sitemaps until its evidence, examples, and tests are materially
distinct. The hubs remain indexable and carry the shared discovery context.

After an SEO-bearing release, the public revision must match the merge commit
before sitemap submission or URL inspection. The
[Caddy deployment guide](README.caddy-deploy.md#search-discovery-after-an-seo-release)
documents the DNS-verified Search Console handoff, priority live-URL checks,
sitemap submission, indexing requests, and query monitoring. Submission is a
discovery hint; it does not guarantee indexing or a particular ranking.

The remediation pillar also records a public repository example for
[CVE-2026-13149 in `brace-expansion`](https://security-recipes.ai/security-remediation/#real-repository-case-study-cve-2026-13149-in-brace-expansion).
It ties the dependency-only change to the
[reviewed pull request](https://github.com/stevologic/security-recipes.ai/pull/89),
tests, advisory evidence, and recovery path while explicitly separating the
same PR's unrelated Fail2Ban work.

| CVE search to canonical record | CVE evidence to bounded agent plan |
| --- | --- |
| ![CVE search, affected surface, evidence, and canonical remediation record](static/images/how-to-use/cve-search-to-record.webp) | ![Seven-phase CVE remediation plan inside a review gate](static/images/how-to-use/cve-to-agent-plan.webp) |
| Proof and human review | Read-only MCP context |
| ![Scope, change, tests, evidence, rollback, and human review](static/images/how-to-use/proof-and-review.webp) | ![Read-only MCP context with write access behind explicit approval](static/images/how-to-use/read-only-mcp-context.webp) |

## What this project is for

AI coding agents can help close security findings when their work is bounded:
one finding, one recipe, one reviewed output.

security-recipes.ai helps teams answer:

- Which recipe matches this finding?
- Which prompt should the agent use?
- Where do I put the instructions for Copilot, Claude, Cursor, Codex, or Devin?
- Which MCP servers should the agent read for advisory, scanner, repository, or
  runbook context?
- What should the PR or triage note include before a reviewer trusts it?

## What ships

- Eleventy documentation site (fast static builds, no Go toolchain).
- CVE-first observatory home page and data-first CVE database.
- Recipe hubs for dependency, SAST, sensitive-data, base-image, CVE, and
  default-hardening remediation.
- CVE intelligence intake policy, prompt, fixtures, and evaluator for routing
  advisory signals before an agent patches.
- A complete rolling ten-year Medium/High/Critical CVE catalog composed from
  integrity-verified NVD JSON 2.0 feeds, CISA KEV metadata, and every applicable
  vetted remediation archetype. Only reviewed `stable` Markdown pages override
  that conservative baseline.
- An integrity-hashed search allowlist that publishes canonical CVE pages only
  for reviewed stable Markdown or AI enrichment that passes the deterministic
  recipe-ready evidence contract. The full database remains searchable even
  when a record is not eligible for search indexing.
- A versioned seven-phase agentic change contract for every catalog CVE:
  discover, assess, mitigate, remediate, verify, rollback, and triage. Each
  action declares likely file targets, mutation and approval boundaries,
  required evidence, outputs, and failure behavior without guessing a patch or
  fixed version.
- A structured compliance library spanning 39 security, privacy, assurance,
  resilience, and software-supply-chain frameworks without reproducing
  licensed control text. Its framework hub is the search surface; templated
  child assessments remain `noindex,follow` until differentiated.
- A 72-recipe code-hygiene library covering cross-language and ecosystem-
  specific audit, remediation, verification, and stop-condition workflows.
  Its development children remain `noindex,follow` while their bodies share a
  generated template.
- Recipes with existing prompt collections preserved.
- Agent setup guides for GitHub Copilot, Claude, Cursor, Codex, and Devin.
- MCP integration guidance for public and organization-approved security data
  sources.
- Optional read-only FastMCP server in `mcp_server.py` for recipe search,
  retrieval, and opt-in upstream MCP context.
- Docker and Docker Compose configuration for local or droplet hosting.
- Helper scripts for site maintenance, validation, imports, and deployment.

## Repository map

| Path | Purpose |
| --- | --- |
| `content/` | Recipes, documentation, remediation guides, and agent setup pages. |
| `eleventy.config.js` | Site build configuration (permalinks, feeds, tag pages). |
| `_includes/` | Page layouts: docs chrome and the standalone home page. |
| `lib/` | Build modules: shortcode ports, JSON feed builders, SEO head. |
| `assets/` | Site CSS and JavaScript for the recipe browser, navigation, and helper tools. |
| `static/` | Images, logos, schemas, and static assets. |
| `static/api/cve-catalog/` | Complete sharded CVE catalog, year-partitioned machine index, compressed browser-search index, provenance manife

What people ask about security-recipes.ai

What is stevologic/security-recipes.ai?

+

stevologic/security-recipes.ai is mcp servers for the Claude AI ecosystem. Turn security findings into bounded agent work: one recipe, scoped context, required proof, and a human-reviewed result. It has 1 GitHub stars and its last recorded update is dated 2026-08-27.

How do I install security-recipes.ai?

+

You can install security-recipes.ai by cloning the repository (https://github.com/stevologic/security-recipes.ai) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is stevologic/security-recipes.ai safe to use?

+

Our security agent has analyzed stevologic/security-recipes.ai and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains stevologic/security-recipes.ai?

+

stevologic/security-recipes.ai is maintained by stevologic. The last recorded GitHub activity is dated 2026-08-27, with 2 open issues.

Are there alternatives to security-recipes.ai?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy security-recipes.ai to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: stevologic/security-recipes.ai
[![Featured on ClaudeWave](https://claudewave.com/api/badge/stevologic-security-recipes-ai)](https://claudewave.com/repo/stevologic-security-recipes-ai)
<a href="https://claudewave.com/repo/stevologic-security-recipes-ai"><img src="https://claudewave.com/api/badge/stevologic-security-recipes-ai" alt="Featured on ClaudeWave: stevologic/security-recipes.ai" width="320" height="64" /></a>

More MCP Servers

security-recipes.ai alternatives