MCP Server
The BreachSpider MCP server lets AI agents such as Claude Code, Claude Desktop and Cursor check devices and look up CVEs through the BreachSpider API. It runs locally, is read only, and sends only the fields each tool needs.
Source and full setup for every client: github.com/Citedrelevance/breachspider-mcp. Package: breachspider-mcp on PyPI.
Tools
| Tool | Arguments | What it does | Key |
|---|---|---|---|
correlate_devices | assets (vendor, product, version, optional asset_id); optional filters and max_findings | CVEs for each device at its exact version, in priority order, with the fix plan, coverage and an honest assessment | trial, partner or customer |
check_changes | assets with the result_hash from an earlier call | Which devices changed since the last check, at a tenth of the cost | trial, partner or customer |
get_fix_plan | asset (one device) | Fix groups and the fix plan for one device | trial, partner or customer |
lookup_cve | cve_id | BreachSpider's record for one CVE, trimmed | trial, partner or customer |
check_windows_host | assets (os_product, edition_id, os_build, architecture, optional installed_kbs, installation_type, esu_enrolled, asset_id); optional max_findings | Windows hosts against Microsoft's own patch data. Nothing about the hosts is stored. Counts of CVEs confirmed open, cleared and needs review, the top open findings with fixed build, KB and Microsoft source, and the fix groups | partner or customer |
Without a key the server runs in demo mode on public examples. check_windows_host is not available in demo mode or with a trial key; it uses the stateless Windows check described in Windows Patch Level (v2), section 10.
Install
Requires Python 3.10 or newer. Install pipx, then the server:
# macOS
brew install pipx && pipx ensurepath
# Debian / Ubuntu
sudo apt install pipx && pipx ensurepath
# Windows (PowerShell)
py -m pip install --user pipx; py -m pipx ensurepath
# then, in a new terminal
pipx install breachspider-mcp
To run it without installing, install uv first and use uvx breachspider-mcp instead of breachspider-mcp.
Add it to Claude Code
With your key in the BREACHSPIDER_API_KEY environment variable:
claude mcp add breachspider -e BREACHSPIDER_API_KEY="$BREACHSPIDER_API_KEY" -- breachspider-mcp
Claude Code stores the key in its configuration, and claude mcp get breachspider prints it. Do not run that command while sharing your screen. Setup for Claude Desktop and Cursor is in the README.
Keys
Get a free trial key on the developers page. Partner keys, which also cover check_windows_host, are scoped individually: use "Talk to us" on the same page.
Privacy
- Only the fields each tool needs are sent: vendor, product, version and
asset_idfor device tools, and the Windows host fields forcheck_windows_host. Any other field is dropped, and identifying ones (host name, IP or MAC address, user, site, serial number) are listed in the tool output underprivacy. - An
asset_idthat contains an IP, MAC or email address, or is a domain or fully qualified host name, is replaced with a neutral id. Your own asset tags, such asPLC-LINE-2, are kept so results map back to your equipment. - The API key is read from the environment only and never appears in tool output or logs.
check_windows_hoststores nothing about the hosts at BreachSpider.
Honest results
Every result carries an assessment sentence. An unresolved device, partial coverage, a Windows host that is not resolved to a Microsoft build, or an empty list is never reported as clean, and needs review is always reported. Agents are told to repeat the assessment in their answer.