Pocmap
FreeNot checkedMCP-native CVE, PoC & exploit discovery toolkit (Metasploit, Nuclei, GitHub & more)
About
MCP-native CVE, PoC & exploit discovery toolkit (Metasploit, Nuclei, GitHub & more)
README
Version PyPI Docs Python License Pydantic
AI-agent-optimized CVE / PoC / exploit discovery toolkit — CLI, Python API, and MCP server.
Docs: https://zebbern.github.io/pocmap/
Features
- Multi-source PoCs — GitHub, Exploit-DB, Metasploit, Nuclei, labs, bug bounty write-ups; curated indexes first, then GitHub Search fallback for index-lag CVEs
- MCP server — 22 tools for Claude Desktop, Cursor, and other MCP clients
- CLI + CI — table/json/csv/md/sarif output, exit-code contract,
bulk --fail-onSARIF gate - Cache & offline — persistent TTL'd HTTP cache and first-class
--offlinemode - Bug bounty toolkit — Python API checklists, workflows, templates, scope (CLI
bugbountysearches write-ups only)
Install
pip install pocmap
pip install "pocmap[server]" # MCP SDK / pocmap-mcp
pip install -e ".[server,dev]" # from a clone
Python 3.10+. Optional: GITHUB_API_TOKEN, NVD_API_KEY for higher rate limits.
More: Getting started · Configuration
Quick start
pocmap lookup CVE-2021-44228
pocmap bulk cves.txt --format sarif --fail-on kev
pocmap latest --since 7d --severity critical --only-with-poc
pocmap discover "Log4j" --version 2.x
pocmap package PyPI django --version 3.2.0
pocmap doctor
pocmap lookup CVE-2021-44228 --format json
pocmap --offline lookup CVE-2021-44228
pocmap --help lists all commands. Guides: CLI reference.
MCP Server Setup
Recommended: uv on PATH, no local clone required.
--from pocmap[server] pulls the package with the MCP SDK and runs the pocmap-mcp
console script over STDIO.
{
"mcpServers": {
"pocmap": {
"command": "uvx",
"args": ["--from", "pocmap[server]", "pocmap-mcp"],
"env": {
"GITHUB_API_TOKEN": "ghp_xxxxxxxxxxxx",
"NVD_API_KEY": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
}
}
}
}
Pin a release by changing the package arg to pocmap[server]==X.Y.Z; keep
pocmap-mcp as the last arg. Optional env vars raise GitHub / NVD rate limits.
Running the MCP Server
Requires the [server] extra (MCP SDK). Protocol revisions up to 2026-07-28 are
supported; STDIO clients typically negotiate 2025-11-25 at initialize.
pip install "pocmap[server]"
# or from a clone: pip install -e ".[server]"
# STDIO (default — what Claude Desktop / Cursor / most MCP clients expect)
pocmap-mcp
python -m pocmap.mcp_server
# Other transports / flags
pocmap-mcp --transport sse
pocmap-mcp --transport http --host 0.0.0.0 --port 9000
pocmap-mcp --debug
MCP Tools (22 Total)
| Tool | Category | Description |
|---|---|---|
lookup_cve |
CVE Intel | Full CVE details from NVD, CVE.org, CISA KEV, EPSS |
get_epss_score |
CVE Intel | EPSS exploitation probability score (0.0-1.0) with risk level |
check_kev_status |
CVE Intel | Check CISA Known Exploited Vulnerabilities catalog status |
get_attack_techniques |
CVE Intel | MITRE ATT&CK techniques a CVE maps to — how it's exploited and what follows |
find_github_pocs |
Exploits | GitHub PoC repos with stars, language, and forks |
verify_github_pocs |
Exploits | Reads PoC source to score whether a repo really exploits the CVE (opt-in) |
find_metasploit_module |
Exploits | Metasploit module availability and msfconsole command |
find_exploitdb_entry |
Exploits | ExploitDB entry with searchsploit command |
find_nuclei_template |
Exploits | Nuclei scanner template for detection/verification |
find_bug_bounty_reports |
Research | Bug bounty write-ups from HackerOne, PentesterLand |
find_practice_labs |
Labs | CTF labs on Vulhub and HackTheBox |
find_vulhub_docker |
Labs | Vulhub Docker Compose environment with setup steps |
find_recent_exploits |
Discovery | Recently published CVEs with PoC/KEV/severity filters |
discover_product_cves |
Discovery | Find CVEs by product name with version constraints |
discover_package_cves |
Discovery | Dependency vulnerabilities + the releases that fix them (OSV, no API key) |
cve_to_cpe |
Conversion | Convert CVE to affected CPE identifiers |
cpe_to_cve |
Conversion | Find all CVEs affecting a given product (CPE) |
generate_json_report |
Reports | One-shot CVE assessment — details + all exploits + labs + bug bounty reports for one or many CVEs in a single call |
generate_html_report |
Reports | Self-contained HTML report with styled cards |
get_cve_assessment_playbook |
Playbooks | Full CVE assessment workflow playbook |
get_rapid_response_playbook |
Playbooks | Emergency response playbook for critical CVEs |
get_bug_bounty_playbook |
Playbooks | Bug bounty submission workflow playbook |
MCP Resources
| Resource | URI Pattern | Content |
|---|---|---|
| CVE Info | cve://{cve_id} |
Full CVE details as human-readable text |
| Exploits | exploits://{cve_id} |
All available exploits and PoCs |
| Report | report://{cve_id} |
Generated vulnerability report (JSON) |
Example Agent Workflow
User: "Should I prioritize CVE-2021-44228, CVE-2023-38408, or CVE-2024-21413?"
Agent:
1. generate_json_report("CVE-2021-44228,CVE-2023-38408,CVE-2024-21413")
2. Read each entry's triage.priority / reasons (KEV, EPSS, exploit counts)
3. Prefer Log4j when triage shows KEV + highest EPSS + most PoCs
PoC-only ask → find_github_pocs (check labels / trust_score / sources).
Dependency ask → discover_package_cves (use canonical_cve + aliases, not product discovery).
Claude Desktop / Cursor JSON configs and transports: Getting started → MCP. Tool inventory: MCP tools. Agent contract: .claude/skills/pocmap-agent/references/mcp_tools.md.
Python API
from pocmap.services.cve_service import CVEService
with CVEService() as svc:
info = svc.get_cve_info("CVE-2021-44228")
print(info.cvss.base_score, info.kev_status, info.epss)
Full service examples: Python API.
Docs
| Topic | Link |
|---|---|
| Getting started / MCP clients | getting-started |
CLI (latest, discover, package, formats, cache, CI) |
cli |
| Python API | python-api |
| Configuration | configuration |
| Bug bounty toolkit | bug-bounty |
| Verifying PoCs (opt-in) | verifying-pocs |
| Architecture | architecture |
| Contributing / plugins | contributing |
| Schemas | schemas |
License
MIT — see LICENSE.
PocMap is a research and defensive tool. Always operate within applicable law and program scope.
Install Pocmap in Claude Desktop, Claude Code & Cursor
unyly install pocmapInstalls into Claude Desktop, Claude Code, Cursor & VS Code — handles npx, uvx and build-from-source repos for you.
First time? Get the CLI: curl -fsSL https://unyly.org/install | sh
Or configure manually
Run in your terminal:
claude mcp add pocmap -- uvx pocmapStep-by-step: how to install Pocmap
FAQ
Is Pocmap MCP free?
Yes, Pocmap MCP is free — one-click install via Unyly at no cost.
Does Pocmap need an API key?
No, Pocmap runs without API keys or environment variables.
Is Pocmap hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Pocmap in Claude Desktop, Claude Code or Cursor?
Open Pocmap on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
by duxiaohuiSupabase
Database, auth and storage
by SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare Pocmap with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
