CyberMax
Home › Use with › Kevscope

Use Kevscope MCP with OpenAI Codex CLI

CVE patch-priority API + MCP: CISA KEV, EPSS, CVSS, SSVC. Keys $19/mo; 200 free calls/day.

Remote MCP server (Streamable HTTP), nothing to install. Free: 200 free calls/day · Paid: Keys $19/mo

Set it up

  1. Open ~/.codex/config.toml (create it if needed).
  2. Add the [mcp_servers] table shown and save.
  3. Start Codex; the server's tools are available to the agent.
  4. Ask a question the tools can answer.

Add to ~/.codex/config.toml:

[mcp_servers.kevscope-api]
url = "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-codex"

With a paid key:

[mcp_servers.kevscope-api]
url = "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-codex"
env_http_headers = { "x-api-key" = "CYBERMAX_API_KEY" }

env_http_headers maps the header to an environment variable name, so the key stays in your environment.

Where it goes:

Config format checked 2026-10-09 against OpenAI Codex CLI's MCP documentation.

Tools you get

Endpoint checked 2026-10-09: https://kevscope-api.cybermaxtools.com/mcp answered an MCP initialize (protocol 2025-06-18) and tools/list with 3 tools, all marked read-only. No key was used and no tool was called.

ToolWhat it doesRequired inputs
cve_priorityPatch-priority verdict for 1-20 CVE IDs with evidence: CISA KEV status (date added, due date, ransomware use), FIRST EPSS probability, CVSS (CNA or CISA-ADP), CISA SSVC exploitation/automatable/impact, vendor, product and links. Sorted most urgent first.cves
kev_recentCVEs added to the CISA Known Exploited Vulnerabilities catalog in the last N days, newest first, with due date, ransomware use and EPSS. Optional vendor/product text filter.none
epss_watchlistThe highest-EPSS CVEs (most likely to be exploited in 30 days) that are not in CISA KEV yet. Defaults to this year's CVE IDs.none

Test the endpoint from a terminal

This lists the tools without a key and without calling any of them:

curl -s https://kevscope-api.cybermaxtools.com/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

If it does not work

Kevscope in other clients

CursorVS Code (GitHub Copilot)Claude CodeClaude Desktop and claude.aiWindsurf (Devin Desktop)ClineGemini CLI

More MCP servers for OpenAI Codex CLI

AfterwrenAwardtide Recompete RadarBonafido: Business Domain Verification APICitewrenCommonkite: Free Image Search API, Creative Commons & CC0CyberMax DataDomainDNADutyfinchFeedpeck: RSS Feed Finder & Reader by WebsiteFieldwrightFigurewellHaulrollHireHeatInsidewellLeafmeltLinkheftLogolark: Company Logo API & Favicon Finder by DomainMailvett: Email Validation API for AI AgentsNamewhereOrbitwrenPinloft: Batch Geocoder — Address to Lat/Long + Census FIPSPricewickPrintwren: HTML to PDF and URL to PDF (real Chrome)RecallrollShiftmoorSumbloomSwellmeter TrendingZiplore: US ZIP Code API (county, time zone, demographics, radius)

All Kevscope setups · All OpenAI Codex CLI setups · All