Use Kevscope MCP with VS Code (GitHub Copilot)
CVE patch-priority API + MCP: CISA KEV, EPSS, CVSS, SSVC. Keys $19/mo; 200 free calls/day.
Remote MCP server (Streamable HTTP), nothing to install. Free: 200 free calls/day · Paid: Keys $19/mo
Set it up
- Create .vscode/mcp.json in your workspace (or run MCP: Add Server from the Command Palette).
- Paste the configuration and save; a Start button appears above the server entry.
- Start the server, then open Copilot Chat in Agent mode and check the tools list.
- Ask a question the tools can answer and approve the tool call.
Add to .vscode/mcp.json:
{
"servers": {
"kevscope-api": {
"type": "http",
"url": "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-vs-code"
}
}
}With a paid key:
{
"inputs": [
{
"type": "promptString",
"id": "cybermax-key",
"description": "CyberMax API key",
"password": true
}
],
"servers": {
"kevscope-api": {
"type": "http",
"url": "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-vs-code",
"headers": {
"x-api-key": "${input:cybermax-key}"
}
}
}
}VS Code asks for the key the first time the server starts and stores it securely; it never sits in the file.
- .vscode/mcp.json in your workspace (VS Code format, top-level "servers")
- or the portable .mcp.json at the workspace root (top-level "mcpServers")
Tools you get
Endpoint checked 2026-10-09: https://kevscope-api.cybermaxtools.com/mcp answered an MCP initialize (protocol 2025-06-18) and tools/list with 3 tools, all marked read-only. No key was used and no tool was called.
| Tool | What it does | Required inputs |
|---|---|---|
cve_priority | Patch-priority verdict for 1-20 CVE IDs with evidence: CISA KEV status (date added, due date, ransomware use), FIRST EPSS probability, CVSS (CNA or CISA-ADP), CISA SSVC exploitation/automatable/impact, vendor, product and links. Sorted most urgent first. | cves |
kev_recent | CVEs added to the CISA Known Exploited Vulnerabilities catalog in the last N days, newest first, with due date, ransomware use and EPSS. Optional vendor/product text filter. | none |
epss_watchlist | The highest-EPSS CVEs (most likely to be exploited in 30 days) that are not in CISA KEV yet. Defaults to this year's CVE IDs. | none |
Test the endpoint from a terminal
This lists the tools without a key and without calling any of them:
curl -s https://kevscope-api.cybermaxtools.com/mcp \
-H 'content-type: application/json' \
-H 'accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'If it does not work
- In .vscode/mcp.json the key is "servers" and "type": "http" is required.
- The docs note the Add Server flow now recommends the portable .mcp.json, which uses "mcpServers" instead; both formats are documented.
- The free tier has a daily limit (see the pricing line above); a paid key raises it.
Kevscope in other clients
CursorClaude CodeClaude Desktop and claude.aiWindsurf (Devin Desktop)ClineOpenAI Codex CLIGemini CLI
More MCP servers for VS Code (GitHub Copilot)
AfterwrenAwardtide Recompete RadarBonafido: Business Domain Verification APICitewrenCommonkite: Free Image Search API, Creative Commons & CC0CyberMax DataDomainDNADutyfinchFeedpeck: RSS Feed Finder & Reader by WebsiteFieldwrightFigurewellHaulrollHireHeatInsidewellLeafmeltLinkheftLogolark: Company Logo API & Favicon Finder by DomainMailvett: Email Validation API for AI AgentsNamewhereOrbitwrenPinloft: Batch Geocoder — Address to Lat/Long + Census FIPSPricewickPrintwren: HTML to PDF and URL to PDF (real Chrome)RecallrollShiftmoorSumbloomSwellmeter TrendingZiplore: US ZIP Code API (county, time zone, demographics, radius)
All Kevscope setups · All VS Code (GitHub Copilot) setups · All