CyberMax
Home › Use with › Kevscope

Use Kevscope MCP with Windsurf (Devin Desktop)

CVE patch-priority API + MCP: CISA KEV, EPSS, CVSS, SSVC. Keys $19/mo; 200 free calls/day.

Remote MCP server (Streamable HTTP), nothing to install. Free: 200 free calls/day · Paid: Keys $19/mo

Set it up

  1. In the Cascade panel, open the … (Actions) menu and click Open MCP config file in the MCPs section.
  2. Add the server under "mcpServers" with "serverUrl" and save.
  3. Check the MCPs section in Cascade for the server and its tools.
  4. Ask Cascade a question the tools can answer.

Add to ~/.config/devin/mcp_config.json:

{
  "mcpServers": {
    "kevscope-api": {
      "serverUrl": "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-windsurf"
    }
  }
}

With a paid key:

{
  "mcpServers": {
    "kevscope-api": {
      "serverUrl": "https://kevscope-api.cybermaxtools.com/mcp?via=use-with-windsurf",
      "headers": {
        "x-api-key": "YOUR_KEY"
      }
    }
  }
}

Keep this file out of shared folders and repositories if it holds a key.

Where it goes:

Config format checked 2026-10-09 against Windsurf (Devin Desktop)'s MCP documentation.

Tools you get

Endpoint checked 2026-10-09: https://kevscope-api.cybermaxtools.com/mcp answered an MCP initialize (protocol 2025-06-18) and tools/list with 3 tools, all marked read-only. No key was used and no tool was called.

ToolWhat it doesRequired inputs
cve_priorityPatch-priority verdict for 1-20 CVE IDs with evidence: CISA KEV status (date added, due date, ransomware use), FIRST EPSS probability, CVSS (CNA or CISA-ADP), CISA SSVC exploitation/automatable/impact, vendor, product and links. Sorted most urgent first.cves
kev_recentCVEs added to the CISA Known Exploited Vulnerabilities catalog in the last N days, newest first, with due date, ransomware use and EPSS. Optional vendor/product text filter.none
epss_watchlistThe highest-EPSS CVEs (most likely to be exploited in 30 days) that are not in CISA KEV yet. Defaults to this year's CVE IDs.none

Test the endpoint from a terminal

This lists the tools without a key and without calling any of them:

curl -s https://kevscope-api.cybermaxtools.com/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

If it does not work

Kevscope in other clients

CursorVS Code (GitHub Copilot)Claude CodeClaude Desktop and claude.aiClineOpenAI Codex CLIGemini CLI

More MCP servers for Windsurf (Devin Desktop)

AfterwrenAwardtide Recompete RadarBonafido: Business Domain Verification APICitewrenCommonkite: Free Image Search API, Creative Commons & CC0CyberMax DataDomainDNADutyfinchFeedpeck: RSS Feed Finder & Reader by WebsiteFieldwrightFigurewellHaulrollHireHeatInsidewellLeafmeltLinkheftLogolark: Company Logo API & Favicon Finder by DomainMailvett: Email Validation API for AI AgentsNamewhereOrbitwrenPinloft: Batch Geocoder — Address to Lat/Long + Census FIPSPricewickPrintwren: HTML to PDF and URL to PDF (real Chrome)RecallrollShiftmoorSumbloomSwellmeter TrendingZiplore: US ZIP Code API (county, time zone, demographics, radius)

All Kevscope setups · All Windsurf (Devin Desktop) setups · All