security-recipes.ai

OPEN SECURITY INTELLIGENCE • HUMAN + AGENT READY

Search CVEs. Remediate vulnerabilities with AI agents.

Research 268K+ CVEs and 177 reviewed workflows in a fast human interface—or give AI agents the same bounded context through MCP.

  • Source-backed
  • Bounded by design
  • Evidence required
  • Human reviewed
Security Research Console example showing CVE-2021-44228 matched to a bounded dependency-remediation workflow. The same source-backed context is available to humans and agents, while evidence, rollback, stop conditions, and reviewer ownership remain required.
268,233CVEs
177Reviewed workflows
75Executable playbooks
73MCP tools
Updated daily NVD + CISA KEV • Jul 22, 2026

Provenance and trust

Intelligence you can inspect. Guardrails you can keep.

security-recipes.ai is an open, self-hostable layer between security findings and governed action. It connects source-backed research to bounded workflows without becoming a scanner, ticketing system, deployment platform, or unrestricted mutation surface.

LOCAL KNOWLEDGE SNAPSHOT REFRESHED JUL 22, 2026
NVD CISA KEV Vendor advisories Reviewed repository data
39Compliance frameworks
1,425In-scope CISA KEV records

Adoption paths

Adopt secure AI at the pace your organization can govern.

Begin with a small, reviewable loop. Expand access only when the workflow produces consistent evidence and named owners can support it.

Small teams

Start with one repository.

Use one finding class, follow the visual guide and AI agent setup guides for the tool you already trust, keep existing tests, and require review for every change.

Enterprise teams

Scale through governed lanes.

Add scoped identities, an MCP gateway, named reviewers, audit evidence, and measurable promotion gates.

Adoption blueprint

Choose a rollout lane.

Define the review model and expand only when bounded workflows behave predictably.

Open the blueprint →

Read-first delivery

MCP is context, not authority.

Existing security systems produce findings. security-recipes.ai helps humans and agents understand them, select bounded workflows, gather the right context, and return evidence without replacing the systems teams already trust.

Human research and agent retrieval use the same source-backed knowledge layer.
JSON feeds work without the optional MCP service being online.
Mutation belongs in a separately approved agent host or operator workflow.
CONTEXT DELIVERY MODEL MCP + JSON
01 • Inputs

Existing findings

Scanner, advisory, repository, ticket, SIEM, or cloud-security evidence.

02 • Knowledge

Bounded context

Reviewed recipes, CVE contracts, playbooks, proof, rollback, and stop conditions.

03 • Ownership

Approved action

A reviewer-ready patch, evidence report, or triage note in the team’s own workflow.

SCA SAST Repositories CI SIEM SOAR Ticketing Cloud security

Open, inspectable, self-hostable

Start with one finding. Keep humans in control.

Use the quick start for a bounded first workflow, or inspect the source, catalogs, and MCP implementation on GitHub.