# EPSS (Exploit Prediction Scoring System)

> Use this tool when you need to prioritize vulnerability remediation efforts based on exploitation probability. The EPSS provides AI assistants with vulnerability intelligence, integrating data from the NVD API and EPSS scoring system to predict exploitation likelihood within 30 days. It takes in CVE information and outputs detailed vulnerability data, including descriptions, CVSS scores, and EPSS percentiles, making it valuable for cybersecurity professionals to inform remediation decisions.

Canonical page: https://skillsregistry.net/skills/jgamblin-epss  
JSON: https://api.skillsregistry.net/v1/skills/jgamblin-epss

## Description

The EPSS MCP server provides AI assistants with access to vulnerability intelligence by integrating data from the NVD API and EPSS scoring system. Developed by Jerry Gamblin, this implementation fetches detailed CVE information including descriptions, CWEs, CVSS scores, and EPSS percentiles that indicate exploitation likelihood within 30 days. The server supports deployment via Docker for Open-WebUI integration or direct connection to VS Code through the Microsoft Copilot Labs extension, making it valuable for cybersecurity professionals who need to prioritize vulnerability remediation efforts based on exploitation probability without switching contexts.

## Trust

- **Trust score (0–1):** 0.92
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/jgamblin-epss)
- **Repository:** <https://github.com/jgamblin/epss-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "jgamblin-epss"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/jgamblin-epss` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/jgamblin-epss/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
