Documentation
The 18 Pix security workflows delivered as MCP prompts. Every one of them a procedure that runs on your machine, because the lookups are tools.
Tools answer one question. Prompts run a whole workflow.
The 18 prompts are the complete Pix skill library, a set of security procedures written and refined by engineers who do this work. They are delivered verbatim from their source, with CI failing the build if the two ever drift.
There used to be 33 of these, and 17 of them ran entirely server-side — which meant they restated a tool sitting right next to them. An agent with this server configured saw the same question answered three ways: once as a tool, once as a prompt, and once again as a skill in the plugin.
Those are gone. What is left is the half that a server genuinely cannot do: read your files, run your package manager, edit your manifest, shell out to your scanners. A Cloudflare Worker has none of those, so every prompt here ships as instructions your own agent follows using the Vulnetix CLI, and every one says so in its first lines:
This workflow needs your local machine. It reads or writes files in the repo, runs package managers, or shells out to scanners. The MCP server has no filesystem, so run these steps yourself with the Vulnetix CLI.
That boundary is also the reason no code ever leaves your machine through this server.
For a straight lookup — a CVE, an exploit list, a KEV check, a package’s advisories — use the tools. There is exactly one place to ask now.
| Prompt | Workflow |
|---|---|
vulnetix_dependency_choice | Which package to add, and what each option costs |
vulnetix_repo_impact | Whether a CVE reaches anything in this repository |
vulnetix_fix | Apply a remediation with rollback |
vulnetix_verify_fix | Re-scan and gate on the result |
vulnetix_dep_resolve | Resolve a blocked upgrade |
vulnetix_typosquat_check | Typosquat and malicious-package detection |
vulnetix_eol_check | End-of-life runtimes and dependencies |
vulnetix_license_check | Copyleft conflicts and SPDX output |
vulnetix_sast_scan | SAST over changed files, optional Semgrep |
vulnetix_secret_scan | Hardcoded-secret detection, staged or full |
vulnetix_iac_scan | Terraform, OpenTofu and k8s misconfiguration |
vulnetix_container_scan | Dockerfile and image analysis |
vulnetix_secure_code_write | Secure-coding coach for the file you are in |
vulnetix_detection_rules | Snort, YARA and Nuclei content for what you cannot patch |
vulnetix_exploit_test | Prove exploitability against an authorised target |
vulnetix_sbom_generate | CycloneDX and SPDX, optionally cosign-signed |
vulnetix_vex_publish | OpenVEX and CycloneDX attestations |
vulnetix_dashboard | Read tracked findings from local memory |
How prompts surface depends on the client:
| Client | How |
|---|---|
| Claude Code | /mcp__vulnetix__vulnetix_repo_impact |
| VS Code | /mcp.vulnetix.vulnetix_repo_impact |
| Claude Desktop | + in the message box, under the server |
| Cursor, Windsurf | Ask by name, or pick from the prompt list |
Most take one free-form argument: an advisory id, a package name, a flag string.
Bodies are generated from the Pix SKILL.md sources by a build script, and CI
fails if the generated file drifts. That is on purpose: the plugin’s own
_system.md and README.md had each drifted to a different count, and
documentation that quietly disagrees with the thing it documents is worse than
none.