What one command wires
Wire Zed to Vulnetix. Zed reads the interoperable ~/.agents/skills, and its context-server configuration points at the MCP server.
vulnetix agent install --agent zed
- Agent Skills: supported —
~/.agents/skills - Dependency guard: not wired by the installer —
hook contract not yet verified - MCP server: supported —
https://mcp.vulnetix.com/mcp
Where Zed reads skills
Agent Skills is an open standard, but hosts disagree about the directory. The installer writes the one Zed actually opens.
- Everywhere, for you:
~/.agents/skills - This repository:
.agents/skills
Add the MCP server to settings.json
{
"context_servers": {
"vulnetix": {
"source": "custom",
"url": "https://mcp.vulnetix.com/mcp",
"headers": { "Authorization": "ApiKey <orgId>:<key>" }
}
}
}
Ask something training data cannot answer
No install and no local binary: one URL and one header give the agent live vulnerability intelligence it can call mid-conversation.
>
is CVE-2021-44228 still actively exploited?
→ calling vulnetix_vuln
org.apache.logging.log4j:log4j-core@2.14.1 · maven
17 vulnerabilities · 11 critical, 4 high
- CVE-2021-44228 critical · CVSS 10.0 · EPSS 100.0%
- CVE-2021-45046 critical · CVSS 9.2 · EPSS 100.0%
- CVE-2021-44832 critical · CVSS 9.3 · EPSS 97.9%
CISA KEV · due 2021-12-24 · known ransomware use