// live drill
One paste. Full exposure check.
Your agent already has shell access to the machine that matters — yours. VexedAI gives it a battle-tested runbook for the exact CVE, so the check fits your setup, not a generic scanner's guess.
We watch the feed
New CVEs drop constantly; almost none apply to you. We triage for real-world impact — the stacks solo devs and small teams actually run — and skip the noise.
We write the runbook
Every alert ships as a tested prompt: correct version checks, config gotchas, edge cases, and the questions a scanner can't ask. Verified before it reaches you.
Your agent runs it
Paste it into Claude Code, Codex, or any harness with shell access. Minutes later: exposed or clear, with remediation steps either way.
// the feed
What an alert looks like.
Each entry is severity-triaged and ships with its prompt attached. Try the copy button — this is the whole workflow.
// sample entries for illustration — real alerts are tied to real CVE IDs
// what this is not
VexedAI checks exposure — whether a vulnerable version or configuration is present on your systems — and guides remediation. It is not a forensics tool and won't promise you haven't been compromised. Anyone who promises that from a prompt is lying to you.
// where it's headed
Copy/paste today. /vex-check tomorrow.
The waitlist gets the email feed first. Early access members get the native integrations as they land:
- ▸MCP server — your agent pulls the latest runbooks itself. New CVE drops, your next session already knows about it.
- ▸/vex-check command — one slash command in Claude Code runs the newest checks against the box you're on.
- ▸Stack profiles — tell us you run Rails + Postgres + nginx on Docker, and only hear about CVEs that can actually touch you.
// early access
The next big CVE is coming.
Have the prompt ready.
Join the waitlist and get the drill-ready feed the moment it opens — plus first crack at the MCP server and /vex-check.
No spam. Only the CVEs worth your time.