Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

CWE

Common Weakness Enumeration

A catalogue of the kinds of mistake that cause vulnerabilities, each with a number.

Where a CVE names one vulnerability, a CWE names the class it belongs to: CWE-78 for injecting into an operating-system command, CWE-918 for server-side request forgery, CWE-1427 for input used to prompt a language model without being neutralised.

The rows of this site's rubric that correspond to a known class of weakness carry its CWE number, and so does every rule in the tool description pattern set, so a result can be read against a standard nobody here wrote.

Why it matters

It turns a finding into something comparable: two scanners that disagree about wording can agree about the class.

The mistake everyone makes

Reading a CWE number as severity. It says what kind of mistake it is, not how bad this instance is.

Related terms

CVE
A public identifier for one specific, disclosed vulnerability in one product.
Rubric
The versioned list of checks verification runs, published in full.
Command injection
When input from outside, such as a tool argument, ends up being run as part of a shell command.
SSRF
Persuading a server to make a network request on your behalf, to somewhere you could not reach yourself.
Previous
CVE
Next
Data exfiltration

See CWE on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue