Skip to main content
Glama

get_chains

Read-onlyIdempotent

Known Chained Vulnerabilities™: pairs of CVEs that a cited source reports were used together in one exploit chain (VulnCheck KEV entry text, Metasploit modules, SigmaHQ rules, press, research or academic sentences, community text judged by a local model). Each row carries both CVEs with their CISA KEV status, the claim kind (observed: the source reports attacks; potential: the source reports they can be chained), the quoted evidence with its source, URL and date, and community discussion counts, which show discussion and are not chain claims. The per-CVE record carries chains.known and chains.candidates (KCV Watch: possible chains for teams to research, pairs whose extracted exploit capabilities connect or whose records tie them together, derived and never confirmed, each with its tier, lane, reasons, basis, product, bridge, grade, a caption and the entry step where one is extracted); search_cves accepts chained=1 and chainability=1. Filters: source (vulncheck_kev, metasploit, sigma, press, research, community), since (YYYY-MM-DD, first seen), claim (observed|potential), limit (1..500).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
claimNoobserved: the source reports attacks that chained them; potential: the source reports they can be chained
limitNo1..500 (default 100)
sinceNoPairs first seen on or after this day (YYYY-MM-DD)
sourceNoEvidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc, exploitdb or exploit_code

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedInput schema / properties / source / description
      Previous value: -"Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc or exploitdb"New value: +"Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc, exploitdb or exploit_code"
  2. Changed1 schema field changed
    • changedInput schema / properties / source / description
      Previous value: -"Evidence lane: vulncheck_kev, metasploit, sigma, press, research, community, github_poc or exploitdb"New value: +"Evidence lane: vulncheck_kev, metasploit, sigma, press, research, academic, community, github_poc or exploitdb"
  3. Added

TDQS

A3.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover readOnly/idempotent/openWorld, but the description adds genuinely useful behavioral context beyond them: community discussion counts 'show discussion and are not chain claims,' candidates are 'derived and never confirmed,' and the observed vs. potential claim distinction. It stops short of describing pagination or ordering.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

One very long paragraph with deeply nested parentheticals (the chains.candidates field list alone spans a dozen comma-separated attributes). Information is crammed rather than structured or front-loaded, and the source enum is duplicated from the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the burden of explaining return shape and does so thoroughly (per-row CVEs, KEV status, claim kind, quoted evidence with source/URL/date, discussion counts). An agent knows what a row contains, though ordering and pagination remain unstated.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all four parameters are already documented, including the observed/potential enum. The description largely restates the source and claim filters and the limit range already in the schema, adding little syntax or format detail beyond the baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening clause states a specific resource ('Known Chained Vulnerabilities: pairs of CVEs... used together in one exploit chain') and enumerates the evidence sources behind the claim, so an agent can tell this apart from get_cve. It is clear, though the purpose is embedded in a dense paragraph rather than front-loaded as a single crisp statement.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It implies relationship to siblings by noting that 'search_cves accepts chained=1 and chainability=1,' and explains that chains.candidates exist for teams to research. However, it never states explicitly when to call get_chains versus search_cves with those flags, leaving the routing decision to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources