Skip to main content
Glama

EchelonGraph CVE & Exposure

CVE feed summary

cve_summary
Read-onlyIdempotent

Summary of EchelonGraph's CVE Pulse feed: summary.total active CVEs, their counts by severity band (summary.critical, summary.high, summary.medium, summary.low), the count with no band (summary.none), and summary.last_updated, the newest modification time among those records. summary.none is not a severity rating of None: it counts the active CVEs with no severity band from any source, that is, CVEs not yet scored, and the answer may carry the same count again as summary.unscored. Whenever summary.none is above zero the note says so: report those CVEs as not yet scored, not as CVEs rated None. summary.nvd_critical, summary.nvd_high, summary.nvd_medium, summary.nvd_low and summary.nvd_none count the same active CVEs as summary.total by NVD's CVSS severity label (v3.x, else v4.0; before NVD's record arrives, or where it gives none, a pre-NVD label from the CVE.org record or a GitHub advisory can stand in): provenance, never EchelonGraph's severity band. summary.nvd_none counts the active CVEs with no Critical, High, Medium or Low label there, CVEs NVD never labelled under CVSS v3 among them, and many of those carry an NVD CVSS v2 score instead: it is neither a count of CVEs rated None nor the count of CVEs with no severity, which is summary.none. Whenever summary.nvd_none is above zero the note says what it counts, with its count. summary.rejected counts the CVE records rejected (withdrawn) by their numbering authority, which summary.total and the other counts above leave out: report them as withdrawn records, never as vulnerabilities. poller holds the in-memory counters of the NVD poller of the one API instance that answered (cves_ingested, cves_skipped, http_retries, poll_count, poll_errors, last_poll_at, last_poll_dur_ms, interval), counted since that instance last started and zeroed on every restart: they describe that instance, never the feed's size, intake, reliability or freshness. Whenever the answer carries poller the note says so. A poller field the answer sends in a JSON type other than the one described here is left out of data and named in the note, and a poller that is neither a JSON object nor null is left out whole: summary is relayed either way. The feed is polled from its sources on a schedule, so this is the state as of that update. Its structured result carries state (measured), measured_at, method, coverage, freshness (null: the feed serves no poll-completion time) and notes, with data equal to the API's JSON less each poller field (or the whole poller) the note names as left out; the result's last text block repeats it without data (the first text block) and without the note's sentences (the text block before it), with which notes ends. Past 30,000 characters of JSON, the first text block holds data cut to fit, and the note says what the cut leaves out and where to read it (TEXT CUT); data in the structured result always holds it whole.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "description": "What the answer covers; null where the answer says nothing about it.",
      -        "type": "null"
      -      },
      -      "data": {
      -        "additionalProperties": {},
      -        "properties": {
      -          "poller": {
      -            "anyOf": [
      -              {
      -                "additionalProperties": {},
      -                "properties": {
      -                  "cves_ingested": {
      -                    "description": "CVE records this instance's NVD poller wrote since the instance last started: never the feed's size or intake.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  },
      -                  "cves_skipped": {
      -                    "description": "CVE records this instance's NVD poller skipped since the instance last started.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  },
      -                  "http_retries": {
      -                    "description": "HTTP retries this instance's NVD poller made since the instance last started.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  },
      -                  "interval": {
      -                    "description": "How often this instance's NVD poller polls.",
      -                    "type": [
      -                      "string",
      -                      "null"
      -                    ]
      -                  },
      -                  "last_poll_at": {
      -                    "description": "When this instance's NVD poller last polled: never the feed's freshness.",
      -                    "type": [
      -                      "string",
      -                      "null"
      -                    ]
      -                  },
      -                  "last_poll_dur_ms": {
      -                    "description": "How long that poll took, in milliseconds.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  },
      -                  "poll_count": {
      -                    "description": "Polls this instance's NVD poller made since the instance last started.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  },
      -                  "poll_errors": {
      -                    "description": "Polls of this instance's NVD poller that failed since the instance last started: never the feed's reliability.",
      -                    "type": [
      -                      "number",
      -                      "null"
      -                    ]
      -                  }
      -                },
      -                "type": "object"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "poller holds the in-memory counters of the NVD poller of the one API instance that answered (cves_ingested, cves_skipped, http_retries, poll_count, poll_errors, last_poll_at, last_poll_dur_ms, interval), counted since that instance last started and zeroed on every restart: they describe that instance, never the feed's size, intake, reliability or freshness. Whenever the answer carries poller the note says so."
      -          },
      -          "summary": {
      -            "additionalProperties": {},
      -            "properties": {
      -              "critical": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "high": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "last_updated": {
      -                "type": [
      -                  "string",
      -                  "null"
      -                ]
      -              },
      -              "low": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "medium": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "none": {
      -                "description": "The active CVEs with no severity band from any source: CVEs not yet scored, not a severity rating of None.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_critical": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Critical: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_high": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is High: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_low": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Low: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_medium": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Medium: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_none": {
      -                "description": "Of the active CVEs total counts, those with no Critical, High, Medium or Low NVD CVSS severity label, many of them with an NVD CVSS v2 score instead: neither a count of CVEs rated None nor the count of CVEs with no severity, which is none.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "rejected": {
      -                "description": "The CVE records rejected (withdrawn) by their numbering authority, which total and every other count here leave out: withdrawn records, never vulnerabilities.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "total": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "unscored": {
      -                "description": "The same count as none, under its own name.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              }
      -            },
      -            "type": "object"
      -          }
      -        },
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "anyOf": [
      -          {
      -            "description": "An RFC 3339 instant.",
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      -      },
      -      "method": {
      -        "description": "How the numbers were produced.",
      -        "type": "string"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      -        "enum": [
      -          "measured",
      -          "not_assessed"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "data"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "type": "null"
      -      },
      -      "error": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "kind": {
      -            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      -            "enum": [
      -              "network",
      -              "timeout",
      -              "http",
      -              "not_json",
      -              "not_object",
      -              "invalid_input",
      -              "internal",
      -              "unexpected_shape",
      -              "radars"
      -            ],
      -            "type": "string"
      -          },
      -          "message": {
      -            "description": "The cause: the API's own message, or what went wrong.",
      -            "type": "string"
      -          },
      -          "path": {
      -            "description": "The API path requested, when a request was made.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "status": {
      -            "anyOf": [
      -              {
      -                "maximum": 9007199254740991,
      -                "minimum": -9007199254740991,
      -                "type": "integer"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The HTTP status, when the API answered one."
      -          }
      -        },
      -        "required": [
      -          "kind",
      -          "path",
      -          "status",
      -          "message"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "type": "null"
      -      },
      -      "method": {
      -        "type": "null"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      -        "enum": [
      -          "failed",
      -          "invalid_input"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "error"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "description": "What the answer covers; null where the answer says nothing about it.",
      +        "type": "null"
      +      },
      +      "data": {
      +        "additionalProperties": {},
      +        "properties": {
      +          "poller": {
      +            "anyOf": [
      +              {
      +                "additionalProperties": {},
      +                "properties": {
      +                  "cves_ingested": {
      +                    "description": "CVE records this instance's NVD poller wrote since the instance last started: never the feed's size or intake.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "cves_skipped": {
      +                    "description": "CVE records this instance's NVD poller skipped since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "http_retries": {
      +                    "description": "HTTP retries this instance's NVD poller made since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "interval": {
      +                    "description": "How often this instance's NVD poller polls.",
      +                    "type": [
      +                      "string",
      +                      "null"
      +                    ]
      +                  },
      +                  "last_poll_at": {
      +                    "description": "When this instance's NVD poller last polled: never the feed's freshness.",
      +                    "type": [
      +                      "string",
      +                      "null"
      +                    ]
      +                  },
      +                  "last_poll_dur_ms": {
      +                    "description": "How long that poll took, in milliseconds.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "poll_count": {
      +                    "description": "Polls this instance's NVD poller made since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "poll_errors": {
      +                    "description": "Polls of this instance's NVD poller that failed since the instance last started: never the feed's reliability.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  }
      +                },
      +                "type": "object"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "poller holds the in-memory counters of the NVD poller of the one API instance that answered (cves_ingested, cves_skipped, http_retries, poll_count, poll_errors, last_poll_at, last_poll_dur_ms, interval), counted since that instance last started and zeroed on every restart: they describe that instance, never the feed's size, intake, reliability or freshness. Whenever the answer carries poller the note says so. A poller field the answer sends in a JSON type other than the one described here is left out of data and named in the note, and a poller that is neither a JSON object nor null is left out whole: summary is relayed either way."
      +          },
      +          "summary": {
      +            "additionalProperties": {},
      +            "properties": {
      +              "critical": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "high": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "last_updated": {
      +                "type": [
      +                  "string",
      +                  "null"
      +                ]
      +              },
      +              "low": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "medium": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "none": {
      +                "description": "The active CVEs with no severity band from any source: CVEs not yet scored, not a severity rating of None.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_critical": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Critical: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_high": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is High: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_low": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Low: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_medium": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Medium: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_none": {
      +                "description": "Of the active CVEs total counts, those with no Critical, High, Medium or Low NVD CVSS severity label, many of them with an NVD CVSS v2 score instead: neither a count of CVEs rated None nor the count of CVEs with no severity, which is none.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "rejected": {
      +                "description": "The CVE records rejected (withdrawn) by their numbering authority, which total and every other count here leave out: withdrawn records, never vulnerabilities.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "total": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "unscored": {
      +                "description": "The same count as none, under its own name.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              }
      +            },
      +            "type": "object"
      +          }
      +        },
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "anyOf": [
      +          {
      +            "description": "An RFC 3339 instant.",
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      +      },
      +      "method": {
      +        "description": "How the numbers were produced.",
      +        "type": "string"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      +        "enum": [
      +          "measured",
      +          "not_assessed"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "data"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "type": "null"
      +      },
      +      "error": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "kind": {
      +            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      +            "enum": [
      +              "network",
      +              "timeout",
      +              "http",
      +              "not_json",
      +              "not_object",
      +              "invalid_input",
      +              "internal",
      +              "unexpected_shape",
      +              "radars"
      +            ],
      +            "type": "string"
      +          },
      +          "message": {
      +            "description": "The cause: the API's own message, or what went wrong.",
      +            "type": "string"
      +          },
      +          "path": {
      +            "description": "The API path requested, when a request was made.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "anyOf": [
      +              {
      +                "maximum": 9007199254740991,
      +                "minimum": -9007199254740991,
      +                "type": "integer"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The HTTP status, when the API answered one."
      +          }
      +        },
      +        "required": [
      +          "kind",
      +          "path",
      +          "status",
      +          "message"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "type": "null"
      +      },
      +      "method": {
      +        "type": "null"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      +        "enum": [
      +          "failed",
      +          "invalid_input"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "error"
      +    ],
      +    "type": "object"
      +  }
      +]
  2. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "description": "What the answer covers; null where the answer says nothing about it.",
      -        "type": "null"
      -      },
      -      "data": {
      -        "additionalProperties": {},
      -        "properties": {
      -          "summary": {
      -            "additionalProperties": {},
      -            "properties": {
      -              "critical": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "high": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "last_updated": {
      -                "type": [
      -                  "string",
      -                  "null"
      -                ]
      -              },
      -              "low": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "medium": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "none": {
      -                "description": "The active CVEs with no severity band from any source: CVEs not yet scored, not a severity rating of None.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_critical": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Critical: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_high": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is High: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_low": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Low: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_medium": {
      -                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Medium: NVD's label, as provenance, never EchelonGraph's severity band.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "nvd_none": {
      -                "description": "Of the active CVEs total counts, those with no Critical, High, Medium or Low NVD CVSS severity label, many of them with an NVD CVSS v2 score instead: neither a count of CVEs rated None nor the count of CVEs with no severity, which is none.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "rejected": {
      -                "description": "The CVE records rejected (withdrawn) by their numbering authority, which total and every other count here leave out: withdrawn records, never vulnerabilities.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "total": {
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              },
      -              "unscored": {
      -                "description": "The same count as none, under its own name.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              }
      -            },
      -            "type": "object"
      -          }
      -        },
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "anyOf": [
      -          {
      -            "description": "An RFC 3339 instant.",
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      -      },
      -      "method": {
      -        "description": "How the numbers were produced.",
      -        "type": "string"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      -        "enum": [
      -          "measured",
      -          "not_assessed"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "data"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "type": "null"
      -      },
      -      "error": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "kind": {
      -            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      -            "enum": [
      -              "network",
      -              "timeout",
      -              "http",
      -              "not_json",
      -              "not_object",
      -              "invalid_input",
      -              "internal",
      -              "unexpected_shape",
      -              "radars"
      -            ],
      -            "type": "string"
      -          },
      -          "message": {
      -            "description": "The cause: the API's own message, or what went wrong.",
      -            "type": "string"
      -          },
      -          "path": {
      -            "description": "The API path requested, when a request was made.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "status": {
      -            "anyOf": [
      -              {
      -                "maximum": 9007199254740991,
      -                "minimum": -9007199254740991,
      -                "type": "integer"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The HTTP status, when the API answered one."
      -          }
      -        },
      -        "required": [
      -          "kind",
      -          "path",
      -          "status",
      -          "message"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "type": "null"
      -      },
      -      "method": {
      -        "type": "null"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      -        "enum": [
      -          "failed",
      -          "invalid_input"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "error"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "description": "What the answer covers; null where the answer says nothing about it.",
      +        "type": "null"
      +      },
      +      "data": {
      +        "additionalProperties": {},
      +        "properties": {
      +          "poller": {
      +            "anyOf": [
      +              {
      +                "additionalProperties": {},
      +                "properties": {
      +                  "cves_ingested": {
      +                    "description": "CVE records this instance's NVD poller wrote since the instance last started: never the feed's size or intake.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "cves_skipped": {
      +                    "description": "CVE records this instance's NVD poller skipped since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "http_retries": {
      +                    "description": "HTTP retries this instance's NVD poller made since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "interval": {
      +                    "description": "How often this instance's NVD poller polls.",
      +                    "type": [
      +                      "string",
      +                      "null"
      +                    ]
      +                  },
      +                  "last_poll_at": {
      +                    "description": "When this instance's NVD poller last polled: never the feed's freshness.",
      +                    "type": [
      +                      "string",
      +                      "null"
      +                    ]
      +                  },
      +                  "last_poll_dur_ms": {
      +                    "description": "How long that poll took, in milliseconds.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "poll_count": {
      +                    "description": "Polls this instance's NVD poller made since the instance last started.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  },
      +                  "poll_errors": {
      +                    "description": "Polls of this instance's NVD poller that failed since the instance last started: never the feed's reliability.",
      +                    "type": [
      +                      "number",
      +                      "null"
      +                    ]
      +                  }
      +                },
      +                "type": "object"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "poller holds the in-memory counters of the NVD poller of the one API instance that answered (cves_ingested, cves_skipped, http_retries, poll_count, poll_errors, last_poll_at, last_poll_dur_ms, interval), counted since that instance last started and zeroed on every restart: they describe that instance, never the feed's size, intake, reliability or freshness. Whenever the answer carries poller the note says so."
      +          },
      +          "summary": {
      +            "additionalProperties": {},
      +            "properties": {
      +              "critical": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "high": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "last_updated": {
      +                "type": [
      +                  "string",
      +                  "null"
      +                ]
      +              },
      +              "low": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "medium": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "none": {
      +                "description": "The active CVEs with no severity band from any source: CVEs not yet scored, not a severity rating of None.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_critical": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Critical: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_high": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is High: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_low": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Low: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_medium": {
      +                "description": "Of the active CVEs total counts, those whose NVD CVSS severity label is Medium: NVD's label, as provenance, never EchelonGraph's severity band.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "nvd_none": {
      +                "description": "Of the active CVEs total counts, those with no Critical, High, Medium or Low NVD CVSS severity label, many of them with an NVD CVSS v2 score instead: neither a count of CVEs rated None nor the count of CVEs with no severity, which is none.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "rejected": {
      +                "description": "The CVE records rejected (withdrawn) by their numbering authority, which total and every other count here leave out: withdrawn records, never vulnerabilities.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "total": {
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "unscored": {
      +                "description": "The same count as none, under its own name.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              }
      +            },
      +            "type": "object"
      +          }
      +        },
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "anyOf": [
      +          {
      +            "description": "An RFC 3339 instant.",
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      +      },
      +      "method": {
      +        "description": "How the numbers were produced.",
      +        "type": "string"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      +        "enum": [
      +          "measured",
      +          "not_assessed"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "data"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "type": "null"
      +      },
      +      "error": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "kind": {
      +            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      +            "enum": [
      +              "network",
      +              "timeout",
      +              "http",
      +              "not_json",
      +              "not_object",
      +              "invalid_input",
      +              "internal",
      +              "unexpected_shape",
      +              "radars"
      +            ],
      +            "type": "string"
      +          },
      +          "message": {
      +            "description": "The cause: the API's own message, or what went wrong.",
      +            "type": "string"
      +          },
      +          "path": {
      +            "description": "The API path requested, when a request was made.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "anyOf": [
      +              {
      +                "maximum": 9007199254740991,
      +                "minimum": -9007199254740991,
      +                "type": "integer"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The HTTP status, when the API answered one."
      +          }
      +        },
      +        "required": [
      +          "kind",
      +          "path",
      +          "status",
      +          "message"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "type": "null"
      +      },
      +      "method": {
      +        "type": "null"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      +        "enum": [
      +          "failed",
      +          "invalid_input"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "error"
      +    ],
      +    "type": "object"
      +  }
      +]
  3. First observed

TDQS

B3.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), so the bar is lower, and the description still adds real behavioral context: the data is a point-in-time state from a scheduled poll, freshness is null because no poll-completion time is served, poller counters are per-instance and zeroed on restart, and output is truncated past 30,000 characters with a TEXT CUT note. Much of the remaining text documents output fields rather than invocation behavior, keeping it just short of a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single unbroken ~600-word paragraph for a zero-parameter tool, with repeated conditional boilerplate ('Whenever summary.none is above zero the note says so', 'Whenever the answer carries poller the note says so'). Much of the field-by-field explanation duplicates what an output schema should carry, and there is no structure, headings or bullets to make it scannable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a relay tool with a structured result envelope and an output schema, the description is more than complete on result interpretation: it covers state, measured_at, method, coverage, freshness-null, notes, poller exclusion and truncation. The only real gap is invocation context (why/when to pick this over sibling tools), which the rubric weights elsewhere.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes no parameters, so per the rubric the baseline is 4. The description adds nothing about inputs (there are none) and spends its length on output semantics, which is appropriate for a zero-argument call.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening line states the resource clearly ('Summary of EchelonGraph's CVE Pulse feed') and the enumeration of summary.* fields makes the returned aggregate counts concrete. However, it never names or contrasts with siblings such as cve_intel, cve_exposure or search_cves, so an agent must infer where this fits in the family. Clear purpose, no sibling differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no when-to-use guidance whatsoever: nothing says to call this for a fleet-wide severity snapshot rather than search_cves or cve_intel, and no exclusions or alternatives are named. The only prescriptive text concerns how to report results, not when to invoke the tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.