Skip to main content
Glama

EchelonGraph CVE & Exposure

EPSS change history for one CVE

epss_history
Read-onlyIdempotent

How one CVE's EPSS score (FIRST's exploit-prediction probability, 0 to 1, with its percentile) has changed, as EchelonGraph recorded it: points, oldest first, each with at, epss_score and epss_percentile; current, the record's value now (epss_score, epss_percentile, epss_updated_at); series_kind, always change_only; series_starts_at, when EchelonGraph began recording EPSS changes for any CVE; history_rows, points_truncated and latest_point_matches_current. Pass a CVE ID like CVE-2023-44487. The series is change-only: a point is a recorded change, and a day without a point is not a recorded value. Never interpolate it into a daily series. Before series_starts_at nothing was recorded, so a missing point there means not recorded, not unchanged, and the value in force before a CVE's first point is not in the series. latest_point_matches_current false means a change is missing from the series. Its structured result carries state (measured), measured_at (current.epss_updated_at: when EchelonGraph last wrote a changed value, not FIRST's score date), method, coverage (series_kind, series_starts_at, points, points_truncated), freshness (null) and notes, with data equal to the API's JSON; the result's last text block repeats it without data (the first text block) and without the note's sentences (the text block before it), with which notes ends. Past 30,000 characters of JSON, the first text block holds data cut to fit, and the note says what the cut leaves out and where to read it (TEXT CUT); data in the structured result always holds it whole.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cve_idYesa CVE ID, e.g. CVE-2023-44487

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare it a read-only, idempotent, open-world, non-destructive call, but the description goes far beyond that: change-only series semantics, the meaning of series_starts_at, latest_point_matches_current=false as a signal of a missing change, the structured result's state/method/coverage/freshness shape, and the 30,000-character TEXT CUT truncation behavior. This is exactly the behavioral context annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The information is genuinely valuable, but it is delivered as a dense wall of semicolon-joined clauses with little paragraphing, making key rules hard to scan. The core purpose is front-loaded, yet the return-shape and truncation details pile into the same run-on sentences, hurting readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex, semantically tricky tool (change-only, no interpolation, truncation-aware), the description covers the edge cases an agent must understand to read the data correctly. An output schema exists, yet the extra disclosure about result blocks and truncation is warranted and present, so nothing essential is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

There is a single parameter with 100% schema description coverage, so the schema already documents cve_id. The description adds only a concrete example format (CVE-2023-44487), matching the schema example rather than extending it. Baseline 3 applies when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening sentence states a specific verb and resource: it returns how one CVE's EPSS score has changed over time, and it even defines EPSS (FIRST's exploit-prediction probability, 0 to 1, with percentile). No sibling tool (get_cve, cve_intel, cve_summary, etc.) deals with EPSS change history, so the purpose is unambiguously distinct from every alternative offered.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives strong interpretive rules ('Pass a CVE ID like CVE-2023-44487', 'Never interpolate it into a daily series', what a missing point means), which shape correct use. However it never states when to reach for this tool versus cve_intel, cve_summary or get_cve, so tool selection guidance is only implied by the resource type.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.