Skip to main content
Glama

EchelonGraph CVE & Exposure

Exposure radar totals

exposure_radar
Read-onlyIdempotent

Aggregate totals from EchelonGraph's internet-exposure radars, each refreshed on its own schedule: internet-facing services running actively-exploited (CISA-KEV) CVEs, plus the ransomware-linked subset, derived from Shodan data; unauthenticated data stores and observability UIs, found through Shodan (LeakIX when Shodan query credits run low) and then confirmed by EchelonGraph's own identified check (not a pure read: on Redis it names its client, and on ClickHouse its query is recorded in the server's query log); leaked credentials sampled from public GitHub push events; and shadow AI services found through Certificate Transparency logs and Shodan and then checked by EchelonGraph's identified probes. It also gives MCP-server counts: hostnames named like an MCP server in EchelonGraph's own Certificate Transparency feed (no Shodan data), each counted once by its latest verdict from EchelonGraph's identified MCP probe, which never sends tools/call. Every number in the result is labelled here and in the result's note by what it counts; a field this version cannot label is left out and named in the note. kev_exposure: kev_exposure.distinct_hosts counts distinct ip:port services, not machines (a machine answering on two ports counts twice), with at least one CISA-KEV-listed CVE on record, and kev_exposure.ransomware_hosts those with a ransomware-linked one; kev_exposure.kev_cves_exposed and kev_exposure.ransomware_cves count distinct CVEs with at least one such service; kev_exposure.correlations counts service×CVE pairs, not services, so a service with three KEV CVEs counts three times. kev_exposure.top_products, kev_exposure.top_countries and kev_exposure.top_cves rank up to 12 products, 10 countries and 12 CVEs by those services; kev_exposure.top_cves[].cvss_v3_score and kev_exposure.top_cves[].epss_score are the highest CVSS v3 base score and EPSS probability recorded on that CVE's observations. kev_exposure.trend counts service×CVE pairs still on record by the week in which each was first recorded, over 12 weeks, so earlier weeks read low. kev_exposure.newest_kev lists the 15 CVEs that EchelonGraph's CVE records most recently mark as CISA-KEV-listed, each with an exposure_state: exposed, where kev_exposure.newest_kev[].exposed_hosts counts distinct ip:port services on record with it; or not_assessed, where the API's answer holds no measurement for that CVE (its 0 is not one) and no count is relayed, and cve_exposure says per CVE whether the radar tracks it. kev_exposure.newest_kev[].cvss_v3_score and kev_exposure.newest_kev[].epss_score are the CVE record's CVSS v3 base score and EPSS probability. exposed_databases: exposed_databases.distinct_hosts counts distinct ip:port services the check confirmed answering without authentication, and exposed_databases.engines the distinct engine types among them; exposed_databases.top_engines and exposed_databases.top_countries rank up to 15 engines and 10 countries by those services. exposed_databases.pii_likely and exposed_databases.pci_likely count services whose schema names (never record values) pass a high-confidence, precision-first gate for personal or payment-card data, so a service outside them is not shown to hold no such data. exposed_databases.window.from and exposed_databases.window.to are timestamps, not counts: when EchelonGraph's check last confirmed the oldest and the newest of the services counted, a span of checks made at different times; with a counted service that has no such time on record there is no window. leaked_credentials: leaked_credentials.total counts (repository, secret) pairs, not distinct secrets, so one secret in three repositories counts three times; leaked_credentials.distinct_secrets counts each secret once and leaked_credentials.distinct_repos counts repositories; leaked_credentials.top_providers and leaked_credentials.top_types rank up to 15 providers and secret types by those pairs. None is validated: each is a credential-shaped string that passed EchelonGraph's filters, at most structurally checked and never tested against its provider. leaked_credentials.window.from and leaked_credentials.window.to are timestamps, not counts: when EchelonGraph's detector last found the oldest and the newest of the pairs counted. Each of those three radars also carries generated_at, when the API computed its totals, and, when the API can tell, last_run_at. kev_exposure.last_run_at, exposed_databases.last_run_at and leaked_credentials.last_run_at are timestamps, not counts: each is when that radar last completed a check, a cycle whose reads succeeded, among them a Shodan search (for exposed_databases, or its LeakIX fallback) that answered at least one query, or for leaked_credentials a read of the public GitHub event stream. A cycle that read nothing does not move it, and it is not the time of every record a radar's numbers count, which cover everything still on record, not only what the last check found. A radar whose answer carries no last_run_at has none in the result, and the note says nothing about it. shadow_ai: the result is regrouped by what each number counts. shadow_ai.confirmed_exposed counts services EchelonGraph's probes found answering without an authentication gate (liveness active, or rechecking during a re-check): confirmed_exposed.total is the sum of confirmed_exposed.by_category, and confirmed_exposed.last_24h counts those first recorded in the last 24 h. Of the shadow_ai numbers, only confirmed_exposed counts exposed services. confirmed_exposed.window.from and confirmed_exposed.window.to are timestamps, not counts: when EchelonGraph's verifier ran the probe that last decided the oldest and the newest of those services, a span of probes made at different times. shadow_ai.observed counts every Certificate Transparency or Shodan observation on record, whatever its verification state: its numbers are observed, not exposed. They are observed.total; observed.by_category (the same observations by category); observed.last_24h (those first recorded in the last 24 h); observed.trend_30d (observations per UTC day over the last 30 days); and observed.top_products, observed.top_countries and observed.top_issuers (up to ten products, countries and issuers ranked by observations, where an issuer is the certificate's CA for a Certificate Transparency observation and the hosting operator Shodan reports for a Shodan one). shadow_ai.authentication counts observations by probe outcome: authentication.observed where a probe observed an authentication gate (a 401/403, a login page or an auth marker), and authentication.not_determined where the service answered but no probe could tell. Neither authentication count is part of confirmed_exposed, and observed.total minus confirmed_exposed.total is not a count of secured services. The shadow-AI poller block carries only running and last_run_at: last_run_at is when the radar's leader last completed a Certificate Transparency (crt.sh) cycle, and its running is true only when that was within 30 minutes of the answer. mcp_servers: counts and timestamps only, no hostname. mcp_servers.total counts hostnames the AI-exposure radar has checked for an MCP server, each once by its latest verdict on record, and not every one is an MCP server; EchelonGraph's own control servers are left out, and mcp_servers.own_controls_excluded counts them. mcp_servers.total is mcp_servers.protected plus mcp_servers.pending_readjudication plus mcp_servers.not_assessed. mcp_servers.protected counts hostnames whose /mcp endpoint asked for credentials and whose OAuth protected-resource metadata validated under RFC 9728; mcp_servers.prm_via divides them by where that document was found: mcp_servers.prm_via.header, mcp_servers.prm_via.wellknown_path and mcp_servers.prm_via.wellknown_root. mcp_servers.pending_readjudication counts verdicts of a rule since replaced, not yet re-checked. mcp_servers.not_assessed counts the rest, whose protection the radar could not assess (not assessed does not mean unprotected), and mcp_servers.not_assessed_by_reason puts each in one bucket. mcp_servers.not_assessed_by_reason.identified_no_challenge holds servers that identified themselves as MCP servers and did not ask for credentials at the handshake. That is normal in MCP: authorization is optional in the spec, and a server can enforce it at tools/call instead, which EchelonGraph never sends, so this bucket is not a finding of exposure. mcp_servers.not_assessed_by_reason.resource_mismatch, mcp_servers.not_assessed_by_reason.cross_origin_pointer, mcp_servers.not_assessed_by_reason.bare_challenge_no_prm, mcp_servers.not_assessed_by_reason.pointer_unreachable, mcp_servers.not_assessed_by_reason.pointer_invalid, mcp_servers.not_assessed_by_reason.no_authorization_servers, mcp_servers.not_assessed_by_reason.wellknown_unreachable and mcp_servers.not_assessed_by_reason.metadata_invalid hold endpoints that asked for credentials but whose RFC 9728 metadata did not validate, by why, so none of them is shown to lack protection; mcp_servers.not_assessed_by_reason.challenge_unadjudicated holds endpoints that asked for credentials before that check existed, not yet re-checked. mcp_servers.not_assessed_by_reason.no_http_answer holds hostnames that gave no HTTP answer, and mcp_servers.not_assessed_by_reason.not_identified_as_mcp hostnames whose HTTP answer identified no MCP server. mcp_servers.era divides every counted hostname by protocol era: mcp_servers.era.legacy; mcp_servers.era.dual, a lower bound; mcp_servers.era.modern, not proven modern-only; mcp_servers.era.unknown; and mcp_servers.era.not_measured, recorded before the era probe and not re-checked since. mcp_servers.transport divides them by transport: mcp_servers.transport.streamable_http, mcp_servers.transport.legacy_sse, mcp_servers.transport.unknown and mcp_servers.transport.not_measured. mcp_servers.window.from and mcp_servers.window.to are when the oldest and the newest of the verdicts counted were last checked. mcp_servers.last_run_at is a timestamp, not a count: when the AI-exposure radar, which checks other AI services too, last completed a check; mcp_servers.enabled is whether one completed within 45 minutes of the answer, and mcp_servers.counted_at is when the API read the counts. A partition whose buckets do not add up to the count it divides is left out and named; an answer that does not say it is the MCP-server counts, or whose mcp_servers.total, mcp_servers.protected, mcp_servers.pending_readjudication and mcp_servers.not_assessed are missing or contradict each other, is a failure. Shodan data is owned by Shodan, which holds its copyright (© Shodan). Its structured result's state is not_assessed with measured_at null: every radar answered, but none gives one time at which what it counts was observed (mcp_servers dates its verdicts at most by a window, mcp_servers.window), so no count is presented as a dated measurement; each count is still relayed, labelled, as what that radar holds on record. freshness gives each radar's last_run_at (and running for shadow_ai, enabled for mcp_servers) where the API serves one; coverage names the radars that answered; data is the relayed result above. The result's last text block repeats the structured result without data (the first text block) and without the note's sentences (the text block before it), with which notes ends. Past 30,000 characters of JSON, the first text block holds data cut to fit, and the note says what the cut leaves out and where to read it (TEXT CUT); data in the structured result always holds it whole.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "anyOf": [
      -          {
      -            "additionalProperties": false,
      -            "properties": {
      -              "answered": {
      -                "description": "The radars that answered. On a failure their answers are withheld.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              "failed": {
      -                "description": "The radars that could not be read.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              "radars": {
      -                "description": "The radars this tool reads.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              }
      -            },
      -            "required": [
      -              "radars",
      -              "answered",
      -              "failed"
      -            ],
      -            "type": "object"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "What the answer covers; null where the answer says nothing about it."
      -      },
      -      "data": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "exposed_databases": {
      -            "additionalProperties": false,
      -            "properties": {
      -              "distinct_hosts": {
      -                "type": "number"
      -              },
      -              "engines": {
      -                "type": "number"
      -              },
      -              "generated_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "last_run_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "pci_likely": {
      -                "type": "number"
      -              },
      -              "pii_likely": {
      -                "type": "number"
      -              },
      -              "top_countries": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "country": {
      -                      "type": "string"
      -                    },
      -                    "hosts": {
      -                      "type": "number"
      -                    }
      -                  },
      -                  "required": [
      -                    "country",
      -                    "hosts"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "top_engines": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "engine": {
      -                      "type": "string"
      -                    },
      -                    "hosts": {
      -                      "type": "number"
      -                    }
      -                  },
      -                  "required": [
      -                    "engine",
      -                    "hosts"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              }
      -            },
      -            "type": "object"
      -          },
      -          "kev_exposure": {
      -            "additionalProperties": false,
      -            "properties": {
      -              "correlations": {
      -                "type": "number"
      -              },
      -              "distinct_hosts": {
      -                "type": "number"
      -              },
      -              "generated_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "kev_cves_exposed": {
      -                "type": "number"
      -              },
      -              "last_run_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "newest_kev": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "added_date": {
      -                      "type": "string"
      -                    },
      -                    "cve_id": {
      -                      "type": "string"
      -                    },
      -                    "cvss_v3_score": {
      -                      "type": "number"
      -                    },
      -                    "epss_score": {
      -                      "type": "number"
      -                    },
      -                    "exposed_hosts": {
      -                      "type": "number"
      -                    },
      -                    "exposure_state": {
      -                      "enum": [
      -                        "exposed",
      -                        "measured_zero",
      -                        "not_assessed"
      -                      ],
      -                      "type": "string"
      -                    },
      -                    "ransomware": {
      -                      "type": "boolean"
      -                    },
      -                    "severity": {
      -                      "type": "string"
      -                    },
      -                    "vuln_name": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "cve_id",
      -                    "exposure_state"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "ransomware_cves": {
      -                "type": "number"
      -              },
      -              "ransomware_hosts": {
      -                "type": "number"
      -              },
      -              "top_countries": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "country": {
      -                      "type": "string"
      -                    },
      -                    "hosts": {
      -                      "type": "number"
      -                    }
      -                  },
      -                  "required": [
      -                    "country",
      -                    "hosts"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "top_cves": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "cve_id": {
      -                      "type": "string"
      -                    },
      -                    "cvss_v3_score": {
      -                      "type": "number"
      -                    },
      -                    "epss_score": {
      -                      "type": "number"
      -                    },
      -                    "hosts": {
      -                      "type": "number"
      -                    },
      -                    "ransomware": {
      -                      "type": "boolean"
      -                    },
      -                    "severity": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "cve_id",
      -                    "hosts"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "top_products": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "hosts": {
      -                      "type": "number"
      -                    },
      -                    "product": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "product",
      -                    "hosts"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "trend": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "new_exposures": {
      -                      "type": "number"
      -                    },
      -                    "week": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "week",
      -                    "new_exposures"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              }
      -            },
      -            "type": "object"
      -          },
      -          "leaked_credentials": {
      -            "additionalProperties": false,
      -            "properties": {
      -              "distinct_repos": {
      -                "type": "number"
      -              },
      -              "distinct_secrets": {
      -                "type": "number"
      -              },
      -              "generated_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "last_run_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "top_providers": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "count": {
      -                      "type": "number"
      -                    },
      -                    "provider": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "provider",
      -                    "count"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "top_types": {
      -                "items": {
      -                  "additionalProperties": false,
      -                  "properties": {
      -                    "count": {
      -                      "type": "number"
      -                    },
      -                    "secret_type": {
      -                      "type": "string"
      -                    }
      -                  },
      -                  "required": [
      -                    "secret_type",
      -                    "count"
      -                  ],
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              "total": {
      -                "type": "number"
      -              }
      -            },
      -            "type": "object"
      -          },
      -          "mcp_servers": {
      -            "additionalProperties": false,
      -            "properties": {
      -              "counted_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "enabled": {
      -                "type": "boolean"
      -              },
      -              "era": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "dual": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "legacy": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "modern": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "not_measured": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "unknown": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  }
      -                },
      -                "required": [
      -                  "legacy",
      -                  "dual",
      -                  "modern",
      -                  "unknown",
      -                  "not_measured"
      -                ],
      -                "type": "object"
      -              },
      -              "last_run_at": {
      -                "description": "An RFC 3339 instant.",
      -                "type": "string"
      -              },
      -              "not_assessed": {
      -                "maximum": 9007199254740991,
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "not_assessed_by_reason": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "bare_challenge_no_prm": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "challenge_unadjudicated": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "cross_origin_pointer": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "identified_no_challenge": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "metadata_invalid": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "no_authorization_servers": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "no_http_answer": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "not_identified_as_mcp": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "pointer_invalid": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "pointer_unreachable": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "resource_mismatch": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "wellknown_unreachable": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  }
      -                },
      -                "required": [
      -                  "identified_no_challenge",
      -                  "resource_mismatch",
      -                  "cross_origin_pointer",
      -                  "bare_challenge_no_prm",
      -                  "pointer_unreachable",
      -                  "pointer_invalid",
      -                  "no_authorization_servers",
      -                  "wellknown_unreachable",
      -                  "metadata_invalid",
      -                  "challenge_unadjudicated",
      -                  "no_http_answer",
      -                  "not_identified_as_mcp"
      -                ],
      -                "type": "object"
      -              },
      -              "own_controls_excluded": {
      -                "maximum": 9007199254740991,
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "pending_readjudication": {
      -                "maximum": 9007199254740991,
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "prm_via": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "header": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "wellknown_path": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "wellknown_root": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  }
      -                },
      -                "required": [
      -                  "header",
      -                  "wellknown_path",
      -                  "wellknown_root"
      -                ],
      -                "type": "object"
      -              },
      -              "protected": {
      -                "maximum": 9007199254740991,
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "total": {
      -                "maximum": 9007199254740991,
      -                "minimum": 0,
      -                "type": "integer"
      -              },
      -              "transport": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "legacy_sse": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "not_measured": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "streamable_http": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  },
      -                  "unknown": {
      -                    "maximum": 9007199254740991,
      -                    "minimum": 0,
      -                    "type": "integer"
      -                  }
      -                },
      -                "required": [
      -                  "streamable_http",
      -                  "legacy_sse",
      -                  "unknown",
      -                  "not_measured"
      -                ],
      -                "type": "object"
      -              },
      -              "window": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "from": {
      -                    "description": "An RFC 3339 instant.",
      -                    "type": "string"
      -                  },
      -                  "to": {
      -                    "description": "An RFC 3339 instant.",
      -                    "type": "string"
      -                  }
      -                },
      -                "required": [
      -                  "from",
      -                  "to"
      -                ],
      -                "type": "object"
      -              }
      -            },
      -            "required": [
      -              "total",
      -              "protected",
      -              "pending_readjudication",
      -              "not_assessed"
      -            ],
      -            "type": "object"
      -          },
      -          "shadow_ai": {
      -            "additionalProperties": false,
      -            "properties": {
      -              "authentication": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "not_determined": {
      -                    "type": "number"
      -                  },
      -                  "observed": {
      -                    "type": "number"
      -                  }
      -                },
      -                "type": "object"
      -              },
      -              "confirmed_exposed": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "by_category": {
      -                    "additionalProperties": {
      -                      "type": "number"
      -                    },
      -                    "propertyNames": {
      -                      "type": "string"
      -                    },
      -                    "type": "object"
      -                  },
      -                  "last_24h": {
      -                    "type": "number"
      -                  },
      -                  "total": {
      -                    "type": "number"
      -                  }
      -                },
      -                "type": "object"
      -              },
      -              "observed": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "by_category": {
      -                    "additionalProperties": {
      -                      "type": "number"
      -                    },
      -                    "propertyNames": {
      -                      "type": "string"
      -                    },
      -                    "type": "object"
      -                  },
      -                  "last_24h": {
      -                    "type": "number"
      -                  },
      -                  "last_observation": {
      -                    "description": "An RFC 3339 instant.",
      -                    "type": "string"
      -                  },
      -                  "top_countries": {
      -                    "items": {
      -                      "additionalProperties": false,
      -                      "properties": {
      -                        "count": {
      -                          "type": "number"
      -                        },
      -                        "country": {
      -                          "type": "string"
      -                        }
      -                      },
      -                      "required": [
      -                        "country",
      -                        "count"
      -                      ],
      -                      "type": "object"
      -                    },
      -                    "type": "array"
      -                  },
      -                  "top_issuers": {
      -                    "items": {
      -                      "additionalProperties": false,
      -                      "properties": {
      -                        "count": {
      -                          "type": "number"
      -                        },
      -                        "issuer": {
      -                          "type": "string"
      -                        }
      -                      },
      -                      "required": [
      -                        "issuer",
      -                        "count"
      -                      ],
      -                      "type": "object"
      -                    },
      -                    "type": "array"
      -                  },
      -                  "top_products": {
      -                    "items": {
      -                      "additionalProperties": false,
      -                      "properties": {
      -                        "count": {
      -                          "type": "number"
      -                        },
      -                        "product": {
      -                          "type": "string"
      -                        }
      -                      },
      -                      "required": [
      -                        "product",
      -                        "count"
      -                      ],
      -                      "type": "object"
      -                    },
      -                    "type": "array"
      -                  },
      -                  "total": {
      -                    "type": "number"
      -                  },
      -                  "trend_30d": {
      -                    "items": {
      -                      "additionalProperties": false,
      -                      "properties": {
      -                        "count": {
      -                          "type": "number"
      -                        },
      -                        "date": {
      -                          "type": "string"
      -                        }
      -                      },
      -                      "required": [
      -                        "date",
      -                        "count"
      -                      ],
      -                      "type": "object"
      -                    },
      -                    "type": "array"
      -                  }
      -                },
      -                "type": "object"
      -              },
      -              "poller": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "last_run_at": {
      -                    "description": "An RFC 3339 instant.",
      -                    "type": "string"
      -                  },
      -                  "running": {
      -                    "type": "boolean"
      -                  }
      -                },
      -                "required": [
      -                  "running",
      -                  "last_run_at"
      -                ],
      -                "type": "object"
      -              }
      -            },
      -            "type": "object"
      -          }
      -        },
      -        "required": [
      -          "kev_exposure",
      -          "exposed_databases",
      -          "leaked_credentials",
      -          "shadow_ai",
      -          "mcp_servers"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "anyOf": [
      -          {
      -            "additionalProperties": false,
      -            "properties": {
      -              "exposed_databases": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "last_run_at": {
      -                    "anyOf": [
      -                      {
      -                        "description": "An RFC 3339 instant.",
      -                        "type": "string"
      -                      },
      -                      {
      -                        "type": "null"
      -                      }
      -                    ]
      -                  }
      -                },
      -                "required": [
      -                  "last_run_at"
      -                ],
      -                "type": "object"
      -              },
      -              "kev_exposure": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "last_run_at": {
      -                    "anyOf": [
      -                      {
      -                        "description": "An RFC 3339 instant.",
      -                        "type": "string"
      -                      },
      -                      {
      -                        "type": "null"
      -                      }
      -                    ]
      -                  }
      -                },
      -                "required": [
      -                  "last_run_at"
      -                ],
      -                "type": "object"
      -              },
      -              "leaked_credentials": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "last_run_at": {
      -                    "anyOf": [
      -                      {
      -                        "description": "An RFC 3339 instant.",
      -                        "type": "string"
      -                      },
      -                      {
      -                        "type": "null"
      -                      }
      -                    ]
      -                  }
      -                },
      -                "required": [
      -                  "last_run_at"
      -                ],
      -                "type": "object"
      -              },
      -              "mcp_servers": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "enabled": {
      -                    "type": [
      -                      "boolean",
      -                      "null"
      -                    ]
      -                  },
      -                  "last_run_at": {
      -                    "anyOf": [
      -                      {
      -                        "description": "An RFC 3339 instant.",
      -                        "type": "string"
      -                      },
      -                      {
      -                        "type": "null"
      -                      }
      -                    ]
      -                  }
      -                },
      -                "required": [
      -                  "last_run_at",
      -                  "enabled"
      -                ],
      -                "type": "object"
      -              },
      -              "shadow_ai": {
      -                "additionalProperties": false,
      -                "properties": {
      -                  "last_run_at": {
      -                    "anyOf": [
      -                      {
      -                        "description": "An RFC 3339 instant.",
      -                        "type": "string"
      -                      },
      -                      {
      -                        "type": "null"
      -                      }
      -                    ]
      -                  },
      -                  "running": {
      -                    "type": [
      -                      "boolean",
      -                      "null"
      -                    ]
      -                  }
      -                },
      -                "required": [
      -                  "last_run_at",
      -                  "running"
      -                ],
      -                "type": "object"
      -              }
      -            },
      -            "required": [
      -              "kev_exposure",
      -              "exposed_databases",
      -              "leaked_credentials",
      -              "shadow_ai",
      -              "mcp_servers"
      -            ],
      -            "type": "object"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "The producing radar's last completed check (last_run_at), where the API serves one."
      -      },
      -      "measured_at": {
      -        "anyOf": [
      -          {
      -            "description": "An RFC 3339 instant.",
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      -      },
      -      "method": {
      -        "description": "How the numbers were produced.",
      -        "type": "string"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      -        "enum": [
      -          "measured",
      -          "not_assessed"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "data"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "anyOf": [
      -          {
      -            "additionalProperties": false,
      -            "properties": {
      -              "answered": {
      -                "description": "The radars that answered. On a failure their answers are withheld.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              "failed": {
      -                "description": "The radars that could not be read.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              "radars": {
      -                "description": "The radars this tool reads.",
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              }
      -            },
      -            "required": [
      -              "radars",
      -              "answered",
      -              "failed"
      -            ],
      -            "type": "object"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ]
      -      },
      -      "error": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "kind": {
      -            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      -            "enum": [
      -              "network",
      -              "timeout",
      -              "http",
      -              "not_json",
      -              "not_object",
      -              "invalid_input",
      -              "internal",
      -              "unexpected_shape",
      -              "radars"
      -            ],
      -            "type": "string"
      -          },
      -          "message": {
      -            "description": "The cause: the API's own message, or what went wrong.",
      -            "type": "string"
      -          },
      -          "path": {
      -            "description": "The API path requested, when a request was made.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "radars": {
      -            "description": "Each radar that could not be read, and why.",
      -            "items": {
      -              "additionalProperties": false,
      -              "properties": {
      -                "kind": {
      -                  "enum": [
      -                    "network",
      -                    "timeout",
      -                    "http",
      -                    "not_json",
      -                    "not_object",
      -                    "unexpected_shape"
      -                  ],
      -                  "type": "string"
      -                },
      -                "message": {
      -                  "type": "string"
      -                },
      -                "path": {
      -                  "type": "string"
      -                },
      -                "radar": {
      -                  "type": "string"
      -                },
      -                "status": {
      -                  "anyOf": [
      -                    {
      -                      "maximum": 9007199254740991,
      -                      "minimum": -9007199254740991,
      -                      "type": "integer"
      -                    },
      -                    {
      -                      "type": "null"
      -                    }
      -                  ]
      -                }
      -              },
      -              "required": [
      -                "radar",
      -                "kind",
      -                "path",
      -                "status",
      -                "message"
      -              ],
      -              "type": "object"
      -            },
      -            "type": "array"
      -          },
      -          "status": {
      -            "anyOf": [
      -              {
      -                "maximum": 9007199254740991,
      -                "minimum": -9007199254740991,
      -                "type": "integer"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The HTTP status, when the API answered one."
      -          }
      -        },
      -        "required": [
      -          "kind",
      -          "path",
      -          "status",
      -          "message"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "type": "null"
      -      },
      -      "method": {
      -        "type": "null"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      -        "enum": [
      -          "failed",
      -          "invalid_input"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "error"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "answered": {
      +                "description": "The radars that answered. On a failure their answers are withheld.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              "failed": {
      +                "description": "The radars that could not be read.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              "radars": {
      +                "description": "The radars this tool reads.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              }
      +            },
      +            "required": [
      +              "radars",
      +              "answered",
      +              "failed"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "What the answer covers; null where the answer says nothing about it."
      +      },
      +      "data": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "exposed_databases": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "distinct_hosts": {
      +                "type": "number"
      +              },
      +              "engines": {
      +                "type": "number"
      +              },
      +              "generated_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "last_run_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "pci_likely": {
      +                "type": "number"
      +              },
      +              "pii_likely": {
      +                "type": "number"
      +              },
      +              "top_countries": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "country": {
      +                      "type": "string"
      +                    },
      +                    "hosts": {
      +                      "type": "number"
      +                    }
      +                  },
      +                  "required": [
      +                    "country",
      +                    "hosts"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "top_engines": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "engine": {
      +                      "type": "string"
      +                    },
      +                    "hosts": {
      +                      "type": "number"
      +                    }
      +                  },
      +                  "required": [
      +                    "engine",
      +                    "hosts"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "window": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "from": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  },
      +                  "to": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  }
      +                },
      +                "required": [
      +                  "from",
      +                  "to"
      +                ],
      +                "type": "object"
      +              }
      +            },
      +            "type": "object"
      +          },
      +          "kev_exposure": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "correlations": {
      +                "type": "number"
      +              },
      +              "distinct_hosts": {
      +                "type": "number"
      +              },
      +              "generated_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "kev_cves_exposed": {
      +                "type": "number"
      +              },
      +              "last_run_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "newest_kev": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "added_date": {
      +                      "type": "string"
      +                    },
      +                    "cve_id": {
      +                      "type": "string"
      +                    },
      +                    "cvss_v3_score": {
      +                      "type": "number"
      +                    },
      +                    "epss_score": {
      +                      "type": "number"
      +                    },
      +                    "exposed_hosts": {
      +                      "type": "number"
      +                    },
      +                    "exposure_state": {
      +                      "enum": [
      +                        "exposed",
      +                        "measured_zero",
      +                        "not_assessed"
      +                      ],
      +                      "type": "string"
      +                    },
      +                    "ransomware": {
      +                      "type": "boolean"
      +                    },
      +                    "severity": {
      +                      "type": "string"
      +                    },
      +                    "vuln_name": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "cve_id",
      +                    "exposure_state"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "ransomware_cves": {
      +                "type": "number"
      +              },
      +              "ransomware_hosts": {
      +                "type": "number"
      +              },
      +              "top_countries": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "country": {
      +                      "type": "string"
      +                    },
      +                    "hosts": {
      +                      "type": "number"
      +                    }
      +                  },
      +                  "required": [
      +                    "country",
      +                    "hosts"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "top_cves": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "cve_id": {
      +                      "type": "string"
      +                    },
      +                    "cvss_v3_score": {
      +                      "type": "number"
      +                    },
      +                    "epss_score": {
      +                      "type": "number"
      +                    },
      +                    "hosts": {
      +                      "type": "number"
      +                    },
      +                    "ransomware": {
      +                      "type": "boolean"
      +                    },
      +                    "severity": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "cve_id",
      +                    "hosts"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "top_products": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "hosts": {
      +                      "type": "number"
      +                    },
      +                    "product": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "product",
      +                    "hosts"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "trend": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "new_exposures": {
      +                      "type": "number"
      +                    },
      +                    "week": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "week",
      +                    "new_exposures"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              }
      +            },
      +            "type": "object"
      +          },
      +          "leaked_credentials": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "distinct_repos": {
      +                "type": "number"
      +              },
      +              "distinct_secrets": {
      +                "type": "number"
      +              },
      +              "generated_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "last_run_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "top_providers": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "count": {
      +                      "type": "number"
      +                    },
      +                    "provider": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "provider",
      +                    "count"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "top_types": {
      +                "items": {
      +                  "additionalProperties": false,
      +                  "properties": {
      +                    "count": {
      +                      "type": "number"
      +                    },
      +                    "secret_type": {
      +                      "type": "string"
      +                    }
      +                  },
      +                  "required": [
      +                    "secret_type",
      +                    "count"
      +                  ],
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              "total": {
      +                "type": "number"
      +              },
      +              "window": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "from": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  },
      +                  "to": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  }
      +                },
      +                "required": [
      +                  "from",
      +                  "to"
      +                ],
      +                "type": "object"
      +              }
      +            },
      +            "type": "object"
      +          },
      +          "mcp_servers": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "counted_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "enabled": {
      +                "type": "boolean"
      +              },
      +              "era": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "dual": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "legacy": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "modern": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "not_measured": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "unknown": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  }
      +                },
      +                "required": [
      +                  "legacy",
      +                  "dual",
      +                  "modern",
      +                  "unknown",
      +                  "not_measured"
      +                ],
      +                "type": "object"
      +              },
      +              "last_run_at": {
      +                "description": "An RFC 3339 instant.",
      +                "type": "string"
      +              },
      +              "not_assessed": {
      +                "maximum": 9007199254740991,
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "not_assessed_by_reason": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "bare_challenge_no_prm": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "challenge_unadjudicated": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "cross_origin_pointer": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "identified_no_challenge": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "metadata_invalid": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "no_authorization_servers": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "no_http_answer": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "not_identified_as_mcp": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "pointer_invalid": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "pointer_unreachable": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "resource_mismatch": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "wellknown_unreachable": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  }
      +                },
      +                "required": [
      +                  "identified_no_challenge",
      +                  "resource_mismatch",
      +                  "cross_origin_pointer",
      +                  "bare_challenge_no_prm",
      +                  "pointer_unreachable",
      +                  "pointer_invalid",
      +                  "no_authorization_servers",
      +                  "wellknown_unreachable",
      +                  "metadata_invalid",
      +                  "challenge_unadjudicated",
      +                  "no_http_answer",
      +                  "not_identified_as_mcp"
      +                ],
      +                "type": "object"
      +              },
      +              "own_controls_excluded": {
      +                "maximum": 9007199254740991,
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "pending_readjudication": {
      +                "maximum": 9007199254740991,
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "prm_via": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "header": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "wellknown_path": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "wellknown_root": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  }
      +                },
      +                "required": [
      +                  "header",
      +                  "wellknown_path",
      +                  "wellknown_root"
      +                ],
      +                "type": "object"
      +              },
      +              "protected": {
      +                "maximum": 9007199254740991,
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "total": {
      +                "maximum": 9007199254740991,
      +                "minimum": 0,
      +                "type": "integer"
      +              },
      +              "transport": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "legacy_sse": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "not_measured": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "streamable_http": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  },
      +                  "unknown": {
      +                    "maximum": 9007199254740991,
      +                    "minimum": 0,
      +                    "type": "integer"
      +                  }
      +                },
      +                "required": [
      +                  "streamable_http",
      +                  "legacy_sse",
      +                  "unknown",
      +                  "not_measured"
      +                ],
      +                "type": "object"
      +              },
      +              "window": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "from": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  },
      +                  "to": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  }
      +                },
      +                "required": [
      +                  "from",
      +                  "to"
      +                ],
      +                "type": "object"
      +              }
      +            },
      +            "required": [
      +              "total",
      +              "protected",
      +              "pending_readjudication",
      +              "not_assessed"
      +            ],
      +            "type": "object"
      +          },
      +          "shadow_ai": {
      +            "additionalProperties": false,
      +            "properties": {
      +              "authentication": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "not_determined": {
      +                    "type": "number"
      +                  },
      +                  "observed": {
      +                    "type": "number"
      +                  }
      +                },
      +                "type": "object"
      +              },
      +              "confirmed_exposed": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "by_category": {
      +                    "additionalProperties": {
      +                      "type": "number"
      +                    },
      +                    "propertyNames": {
      +                      "type": "string"
      +                    },
      +                    "type": "object"
      +                  },
      +                  "last_24h": {
      +                    "type": "number"
      +                  },
      +                  "total": {
      +                    "type": "number"
      +                  },
      +                  "window": {
      +                    "additionalProperties": false,
      +                    "properties": {
      +                      "from": {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      "to": {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      }
      +                    },
      +                    "required": [
      +                      "from",
      +                      "to"
      +                    ],
      +                    "type": "object"
      +                  }
      +                },
      +                "type": "object"
      +              },
      +              "observed": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "by_category": {
      +                    "additionalProperties": {
      +                      "type": "number"
      +                    },
      +                    "propertyNames": {
      +                      "type": "string"
      +                    },
      +                    "type": "object"
      +                  },
      +                  "last_24h": {
      +                    "type": "number"
      +                  },
      +                  "last_observation": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  },
      +                  "top_countries": {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "count": {
      +                          "type": "number"
      +                        },
      +                        "country": {
      +                          "type": "string"
      +                        }
      +                      },
      +                      "required": [
      +                        "country",
      +                        "count"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  },
      +                  "top_issuers": {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "count": {
      +                          "type": "number"
      +                        },
      +                        "issuer": {
      +                          "type": "string"
      +                        }
      +                      },
      +                      "required": [
      +                        "issuer",
      +                        "count"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  },
      +                  "top_products": {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "count": {
      +                          "type": "number"
      +                        },
      +                        "product": {
      +                          "type": "string"
      +                        }
      +                      },
      +                      "required": [
      +                        "product",
      +                        "count"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  },
      +                  "total": {
      +                    "type": "number"
      +                  },
      +                  "trend_30d": {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "count": {
      +                          "type": "number"
      +                        },
      +                        "date": {
      +                          "type": "string"
      +                        }
      +                      },
      +                      "required": [
      +                        "date",
      +                        "count"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  }
      +                },
      +                "type": "object"
      +              },
      +              "poller": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "last_run_at": {
      +                    "description": "An RFC 3339 instant.",
      +                    "type": "string"
      +                  },
      +                  "running": {
      +                    "type": "boolean"
      +                  }
      +                },
      +                "required": [
      +                  "running",
      +                  "last_run_at"
      +                ],
      +                "type": "object"
      +              }
      +            },
      +            "type": "object"
      +          }
      +        },
      +        "required": [
      +          "kev_exposure",
      +          "exposed_databases",
      +          "leaked_credentials",
      +          "shadow_ai",
      +          "mcp_servers"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "exposed_databases": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "last_run_at": {
      +                    "anyOf": [
      +                      {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      {
      +                        "type": "null"
      +                      }
      +                    ]
      +                  }
      +                },
      +                "required": [
      +                  "last_run_at"
      +                ],
      +                "type": "object"
      +              },
      +              "kev_exposure": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "last_run_at": {
      +                    "anyOf": [
      +                      {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      {
      +                        "type": "null"
      +                      }
      +                    ]
      +                  }
      +                },
      +                "required": [
      +                  "last_run_at"
      +                ],
      +                "type": "object"
      +              },
      +              "leaked_credentials": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "last_run_at": {
      +                    "anyOf": [
      +                      {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      {
      +                        "type": "null"
      +                      }
      +                    ]
      +                  }
      +                },
      +                "required": [
      +                  "last_run_at"
      +                ],
      +                "type": "object"
      +              },
      +              "mcp_servers": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "enabled": {
      +                    "type": [
      +                      "boolean",
      +                      "null"
      +                    ]
      +                  },
      +                  "last_run_at": {
      +                    "anyOf": [
      +                      {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      {
      +                        "type": "null"
      +                      }
      +                    ]
      +                  }
      +                },
      +                "required": [
      +                  "last_run_at",
      +                  "enabled"
      +                ],
      +                "type": "object"
      +              },
      +              "shadow_ai": {
      +                "additionalProperties": false,
      +                "properties": {
      +                  "last_run_at": {
      +                    "anyOf": [
      +                      {
      +                        "description": "An RFC 3339 instant.",
      +                        "type": "string"
      +                      },
      +                      {
      +                        "type": "null"
      +                      }
      +                    ]
      +                  },
      +                  "running": {
      +                    "type": [
      +                      "boolean",
      +                      "null"
      +                    ]
      +                  }
      +                },
      +                "required": [
      +                  "last_run_at",
      +                  "running"
      +                ],
      +                "type": "object"
      +              }
      +            },
      +            "required": [
      +              "kev_exposure",
      +              "exposed_databases",
      +              "leaked_credentials",
      +              "shadow_ai",
      +              "mcp_servers"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "The producing radar's last completed check (last_run_at), where the API serves one."
      +      },
      +      "measured_at": {
      +        "anyOf": [
      +          {
      +            "description": "An RFC 3339 instant.",
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      +      },
      +      "method": {
      +        "description": "How the numbers were produced.",
      +        "type": "string"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      +        "enum": [
      +          "measured",
      +          "not_assessed"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "data"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "answered": {
      +                "description": "The radars that answered. On a failure their answers are withheld.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              "failed": {
      +                "description": "The radars that could not be read.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              "radars": {
      +                "description": "The radars this tool reads.",
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              }
      +            },
      +            "required": [
      +              "radars",
      +              "answered",
      +              "failed"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ]
      +      },
      +      "error": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "kind": {
      +            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      +            "enum": [
      +              "network",
      +              "timeout",
      +              "http",
      +              "not_json",
      +              "not_object",
      +              "invalid_input",
      +              "internal",
      +              "unexpected_shape",
      +              "radars"
      +            ],
      +            "type": "string"
      +          },
      +          "message": {
      +            "description": "The cause: the API's own message, or what went wrong.",
      +            "type": "string"
      +          },
      +          "path": {
      +            "description": "The API path requested, when a request was made.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "radars": {
      +            "description": "Each radar that could not be read, and why.",
      +            "items": {
      +              "additionalProperties": false,
      +              "properties": {
      +                "kind": {
      +                  "enum": [
      +                    "network",
      +                    "timeout",
      +                    "http",
      +                    "not_json",
      +                    "not_object",
      +                    "unexpected_shape"
      +                  ],
      +                  "type": "string"
      +                },
      +                "message": {
      +                  "type": "string"
      +                },
      +                "path": {
      +                  "type": "string"
      +                },
      +                "radar": {
      +                  "type": "string"
      +                },
      +                "status": {
      +                  "anyOf": [
      +                    {
      +                      "maximum": 9007199254740991,
      +                      "minimum": -9007199254740991,
      +                      "type": "integer"
      +                    },
      +                    {
      +                      "type": "null"
      +                    }
      +                  ]
      +                }
      +              },
      +              "required": [
      +                "radar",
      +                "kind",
      +                "path",
      +                "status",
      +                "message"
      +              ],
      +              "type": "object"
      +            },
      +            "type": "array"
      +          },
      +          "status": {
      +            "anyOf": [
      +              {
      +                "maximum": 9007199254740991,
      +                "minimum": -9007199254740991,
      +                "type": "integer"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The HTTP status, when the API answered one."
      +          }
      +        },
      +        "required": [
      +          "kind",
      +          "path",
      +          "status",
      +          "message"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "type": "null"
      +      },
      +      "method": {
      +        "type": "null"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      +        "enum": [
      +          "failed",
      +          "invalid_input"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "error"
      +    ],
      +    "type": "object"
      +  }
      +]
  2. First observed

TDQS

A3.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Despite readOnlyHint=true, the description discloses that this is 'not a pure read' because probes name their client on Redis and are logged in ClickHouse's query log, plus data provenance (Shodan, LeakIX fallback, Certificate Transparency), that the MCP probe never sends tools/call, refresh cadences, staleness windows and the failure conditions for the MCP block. It also spells out truncation behavior past 30,000 characters of JSON and what the state=not_assessed result means. This is far beyond what the annotations convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose is front-loaded, but the body is an enormous single-paragraph run-on that prose-documents essentially the entire output schema field by field, for a tool that already has an output schema. 'timestamps, not counts' and similar counting disclaimers are repeated many times, so much of the text is redundant rather than additive.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a high-complexity multi-radar aggregate, the description covers provenance, side effects, per-field counting semantics, staleness/refresh semantics, failure detection, and response-truncation behaviour. An agent can interpret the returned counts correctly without opening the output schema, so nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so the schema has nothing to document and there is no parameter behaviour to add meaning to. Baseline for a parameterless tool is 4; the description cannot score higher because no parameter semantics exist to clarify.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb and resource ('aggregate totals from EchelonGraph's internet-exposure radars') and enumerates the exact content (KEV exposure, exposed databases, leaked credentials, shadow AI, MCP-server counts), which lets an agent distinguish this broad aggregate endpoint from the per-CVE siblings like get_cve or cve_exposure. It is clear and specific, but it never explicitly contrasts itself with those sibling tools, so it falls short of full sibling differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied: the tool is the overview of radar totals, but there is no sentence saying when to reach for this instead of cve_exposure, kev_recent or search_cves. It does supply substantial interpretation guidance (e.g. a service outside pii_likely is not shown to hold no such data; a missing last_run_at means the note says nothing), which is helpful context but not when-to-use routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.