Skip to main content
Glama

EchelonGraph CVE & Exposure

Vendor advisory detail

get_vendor_advisory
Read-onlyIdempotent

One vendor advisory in full, by vendor and the vendor's advisory ID (the vendor and vendor_advisory_id fields of a row from search_vendor_advisories or vendor_advisories_for_cve): title, description, severity, cvss_v3_score, cve_ids and known_cve_ids (those with a record in EchelonGraph's CVE feed), affected_products, remediation, references, vendor_modified_at, and withdrawn_at and withdrawn_reason when the vendor withdrew it. Each advisory carries vendor_published_at (the vendor's date), our_first_seen_at (when EchelonGraph first recorded it) and withdrawn (true: the vendor rescinded it; the note names each such advisory). coverage.vendor_window is that vendor's window in what EchelonGraph holds: vendor, advisories (how many EchelonGraph holds from that vendor), earliest_vendor_published_at and latest_vendor_published_at (the earliest and latest vendor_published_at among them, null when none is held) and history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried); null when the windows could not be read or carry none for that vendor. measured_at is our_first_seen_at. Its structured result carries state (measured), measured_at, method, coverage, freshness (null: the answer carries no poll-completion time) and notes, with data equal to the API's JSON; the result's last text block repeats it without data (the first text block) and without the note's sentences (the text block before it), with which notes ends. Past 30,000 characters of JSON, the first text block holds data cut to fit, and the note says what the cut leaves out and where to read it (TEXT CUT); data in the structured result always holds it whole.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
vendorYesthe vendor slug, e.g. microsoft, redhat, github
advisory_idYesthe vendor's advisory ID, e.g. RHSA-2024:1234 or GHSA-xxxx-xxxx-xxxx

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "description": "What the answer covers; null where the answer says nothing about it.",
      -        "type": "null"
      -      },
      -      "data": {
      -        "additionalProperties": {},
      -        "properties": {
      -          "advisory_id": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "affected_products": {
      -            "anyOf": [
      -              {
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ]
      -          },
      -          "cve_ids": {
      -            "anyOf": [
      -              {
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ]
      -          },
      -          "cvss_v3_score": {
      -            "type": [
      -              "number",
      -              "null"
      -            ]
      -          },
      -          "description": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "known_cve_ids": {
      -            "anyOf": [
      -              {
      -                "items": {
      -                  "type": "string"
      -                },
      -                "type": "array"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The CVE IDs of cve_ids that have a record in EchelonGraph's CVE feed."
      -          },
      -          "our_first_seen_at": {
      -            "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "references": {},
      -          "remediation": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "severity": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "summary": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "title": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "vendor": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "vendor_advisory_id": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "vendor_display_name": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "vendor_modified_at": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "vendor_published_at": {
      -            "description": "The date the vendor gives for the advisory.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "withdrawn": {
      -            "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
      -            "type": [
      -              "boolean",
      -              "null"
      -            ]
      -          },
      -          "withdrawn_at": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "withdrawn_reason": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          }
      -        },
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "anyOf": [
      -          {
      -            "description": "An RFC 3339 instant.",
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      -      },
      -      "method": {
      -        "description": "How the numbers were produced.",
      -        "type": "string"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      -        "enum": [
      -          "measured",
      -          "not_assessed"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "data"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "type": "null"
      -      },
      -      "error": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "kind": {
      -            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      -            "enum": [
      -              "network",
      -              "timeout",
      -              "http",
      -              "not_json",
      -              "not_object",
      -              "invalid_input",
      -              "internal",
      -              "unexpected_shape",
      -              "radars"
      -            ],
      -            "type": "string"
      -          },
      -          "message": {
      -            "description": "The cause: the API's own message, or what went wrong.",
      -            "type": "string"
      -          },
      -          "path": {
      -            "description": "The API path requested, when a request was made.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "status": {
      -            "anyOf": [
      -              {
      -                "maximum": 9007199254740991,
      -                "minimum": -9007199254740991,
      -                "type": "integer"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The HTTP status, when the API answered one."
      -          }
      -        },
      -        "required": [
      -          "kind",
      -          "path",
      -          "status",
      -          "message"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "type": "null"
      -      },
      -      "method": {
      -        "type": "null"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      -        "enum": [
      -          "failed",
      -          "invalid_input"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "error"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "vendor_window": {
      +                "anyOf": [
      +                  {
      +                    "additionalProperties": false,
      +                    "properties": {
      +                      "advisories": {
      +                        "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
      +                        "type": [
      +                          "number",
      +                          "null"
      +                        ]
      +                      },
      +                      "earliest_vendor_published_at": {
      +                        "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      },
      +                      "history_backfill": {
      +                        "anyOf": [
      +                          {
      +                            "anyOf": [
      +                              {
      +                                "enum": [
      +                                  "complete",
      +                                  "in_progress",
      +                                  "not_started",
      +                                  "not_supported"
      +                                ],
      +                                "type": "string"
      +                              },
      +                              {
      +                                "type": "string"
      +                              }
      +                            ]
      +                          },
      +                          {
      +                            "type": "null"
      +                          }
      +                        ],
      +                        "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
      +                      },
      +                      "latest_vendor_published_at": {
      +                        "description": "The latest vendor_published_at among them; null when none is held.",
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      },
      +                      "vendor": {
      +                        "description": "The vendor slug.",
      +                        "type": "string"
      +                      },
      +                      "vendor_display_name": {
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      }
      +                    },
      +                    "required": [
      +                      "vendor",
      +                      "vendor_display_name",
      +                      "advisories",
      +                      "earliest_vendor_published_at",
      +                      "latest_vendor_published_at",
      +                      "history_backfill"
      +                    ],
      +                    "type": "object"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "This advisory's vendor's window in what EchelonGraph holds; null when the windows could not be read or carry none for this vendor."
      +              }
      +            },
      +            "required": [
      +              "vendor_window"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "What the answer covers; null where the answer says nothing about it."
      +      },
      +      "data": {
      +        "additionalProperties": {},
      +        "properties": {
      +          "advisory_id": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "affected_products": {
      +            "anyOf": [
      +              {
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ]
      +          },
      +          "cve_ids": {
      +            "anyOf": [
      +              {
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ]
      +          },
      +          "cvss_v3_score": {
      +            "type": [
      +              "number",
      +              "null"
      +            ]
      +          },
      +          "description": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "known_cve_ids": {
      +            "anyOf": [
      +              {
      +                "items": {
      +                  "type": "string"
      +                },
      +                "type": "array"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The CVE IDs of cve_ids that have a record in EchelonGraph's CVE feed."
      +          },
      +          "our_first_seen_at": {
      +            "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "references": {},
      +          "remediation": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "severity": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "summary": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "title": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "vendor": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "vendor_advisory_id": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "vendor_display_name": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "vendor_modified_at": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "vendor_published_at": {
      +            "description": "The date the vendor gives for the advisory.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "withdrawn": {
      +            "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
      +            "type": [
      +              "boolean",
      +              "null"
      +            ]
      +          },
      +          "withdrawn_at": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "withdrawn_reason": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          }
      +        },
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "anyOf": [
      +          {
      +            "description": "An RFC 3339 instant.",
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      +      },
      +      "method": {
      +        "description": "How the numbers were produced.",
      +        "type": "string"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      +        "enum": [
      +          "measured",
      +          "not_assessed"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "data"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "vendor_window": {
      +                "anyOf": [
      +                  {
      +                    "additionalProperties": false,
      +                    "properties": {
      +                      "advisories": {
      +                        "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
      +                        "type": [
      +                          "number",
      +                          "null"
      +                        ]
      +                      },
      +                      "earliest_vendor_published_at": {
      +                        "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      },
      +                      "history_backfill": {
      +                        "anyOf": [
      +                          {
      +                            "anyOf": [
      +                              {
      +                                "enum": [
      +                                  "complete",
      +                                  "in_progress",
      +                                  "not_started",
      +                                  "not_supported"
      +                                ],
      +                                "type": "string"
      +                              },
      +                              {
      +                                "type": "string"
      +                              }
      +                            ]
      +                          },
      +                          {
      +                            "type": "null"
      +                          }
      +                        ],
      +                        "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
      +                      },
      +                      "latest_vendor_published_at": {
      +                        "description": "The latest vendor_published_at among them; null when none is held.",
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      },
      +                      "vendor": {
      +                        "description": "The vendor slug.",
      +                        "type": "string"
      +                      },
      +                      "vendor_display_name": {
      +                        "type": [
      +                          "string",
      +                          "null"
      +                        ]
      +                      }
      +                    },
      +                    "required": [
      +                      "vendor",
      +                      "vendor_display_name",
      +                      "advisories",
      +                      "earliest_vendor_published_at",
      +                      "latest_vendor_published_at",
      +                      "history_backfill"
      +                    ],
      +                    "type": "object"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "This advisory's vendor's window in what EchelonGraph holds; null when the windows could not be read or carry none for this vendor."
      +              }
      +            },
      +            "required": [
      +              "vendor_window"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ]
      +      },
      +      "error": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "kind": {
      +            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      +            "enum": [
      +              "network",
      +              "timeout",
      +              "http",
      +              "not_json",
      +              "not_object",
      +              "invalid_input",
      +              "internal",
      +              "unexpected_shape",
      +              "radars"
      +            ],
      +            "type": "string"
      +          },
      +          "message": {
      +            "description": "The cause: the API's own message, or what went wrong.",
      +            "type": "string"
      +          },
      +          "path": {
      +            "description": "The API path requested, when a request was made.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "anyOf": [
      +              {
      +                "maximum": 9007199254740991,
      +                "minimum": -9007199254740991,
      +                "type": "integer"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The HTTP status, when the API answered one."
      +          }
      +        },
      +        "required": [
      +          "kind",
      +          "path",
      +          "status",
      +          "message"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "type": "null"
      +      },
      +      "method": {
      +        "type": "null"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      +        "enum": [
      +          "failed",
      +          "invalid_input"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "error"
      +    ],
      +    "type": "object"
      +  }
      +]
  2. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover read-only, idempotent, open-world, and non-destructive behavior. The description adds substantial behavioral detail beyond annotations: the result fields, coverage.vendor_window semantics, freshness, measured_at, structured result shape, and truncation behavior past 30,000 characters including what the first text block contains and where full data lives.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The core purpose is front-loaded in the first clause, but the remainder is a dense wall of implementation details about return fields, coverage windows, structured results, and truncation. Given that an output schema already exists, much of this is redundant, making the description less concise than it could be.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only single-advisory fetch with annotations and an output schema, the description is more than complete: it covers purpose, argument provenance, returned advisory fields, coverage metadata, structured result behavior, and text truncation. No essential context for correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents the vendor slug and advisory ID formats with examples. The description adds meaning by identifying vendor and advisory_id as fields from rows returned by search_vendor_advisories or vendor_advisories_for_cve, helping the agent know where to obtain them.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: 'One vendor advisory in full, by vendor and the vendor's advisory ID'. It distinguishes this detail-fetch tool from sibling search/list tools by naming search_vendor_advisories and vendor_advisories_for_cve as sources for the input IDs.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clarifies that the vendor and advisory_id arguments are the corresponding fields from search_vendor_advisories or vendor_advisories_for_cve, implying it is used after finding an advisory. It gives clear context but does not state explicit when-not conditions or direct alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.