Skip to main content
Glama

EchelonGraph CVE & Exposure

Vendor advisories for one CVE

vendor_advisories_for_cve
Read-onlyIdempotent

The vendor-published advisories that name one CVE, newest first, at most 20: for each, vendor, vendor_display_name, vendor_advisory_id, title, severity and cvss_v3_score where the vendor gives them. Covers the vendor feeds EchelonGraph polls, for example Microsoft MSRC, Red Hat, Cisco, Palo Alto Networks and GitHub GHSA; an empty answer means that none of the advisories EchelonGraph holds from those feeds names the CVE, not that no vendor published one (see vendor_windows and vendors_not_fully_held). Each advisory carries vendor_published_at (the vendor's date), our_first_seen_at (when EchelonGraph first recorded it) and withdrawn (true: the vendor rescinded it; the note names each such advisory). Pass a CVE ID like CVE-2024-21412. coverage gives returned, cap and at_cap (true: the answer is full, so there may be more); cve_year, the year in the CVE ID; vendor_windows, each vendor's window in what EchelonGraph holds: vendor, advisories (how many EchelonGraph holds from that vendor), earliest_vendor_published_at and latest_vendor_published_at (the earliest and latest vendor_published_at among them, null when none is held) and history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried); and vendors_not_fully_held, the vendors with no advisory in the answer of which EchelonGraph holds none, whose earliest held advisory is dated after 1 January of cve_year, or whose history is still being read, which the note names. An advisory a vendor published before its earliest_vendor_published_at is not held, so no advisory from a vendor is not a finding that it published none. vendor_windows and vendors_not_fully_held are null when the windows could not be read, and the note says so. measured_at is null. Its structured result carries state (measured), measured_at, method, coverage, freshness (null: the answer carries no poll-completion time) and notes, with data equal to the API's JSON; the result's last text block repeats it without data (the first text block) and without the note's sentences (the text block before it), with which notes ends. Past 30,000 characters of JSON, the first text block holds data cut to fit, and the note says what the cut leaves out and where to read it (TEXT CUT); data in the structured result always holds it whole. Cut, each row keeps vendor, vendor_advisory_id, title, severity and cve_ids at least, its strings and lists shortened.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cve_idYesa CVE ID, e.g. CVE-2024-21412

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • changedOutput schema / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "anyOf": [
      -          {
      -            "additionalProperties": false,
      -            "properties": {
      -              "at_cap": {
      -                "description": "true: the answer is full, so the vendor feeds may hold more advisories for this CVE than it lists.",
      -                "type": [
      -                  "boolean",
      -                  "null"
      -                ]
      -              },
      -              "cap": {
      -                "description": "The most the API returns for one CVE, newest first.",
      -                "type": "number"
      -              },
      -              "returned": {
      -                "description": "The advisories in this answer.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              }
      -            },
      -            "required": [
      -              "returned",
      -              "cap",
      -              "at_cap"
      -            ],
      -            "type": "object"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "What the answer covers; null where the answer says nothing about it."
      -      },
      -      "data": {
      -        "additionalProperties": {},
      -        "properties": {
      -          "advisories": {
      -            "anyOf": [
      -              {
      -                "items": {
      -                  "additionalProperties": {},
      -                  "properties": {
      -                    "advisory_id": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "affected_products": {
      -                      "anyOf": [
      -                        {
      -                          "items": {
      -                            "type": "string"
      -                          },
      -                          "type": "array"
      -                        },
      -                        {
      -                          "type": "null"
      -                        }
      -                      ]
      -                    },
      -                    "cve_ids": {
      -                      "anyOf": [
      -                        {
      -                          "items": {
      -                            "type": "string"
      -                          },
      -                          "type": "array"
      -                        },
      -                        {
      -                          "type": "null"
      -                        }
      -                      ]
      -                    },
      -                    "cvss_v3_score": {
      -                      "type": [
      -                        "number",
      -                        "null"
      -                      ]
      -                    },
      -                    "our_first_seen_at": {
      -                      "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "severity": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "summary": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "title": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "vendor": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "vendor_advisory_id": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "vendor_display_name": {
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "vendor_published_at": {
      -                      "description": "The date the vendor gives for the advisory.",
      -                      "type": [
      -                        "string",
      -                        "null"
      -                      ]
      -                    },
      -                    "withdrawn": {
      -                      "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
      -                      "type": [
      -                        "boolean",
      -                        "null"
      -                      ]
      -                    }
      -                  },
      -                  "type": "object"
      -                },
      -                "type": "array"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ]
      -          },
      -          "cve_id": {
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "total": {
      -            "type": [
      -              "number",
      -              "null"
      -            ]
      -          }
      -        },
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "anyOf": [
      -          {
      -            "description": "An RFC 3339 instant.",
      -            "type": "string"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ],
      -        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      -      },
      -      "method": {
      -        "description": "How the numbers were produced.",
      -        "type": "string"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      -        "enum": [
      -          "measured",
      -          "not_assessed"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "data"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "coverage": {
      -        "anyOf": [
      -          {
      -            "additionalProperties": false,
      -            "properties": {
      -              "at_cap": {
      -                "description": "true: the answer is full, so the vendor feeds may hold more advisories for this CVE than it lists.",
      -                "type": [
      -                  "boolean",
      -                  "null"
      -                ]
      -              },
      -              "cap": {
      -                "description": "The most the API returns for one CVE, newest first.",
      -                "type": "number"
      -              },
      -              "returned": {
      -                "description": "The advisories in this answer.",
      -                "type": [
      -                  "number",
      -                  "null"
      -                ]
      -              }
      -            },
      -            "required": [
      -              "returned",
      -              "cap",
      -              "at_cap"
      -            ],
      -            "type": "object"
      -          },
      -          {
      -            "type": "null"
      -          }
      -        ]
      -      },
      -      "error": {
      -        "additionalProperties": false,
      -        "properties": {
      -          "kind": {
      -            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      -            "enum": [
      -              "network",
      -              "timeout",
      -              "http",
      -              "not_json",
      -              "not_object",
      -              "invalid_input",
      -              "internal",
      -              "unexpected_shape",
      -              "radars"
      -            ],
      -            "type": "string"
      -          },
      -          "message": {
      -            "description": "The cause: the API's own message, or what went wrong.",
      -            "type": "string"
      -          },
      -          "path": {
      -            "description": "The API path requested, when a request was made.",
      -            "type": [
      -              "string",
      -              "null"
      -            ]
      -          },
      -          "status": {
      -            "anyOf": [
      -              {
      -                "maximum": 9007199254740991,
      -                "minimum": -9007199254740991,
      -                "type": "integer"
      -              },
      -              {
      -                "type": "null"
      -              }
      -            ],
      -            "description": "The HTTP status, when the API answered one."
      -          }
      -        },
      -        "required": [
      -          "kind",
      -          "path",
      -          "status",
      -          "message"
      -        ],
      -        "type": "object"
      -      },
      -      "freshness": {
      -        "type": "null"
      -      },
      -      "measured_at": {
      -        "type": "null"
      -      },
      -      "method": {
      -        "type": "null"
      -      },
      -      "notes": {
      -        "description": "Caveats, one sentence each.",
      -        "items": {
      -          "type": "string"
      -        },
      -        "type": "array"
      -      },
      -      "state": {
      -        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      -        "enum": [
      -          "failed",
      -          "invalid_input"
      -        ],
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "state",
      -      "measured_at",
      -      "method",
      -      "coverage",
      -      "freshness",
      -      "notes",
      -      "error"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "at_cap": {
      +                "description": "true: the answer is full, so the vendor feeds may hold more advisories for this CVE than it lists.",
      +                "type": [
      +                  "boolean",
      +                  "null"
      +                ]
      +              },
      +              "cap": {
      +                "description": "The most the API returns for one CVE, newest first.",
      +                "type": "number"
      +              },
      +              "cve_year": {
      +                "description": "The year in the CVE ID.",
      +                "type": "number"
      +              },
      +              "returned": {
      +                "description": "The advisories in this answer.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "vendor_windows": {
      +                "anyOf": [
      +                  {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "advisories": {
      +                          "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
      +                          "type": [
      +                            "number",
      +                            "null"
      +                          ]
      +                        },
      +                        "earliest_vendor_published_at": {
      +                          "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        },
      +                        "history_backfill": {
      +                          "anyOf": [
      +                            {
      +                              "anyOf": [
      +                                {
      +                                  "enum": [
      +                                    "complete",
      +                                    "in_progress",
      +                                    "not_started",
      +                                    "not_supported"
      +                                  ],
      +                                  "type": "string"
      +                                },
      +                                {
      +                                  "type": "string"
      +                                }
      +                              ]
      +                            },
      +                            {
      +                              "type": "null"
      +                            }
      +                          ],
      +                          "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
      +                        },
      +                        "latest_vendor_published_at": {
      +                          "description": "The latest vendor_published_at among them; null when none is held.",
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        },
      +                        "vendor": {
      +                          "description": "The vendor slug.",
      +                          "type": "string"
      +                        },
      +                        "vendor_display_name": {
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        }
      +                      },
      +                      "required": [
      +                        "vendor",
      +                        "vendor_display_name",
      +                        "advisories",
      +                        "earliest_vendor_published_at",
      +                        "latest_vendor_published_at",
      +                        "history_backfill"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "Each vendor's window in what EchelonGraph holds; null when the windows could not be read. An advisory a vendor published before its earliest_vendor_published_at is not held, so no advisory from a vendor is not a finding that it published none."
      +              },
      +              "vendors_not_fully_held": {
      +                "anyOf": [
      +                  {
      +                    "items": {
      +                      "type": "string"
      +                    },
      +                    "type": "array"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "The vendors with no advisory in this answer that may have published one EchelonGraph does not hold: none held, the earliest held dated after 1 January of cve_year, or history_backfill in_progress or not_started. No advisory from them is not a finding that they published none. null when the windows could not be read."
      +              }
      +            },
      +            "required": [
      +              "returned",
      +              "cap",
      +              "at_cap",
      +              "cve_year",
      +              "vendor_windows",
      +              "vendors_not_fully_held"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "What the answer covers; null where the answer says nothing about it."
      +      },
      +      "data": {
      +        "additionalProperties": {},
      +        "properties": {
      +          "advisories": {
      +            "anyOf": [
      +              {
      +                "items": {
      +                  "additionalProperties": {},
      +                  "properties": {
      +                    "advisory_id": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "affected_products": {
      +                      "anyOf": [
      +                        {
      +                          "items": {
      +                            "type": "string"
      +                          },
      +                          "type": "array"
      +                        },
      +                        {
      +                          "type": "null"
      +                        }
      +                      ]
      +                    },
      +                    "cve_ids": {
      +                      "anyOf": [
      +                        {
      +                          "items": {
      +                            "type": "string"
      +                          },
      +                          "type": "array"
      +                        },
      +                        {
      +                          "type": "null"
      +                        }
      +                      ]
      +                    },
      +                    "cvss_v3_score": {
      +                      "type": [
      +                        "number",
      +                        "null"
      +                      ]
      +                    },
      +                    "our_first_seen_at": {
      +                      "description": "When EchelonGraph first recorded the advisory; not the vendor's date.",
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "severity": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "summary": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "title": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "vendor": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "vendor_advisory_id": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "vendor_display_name": {
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "vendor_published_at": {
      +                      "description": "The date the vendor gives for the advisory.",
      +                      "type": [
      +                        "string",
      +                        "null"
      +                      ]
      +                    },
      +                    "withdrawn": {
      +                      "description": "true: the vendor withdrew (rescinded) this advisory; report it as withdrawn.",
      +                      "type": [
      +                        "boolean",
      +                        "null"
      +                      ]
      +                    }
      +                  },
      +                  "type": "object"
      +                },
      +                "type": "array"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ]
      +          },
      +          "cve_id": {
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "total": {
      +            "type": [
      +              "number",
      +              "null"
      +            ]
      +          }
      +        },
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "description": "The producing radar's last completed check (last_run_at), where the API serves one.",
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "anyOf": [
      +          {
      +            "description": "An RFC 3339 instant.",
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "description": "When the underlying observation was made, as the API states it; null when the answer does not say or holds no observation."
      +      },
      +      "method": {
      +        "description": "How the numbers were produced.",
      +        "type": "string"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "measured: a measurement of what was asked; an exposure count is measured only with measured_at and method. not_assessed: the answer holds no dated measurement of what was asked, so no count in it is presented as one; it can still relay a count, as what the source holds on record, undated, and its notes (and exposure_state, where the result carries it) say what each count is.",
      +        "enum": [
      +          "measured",
      +          "not_assessed"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "data"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "coverage": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": false,
      +            "properties": {
      +              "at_cap": {
      +                "description": "true: the answer is full, so the vendor feeds may hold more advisories for this CVE than it lists.",
      +                "type": [
      +                  "boolean",
      +                  "null"
      +                ]
      +              },
      +              "cap": {
      +                "description": "The most the API returns for one CVE, newest first.",
      +                "type": "number"
      +              },
      +              "cve_year": {
      +                "description": "The year in the CVE ID.",
      +                "type": "number"
      +              },
      +              "returned": {
      +                "description": "The advisories in this answer.",
      +                "type": [
      +                  "number",
      +                  "null"
      +                ]
      +              },
      +              "vendor_windows": {
      +                "anyOf": [
      +                  {
      +                    "items": {
      +                      "additionalProperties": false,
      +                      "properties": {
      +                        "advisories": {
      +                          "description": "How many advisories EchelonGraph holds from this vendor, withdrawn ones not counted.",
      +                          "type": [
      +                            "number",
      +                            "null"
      +                          ]
      +                        },
      +                        "earliest_vendor_published_at": {
      +                          "description": "The earliest vendor_published_at among them; null when none is held. An advisory this vendor published before it is not held.",
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        },
      +                        "history_backfill": {
      +                          "anyOf": [
      +                            {
      +                              "anyOf": [
      +                                {
      +                                  "enum": [
      +                                    "complete",
      +                                    "in_progress",
      +                                    "not_started",
      +                                    "not_supported"
      +                                  ],
      +                                  "type": "string"
      +                                },
      +                                {
      +                                  "type": "string"
      +                                }
      +                              ]
      +                            },
      +                            {
      +                              "type": "null"
      +                            }
      +                          ],
      +                          "description": "history_backfill: complete (the vendor's published history has been read back as far as its source goes), in_progress or not_started (it is still being read, so the vendor's older advisories are not all held yet), or not_supported (EchelonGraph has no history read for that vendor, so what it holds is what the vendor's feed has carried)."
      +                        },
      +                        "latest_vendor_published_at": {
      +                          "description": "The latest vendor_published_at among them; null when none is held.",
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        },
      +                        "vendor": {
      +                          "description": "The vendor slug.",
      +                          "type": "string"
      +                        },
      +                        "vendor_display_name": {
      +                          "type": [
      +                            "string",
      +                            "null"
      +                          ]
      +                        }
      +                      },
      +                      "required": [
      +                        "vendor",
      +                        "vendor_display_name",
      +                        "advisories",
      +                        "earliest_vendor_published_at",
      +                        "latest_vendor_published_at",
      +                        "history_backfill"
      +                      ],
      +                      "type": "object"
      +                    },
      +                    "type": "array"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "Each vendor's window in what EchelonGraph holds; null when the windows could not be read. An advisory a vendor published before its earliest_vendor_published_at is not held, so no advisory from a vendor is not a finding that it published none."
      +              },
      +              "vendors_not_fully_held": {
      +                "anyOf": [
      +                  {
      +                    "items": {
      +                      "type": "string"
      +                    },
      +                    "type": "array"
      +                  },
      +                  {
      +                    "type": "null"
      +                  }
      +                ],
      +                "description": "The vendors with no advisory in this answer that may have published one EchelonGraph does not hold: none held, the earliest held dated after 1 January of cve_year, or history_backfill in_progress or not_started. No advisory from them is not a finding that they published none. null when the windows could not be read."
      +              }
      +            },
      +            "required": [
      +              "returned",
      +              "cap",
      +              "at_cap",
      +              "cve_year",
      +              "vendor_windows",
      +              "vendors_not_fully_held"
      +            ],
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ]
      +      },
      +      "error": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "kind": {
      +            "description": "What failed: the request (network, timeout), the answer (http, not_json, not_object, unexpected_shape), the input, or this server.",
      +            "enum": [
      +              "network",
      +              "timeout",
      +              "http",
      +              "not_json",
      +              "not_object",
      +              "invalid_input",
      +              "internal",
      +              "unexpected_shape",
      +              "radars"
      +            ],
      +            "type": "string"
      +          },
      +          "message": {
      +            "description": "The cause: the API's own message, or what went wrong.",
      +            "type": "string"
      +          },
      +          "path": {
      +            "description": "The API path requested, when a request was made.",
      +            "type": [
      +              "string",
      +              "null"
      +            ]
      +          },
      +          "status": {
      +            "anyOf": [
      +              {
      +                "maximum": 9007199254740991,
      +                "minimum": -9007199254740991,
      +                "type": "integer"
      +              },
      +              {
      +                "type": "null"
      +              }
      +            ],
      +            "description": "The HTTP status, when the API answered one."
      +          }
      +        },
      +        "required": [
      +          "kind",
      +          "path",
      +          "status",
      +          "message"
      +        ],
      +        "type": "object"
      +      },
      +      "freshness": {
      +        "type": "null"
      +      },
      +      "measured_at": {
      +        "type": "null"
      +      },
      +      "method": {
      +        "type": "null"
      +      },
      +      "notes": {
      +        "description": "Caveats, one sentence each.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "type": "array"
      +      },
      +      "state": {
      +        "description": "failed: the lookup did not complete. invalid_input: the input was refused, so nothing was looked up. Neither is a finding.",
      +        "enum": [
      +          "failed",
      +          "invalid_input"
      +        ],
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "state",
      +      "measured_at",
      +      "method",
      +      "coverage",
      +      "freshness",
      +      "notes",
      +      "error"
      +    ],
      +    "type": "object"
      +  }
      +]
  2. First observed

TDQS

A3.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover read-only/idempotent/open-world safety, yet the description adds substantial behavior the annotations cannot: the 20-row cap, newest-first ordering, withdrawn-advisory flagging, null semantics for measured_at/freshness, the coverage object (returned/cap/at_cap), and the 30,000-character truncation rule including what the cut preserves and where the whole data lives. This is unusually rich disclosure for a read-only tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose is front-loaded, but the body is one enormous run-on paragraph that buries return-shape details, truncation rules and null semantics together with no headings or bullets. Much of that material duplicates the output schema, so the size is not earning its place in the description.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given a single required param, an existing output schema and a complex response (coverage, vendor_windows, vendors_not_fully_held, notes), the description is thorough about nulls, truncation and empty-result interpretation. It is nearly over-complete; the only gap is that it never explicitly routes the agent against sibling advisory tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the single cve_id parameter is already documented, and the description's 'Pass a CVE ID like CVE-2024-21412' merely repeats the schema example. It does add the derived cve_year concept, but that is a response field rather than input guidance, so baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource+scope: the vendor-published advisories naming one CVE, newest first, capped at 20. It also enumerates the covered feeds (MSRC, Red Hat, Cisco, Palo Alto, GHSA), which separates it from siblings like get_vendor_advisory and search_vendor_advisories without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is implied by 'the vendor-published advisories that name one CVE' and the caveat that an empty answer means EchelonGraph holds none, not that no vendor published one. However it never explicitly contrasts this tool with get_vendor_advisory or search_vendor_advisories, and its references to vendor_windows/vendors_not_fully_held are response fields, not alternative tools, so the agent must infer when to prefer this call.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.