Skip to main content
Glama

cisa-cybersecurity-mcp-server

cisa_search_ics_advisories

cisa_search_ics_advisories
Read-onlyIdempotent

Search the CISA industrial control system advisory corpus — every CSAF 2.0 advisory covering PLC, HMI, SCADA, building-automation, and medical-device products from 2010 onward. Filter by vendor, product, CVE, CWE, CVSS range, severity band, critical-infrastructure sector, advisory series, publication date, revision date, or whether an advisory covers a CVE in the CISA Known Exploited Vulnerabilities catalog, and run full-text search over advisory titles and product names. Sector filtering reaches only advisories that carry a sector note, which begins in 2017; the response reports how many documents a sector filter can never match. Returns advisory IDs for cisa_get_advisory, the CVEs each advisory covers and which of them are in KEV, and the source URL and attribution every advisory response carries.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
qNoFull-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored, and a token with no letter or digit is ignored. Needs at least one word or number.
cveNoExact CVE membership, e.g. CVE-2021-44228. Case and surrounding whitespace are normalized.
cweNoExact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. Case and surrounding whitespace are normalized. A parent class does not match its children.
inKevNotrue selects advisories covering at least one CVE in the CISA Known Exploited Vulnerabilities catalog; false selects advisories covering none. Checked against every CVE an advisory covers, not only the twenty listed per result.
limitNoMaximum advisories per page.
orderNoSort direction. Under relevance, desc means most relevant first.desc
cursorNoOpaque pagination cursor from a previous call. Omit for the first page.
sectorNoCritical-infrastructure sector, matched against the normalized sector set. Multiple is the sentinel the corpus uses for an advisory affecting many sectors.
seriesNoAdvisory series: ICSA industrial control system advisories, or ICSMA medical-device advisories, a small minority of the corpus.
sortByNoField to sort by. relevance requires q and ranks by FTS5 bm25.revised
vendorNoCase-insensitive substring of a vendor label, matched literally — % and _ are ordinary characters. Vendor names are unnormalized upstream — the same company appears under several spellings — so this is substring, not exact.
cvssMaxNoMaximum value of the advisory's maximum CVSS base score, inclusive.
cvssMinNoMinimum value of the advisory's maximum CVSS base score, inclusive.
productNoCase-insensitive substring of a product name, matched literally — % and _ are ordinary characters.
severityNoSeverity band of the advisory's maximum CVSS score.
publisherNocoordinator selects CISA-authored advisories; other selects vendor advisories CISA republished, over a quarter of the corpus.
revisedToNoLatest current release date, inclusive, YYYY-MM-DD.
publishedToNoLatest initial release date, inclusive, YYYY-MM-DD.
revisedFromNoEarliest current release date, inclusive, YYYY-MM-DD.
publishedFromNoEarliest initial release date, inclusive, YYYY-MM-DD.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
capNoThe page limit that was applied.
errorNoPresent when the call failed. Absent on success.
shownNoAdvisories returned on this page.
cursorNoOpaque cursor for the next page. Absent when this is the last page.
mirrorNoWhich index state answered this call.
noticeNoGuidance when nothing matched — the filter that matches no advisory on its own and what dropping it restores, or the filters whose removal restores results and how many — when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete.
hasMoreNoWhether more matches exist beyond this page.
resultsNoMatching advisories for this page.
truncatedNoTrue when the page limit capped this result.
totalCountNoTotal matches before paging.
cvssCoverageNoDisclosure of derived-band and no-score coverage under a score filter.
appliedFiltersNoThe filters the server actually applied.
sectorCoverageNoDisclosure of how many advisories a sector filter can never match.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed7 schema fields changed
    • changedInput schema / properties / cve / description
      Previous value: -"Exact CVE membership, e.g. CVE-2021-44228. Case and surrounding whitespace are normalized. The corpus covers 12,321 distinct CVEs."New value: +"Exact CVE membership, e.g. CVE-2021-44228. Case and surrounding whitespace are normalized."
    • changedInput schema / properties / publisher / description
      Previous value: -"coordinator selects CISA-authored advisories (2,863); other selects republished vendor advisories (1,063)."New value: +"coordinator selects CISA-authored advisories; other selects vendor advisories CISA republished, over a quarter of the corpus."
    • changedInput schema / properties / series / description
      Previous value: -"Advisory series: ICSA (3,738 documents) or ICSMA medical devices (188)."New value: +"Advisory series: ICSA industrial control system advisories, or ICSMA medical-device advisories, a small minority of the corpus."
    • changedOutput schema / properties / error / properties / data / properties / reason / description
      Previous value: -"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. `empty_search_text`: q contains no word or number once quotes and punctuation are removed, so there is nothing to search for. `catalog_unavailable`: inKev is set, no KEV catalog snapshot is held, and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler."New value: +"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `mirror_unavailable`: The advisory index store cannot be opened: its location is not writable, is read-only, runs through a missing directory or a file, or holds a file that is not a SQLite database. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. `empty_search_text`: q contains no word or number once quotes and punctuation are removed, so there is nothing to search for. `catalog_unavailable`: inKev is set, no KEV catalog snapshot is held, and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler."
    • changedOutput schema / properties / error / properties / data / properties / reason / examples
      Previous value: -[
      -  "mirror_not_ready",
      -  "invalid_cvss_range",
      -  "invalid_date_range",
      -  "relevance_sort_without_query",
      -  "empty_search_text",
      -  "catalog_unavailable"
      -]New value: +[
      +  "mirror_not_ready",
      +  "mirror_unavailable",
      +  "invalid_cvss_range",
      +  "invalid_date_range",
      +  "relevance_sort_without_query",
      +  "empty_search_text",
      +  "catalog_unavailable"
      +]
    • changedOutput schema / properties / notice / description
      Previous value: -"Guidance when nothing matched, when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete."New value: +"Guidance when nothing matched — the filter that matches no advisory on its own and what dropping it restores, or the filters whose removal restores results and how many — when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete."
    • changedOutput schema / properties / results / items / properties / maxCvss / description
      Previous value: -"Highest CVSS score across the advisory. Absent on the two advisories with no CVSS."New value: +"Highest CVSS score across the advisory. Absent when the advisory carries no CVSS score."
  2. Changed3 schema fields changed
    • changedInput schema / properties / cve / description
      Previous value: -"Exact CVE membership. The corpus covers 12,321 distinct CVEs."New value: +"Exact CVE membership, e.g. CVE-2021-44228. Case and surrounding whitespace are normalized. The corpus covers 12,321 distinct CVEs."
    • changedInput schema / properties / cwe / description
      Previous value: -"Exact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. A parent class does not match its children."New value: +"Exact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. Case and surrounding whitespace are normalized. A parent class does not match its children."
    • changedOutput schema / properties / results / items / properties / advisoryId / pattern
      Previous value: -"^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[a-z]|-\\d+)?$"New value: +"^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[A-Z]|-\\d+)?$"
  3. Changed9 schema fields changed
    • addedInput schema / properties / cwe
      Added value: +{
      +  "description": "Exact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. A parent class does not match its children.",
      +  "pattern": "^CWE-[0-9]+$",
      +  "type": "string"
      +}
    • addedInput schema / properties / inKev
      Added value: +{
      +  "description": "true selects advisories covering at least one CVE in the CISA Known Exploited Vulnerabilities catalog; false selects advisories covering none. Checked against every CVE an advisory covers, not only the twenty listed per result.",
      +  "type": "boolean"
      +}
    • changedInput schema / properties / product / description
      Previous value: -"Case-insensitive substring of a product name."New value: +"Case-insensitive substring of a product name, matched literally — % and _ are ordinary characters."
    • changedInput schema / properties / q / description
      Previous value: -"Full-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored."New value: +"Full-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored, and a token with no letter or digit is ignored. Needs at least one word or number."
    • changedInput schema / properties / vendor / description
      Previous value: -"Case-insensitive substring of a vendor label. Vendor names are unnormalized upstream — the same company appears under several spellings — so this is substring, not exact."New value: +"Case-insensitive substring of a vendor label, matched literally — % and _ are ordinary characters. Vendor names are unnormalized upstream — the same company appears under several spellings — so this is substring, not exact."
    • changedOutput schema / properties / error / properties / data / properties / reason / description
      Previous value: -"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. Other values are possible when a failure originates below the handler."New value: +"Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. `empty_search_text`: q contains no word or number once quotes and punctuation are removed, so there is nothing to search for. `catalog_unavailable`: inKev is set, no KEV catalog snapshot is held, and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler."
    • changedOutput schema / properties / error / properties / data / properties / reason / examples
      Previous value: -[
      -  "mirror_not_ready",
      -  "invalid_cvss_range",
      -  "invalid_date_range",
      -  "relevance_sort_without_query"
      -]New value: +[
      +  "mirror_not_ready",
      +  "invalid_cvss_range",
      +  "invalid_date_range",
      +  "relevance_sort_without_query",
      +  "empty_search_text",
      +  "catalog_unavailable"
      +]
    • changedOutput schema / properties / notice / description
      Previous value: -"Guidance when nothing matched."New value: +"Guidance when nothing matched, when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete."
    • addedOutput schema / properties / results / items / properties / kevCves
      Added value: +{
      +  "description": "Every CVE this advisory covers that is in the KEV catalog, drawn from its full CVE list rather than the twenty in cves. Empty when none is; absent when KEV membership could not be evaluated.",
      +  "items": {
      +    "description": "One CVE identifier.",
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
  4. First observed

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already signal a read-only, idempotent search, and the description adds materially beyond them: the sector-filter coverage gap (sector notes only begin in 2017 and the response reports how many documents can never match), plus the guarantee that every response carries source URL and attribution. No behavior contradicts the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three dense sentences: scope, filter surface, then caveat and return contract. For a 20-parameter tool this is appropriately sized and front-loaded, with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite high complexity, everything an agent needs to decide and invoke correctly is present: corpus definition, filter categories, a critical coverage caveat, and output contract. The rich input/output schemas handle the remaining details.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema carries nearly all parameter meaning; the description adds a high-level taxonomy of the filter dimensions. The one genuinely new semantic is the sector parameter's limitation, which is not expressed in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource — search the CISA ICS advisory corpus — and further delimits the corpus by standard (CSAF 2.0), product families, and date range. It also states what the call returns (advisory IDs, CVEs, KEV flags, source URL/attribution), which separates it from sibling getter/search tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context for when to call it: to search the whole ICS advisory corpus across many filter dimensions, and it wires the result into cisa_get_advisory. It does not explicitly name alternatives like cisa_search_kev or say when not to use this tool, so it misses the full when/when-not bar.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.