get_product_vex
Return the VEX MANIFEST for one of the caller's products — metadata, not the document.
Multi-megabyte CycloneDX documents (up to 8,000+ vulnerability entries)
are not safe model-context payloads, so this tool returns a bounded
manifest: CycloneDX format/spec version, product id, generated/expires
timestamps, the VEX hash and the composite ETag identity, the
uncompressed size in bytes, total + per-status vulnerability counts,
and the authenticated REST download path. Reads from the 24h
ProductVexCache; if the cache is empty/expired the next call to
``get_product`` (or the REST endpoint) will regenerate it.
The MANIFEST carries the same ``kernelscan.io:exploit_maturity`` /
``kernelscan.io:kev`` overlay identity as the REST download
(backend#337), so ETags compare across transports.
To inspect the entries themselves, use ``list_product_vex_entries``.
To retrieve the COMPLETE CycloneDX document, use the authenticated
REST endpoint ``GET /api/products/{product_id}/vex`` (same ks_live_
key) — that is the canonical way to retrieve the full artifact; no
MCP tool returns it.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| product_id | Yes |