vulnerability_scan_check
Assess vulnerability scanning compliance against PCI DSS ASV requirements. Input scan dates and results to identify gaps and generate compliance documentation.
Instructions
Evaluate vulnerability scanning compliance per PCI DSS ASV requirements.
Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage.
When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation.
When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice.
Args: last_external_scan_date (str): The last external scan date to analyze or process. last_internal_scan_date (str): The last internal scan date to analyze or process. external_scan_passed (bool): The external scan passed to analyze or process. internal_scan_passed (bool): The internal scan passed to analyze or process. asv_vendor (str): The asv vendor to analyze or process. quarterly_scans (bool): The quarterly scans to analyze or process. scan_after_changes (bool): The scan after changes to analyze or process. api_key (str): The api key to analyze or process.
Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| last_external_scan_date | No | ||
| last_internal_scan_date | No | ||
| external_scan_passed | No | ||
| internal_scan_passed | No | ||
| asv_vendor | No | ||
| quarterly_scans | No | ||
| scan_after_changes | No | ||
| caller | No | ||
| api_key | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |