BreachSpider MCP server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| BREACHSPIDER_API_KEY | No | Your BreachSpider API key. Get a free 14 day trial key at breachspider.com/developers. With no key the server runs in demo mode: public example access only, using a short lived public demo token. | |
| BREACHSPIDER_BASE_URL | No | Points the server at another BreachSpider deployment. | https://breachspider.com |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| correlate_devicesA | Find the CVEs that affect specific devices at their exact firmware or software version. Use this for any specific device and firmware. Send vendor, product and version exactly as the inventory says; no CPE is needed. Returns, per device: how it resolved, data coverage, an honest assessment, warnings, needs_review, result_hash (keep it for check_changes), the fix plan, and the top findings in priority order (known-exploited and confirmed first). Each finding gives the affected range with its source, the fix, advisory guidance and vendor advisories: cite the range source and the vendor advisory when explaining it. Report needs_review and partial coverage honestly and never call an empty, unresolved or partial result clean. Never send host names, IP or MAC addresses, user names or site names; such fields are stripped and listed under privacy. |
| check_changesA | Cheap repeat check. For devices you already checked with correlate_devices, send the same vendor, product and version plus the result_hash you kept. Returns which devices changed and their new hash; only changed devices need a fresh correlate_devices call. Use this for repeat checks. Never send host names, IP or MAC addresses, user names or site names. |
| get_fix_planA | Fix plan for one device: fix groups (which update clears which CVEs) and the fix plan (the single step that clears the known-exploited CVEs, and the one that clears everything fixable). Send vendor, product and version exactly as the inventory says. Says so plainly when the device did not resolve or coverage is partial. Never send host names, IP or MAC addresses, user names or site names. |
| lookup_cveA | Look up one CVE by id (for example CVE-2024-9137) and return BreachSpider's record, trimmed: severity, CVSS, known-exploited status, EPSS, fix status, vendor and CISA ICS advisories and links. It is not device specific; to know whether a device is affected, use correlate_devices. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a fairly distinct purpose: correlate_devices (device-to-CVE mapping), check_changes (cheap re-check via result_hash), lookup_cve (single CVE by id), and get_fix_plan (per-device remediation). The one soft overlap is that correlate_devices already returns a fix plan in its output while get_fix_plan offers a dedicated per-device plan, which could cause an agent to hesitate; descriptions mostly resolve this.
All four tools follow a clean snake_case verb_noun pattern: correlate_devices, check_changes, lookup_cve, get_fix_plan. The convention is uniform throughout with no mixed styles or casing.
Four tools is lean but appropriate for a focused device-vulnerability correlation service, and each earns its place (correlate, re-check, CVE lookup, fix plan). It is on the thin side, with no room for batch or search operations.
The core lifecycle is covered: correlate devices, cheaply detect changes, look up individual CVEs, and get a fix plan. Minor gaps exist—no cross-cutting CVE search (by keyword/severity) or a tool to enumerate inventory—but the primary workflows are complete and the result_hash linkage is a thoughtful touch.