Skip to main content
Glama
Citedrelevance

BreachSpider MCP server

Official

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
BREACHSPIDER_API_KEYNoYour BreachSpider API key. Get a free 14 day trial key at breachspider.com/developers. With no key the server runs in demo mode: public example access only, using a short lived public demo token.
BREACHSPIDER_BASE_URLNoPoints the server at another BreachSpider deployment.https://breachspider.com

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
correlate_devicesA

Find the CVEs that affect specific devices at their exact firmware or software version. Use this for any specific device and firmware. Send vendor, product and version exactly as the inventory says; no CPE is needed. Returns, per device: how it resolved, data coverage, an honest assessment, warnings, needs_review, result_hash (keep it for check_changes), the fix plan, and the top findings in priority order (known-exploited and confirmed first). Each finding gives the affected range with its source, the fix, advisory guidance and vendor advisories: cite the range source and the vendor advisory when explaining it. Report needs_review and partial coverage honestly and never call an empty, unresolved or partial result clean. Never send host names, IP or MAC addresses, user names or site names; such fields are stripped and listed under privacy.

check_changesA

Cheap repeat check. For devices you already checked with correlate_devices, send the same vendor, product and version plus the result_hash you kept. Returns which devices changed and their new hash; only changed devices need a fresh correlate_devices call. Use this for repeat checks. Never send host names, IP or MAC addresses, user names or site names.

get_fix_planA

Fix plan for one device: fix groups (which update clears which CVEs) and the fix plan (the single step that clears the known-exploited CVEs, and the one that clears everything fixable). Send vendor, product and version exactly as the inventory says. Says so plainly when the device did not resolve or coverage is partial. Never send host names, IP or MAC addresses, user names or site names.

lookup_cveA

Look up one CVE by id (for example CVE-2024-9137) and return BreachSpider's record, trimmed: severity, CVSS, known-exploited status, EPSS, fix status, vendor and CISA ICS advisories and links. It is not device specific; to know whether a device is affected, use correlate_devices.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.2/5.0

Scored across 4 tools

Disambiguation4/5

Each tool has a fairly distinct purpose: correlate_devices (device-to-CVE mapping), check_changes (cheap re-check via result_hash), lookup_cve (single CVE by id), and get_fix_plan (per-device remediation). The one soft overlap is that correlate_devices already returns a fix plan in its output while get_fix_plan offers a dedicated per-device plan, which could cause an agent to hesitate; descriptions mostly resolve this.

Naming Consistency5/5

All four tools follow a clean snake_case verb_noun pattern: correlate_devices, check_changes, lookup_cve, get_fix_plan. The convention is uniform throughout with no mixed styles or casing.

Tool Count4/5

Four tools is lean but appropriate for a focused device-vulnerability correlation service, and each earns its place (correlate, re-check, CVE lookup, fix plan). It is on the thin side, with no room for batch or search operations.

Completeness4/5

The core lifecycle is covered: correlate devices, cheaply detect changes, look up individual CVEs, and get a fix plan. Minor gaps exist—no cross-cutting CVE search (by keyword/severity) or a tool to enumerate inventory—but the primary workflows are complete and the result_hash linkage is a thoughtful touch.