Skip to main content
Glama
Cyreslab-AI

CIRCL CVE SEARCH MCP Server

get_cve

Read-only

Retrieve detailed vulnerability data for any CVE ID, including analysis and references, to assess security risks and inform remediation efforts.

Instructions

Get detailed information about a specific CVE by its ID with enhanced data analysis

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cve_idYesCVE identifier (e.g., "CVE-2021-44228")

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
titleYes
cve_idYes
summaryYes
raw_dataNoFull raw CVE record as returned by the platform
discoveryNo
referencesNo
weaknessesNo
affected_systemsNo
security_detailsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.2.0

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and openWorldHint=true, so the safety profile is covered. The description adds only 'enhanced data analysis,' which is too vague to meaningfully disclose behavior such as enrichment, external lookups, or response shaping. No contradiction exists, but the description contributes limited additional behavioral context beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence that immediately identifies the resource and operation. It is not bloated, but the trailing 'with enhanced data analysis' is vague and does not earn its place with concrete information, keeping it slightly below a perfect score.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a single-parameter, read-only lookup tool with full schema documentation, an output schema, and safety annotations, the description is almost sufficient. It lacks explicit sibling differentiation or guidance about what 'enhanced data analysis' includes, but the core invocation context is adequately covered.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with the cve_id parameter fully documented including a pattern and example. The description restates the concept of 'by its ID' but adds no new parameter semantics beyond what the schema already provides. Baseline 3 is appropriate since the schema carries the documentation burden.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb and resource: 'Get detailed information about a specific CVE by its ID.' This clearly distinguishes it from sibling tools like get_recent_vulnerabilities (which lists by recency) and get_cwe/get_capec (which query different knowledge bases). The only minor weakness is the vague phrase 'enhanced data analysis,' but it does not obscure the core purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'specific CVE by its ID' provides clear usage context: call this tool when you already have a concrete CVE identifier. It does not explicitly name alternatives or state when not to use it, but the scope is clear enough to route an agent correctly relative to the sibling tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.