Skip to main content
Glama
RedHatInsights

Red Hat Lightspeed MCP

Official

vulnerability__get_system_cves

Read-only

Retrieve CVEs affecting a system by its UUID. Filter by CVE name, sort, and paginate results.

Instructions

Get list of CVEs affecting a given system.

IMPORTANT: Prefer get_cves as get_cves can filter for CVEs with available advisories.

This is a report of CVEs affecting a given system. Use this tool to obtain list of all CVEs affecting a given system. For more info refer to OpenAPI spec

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
system_uuidYesSystems Inventory UUID. Example : 123e4567-e89b-12d3-a456-426614174000 (Required)
filter_NoFull text filter for the CVE name.
limitNoPagination - Maximum number of records per page.
offsetNoPagination - Offset of first record of paginated response.
sortNoAttribute sorting. Use `-` prefix to sort in descending order.-public_date

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, so the description's label 'This is a report' aligns and adds minimal extra context. No contradictions. The description doesn't disclose pagination or ordering behavior, but these are covered in schema. With annotations, the burden is lower.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is somewhat repetitive: 'This is a report of CVEs affecting a given system' and 'Use this tool to obtain list of all CVEs affecting a given system' say the same thing. The important note about get_cves is valuable, but the redundancy reduces conciseness.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the high schema coverage and presence of output schema, the description is adequate. It explains the tool's purpose, gives usage guidance, and indicates it's a report (read-only). Missing details like pagination or sort are covered by schema. A reference to OpenAPI spec is a minor supplement.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents each parameter. The description does not add additional meaning beyond what is in schema, such as clarifying formats or usage constraints. Baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'Get list of CVEs affecting a given system' and explicitly distinguishes from sibling `get_cves` by noting that `get_cves` can filter for CVEs with advisories. Purpose is specific verb+resource with differentiation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit guidance: 'IMPORTANT: Prefer `get_cves` as `get_cves` can filter for CVEs with available advisories', indicating when not to use this tool and pointing to an alternative. It also states when to use this tool: 'Use this tool to obtain list of all CVEs affecting a given system'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/RedHatInsights/insights-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server