Skip to main content
Glama
d4ngkh04w

NVD/NIST MCP server

by d4ngkh04w

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
LOG_LEVELNoLog level: debug | info | warn | error | silent.info
NVD_API_KEYNoNVD API key, sent as the `apiKey` header only. Optional but recommended; without it the public API allows roughly 5 requests / 30 s.
SQLITE_PATHNoDatabase file path../data/nvd.sqlite
NVD_BASE_URLNoUpstream base URL (HTTPS, or HTTP for localhost).https://services.nvd.nist.gov/rest/json
CURSOR_SECRETNoHMAC key for cursors; set it (>= 16 chars) to keep cursors valid across restarts.random per process
CACHE_DIRECTORYNoJSON disk cache directory../data/cache
NVD_MAX_RETRIESNoRetries on 429/5xx/network errors.4
CURSOR_TTL_SECONDSNoCursor lifetime, in seconds.1800
NVD_MIN_INTERVAL_MSNoMinimum gap between upstream requests, in milliseconds.6000
NVD_REQUEST_TIMEOUT_MSNoPer-request timeout, in milliseconds.15000

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
nvd_get_cveA

Return the full NVD record for one CVE: description, all CVSS metrics, CWEs, configurations, references and CISA KEV status. Use nvd_get_cve_summary for the essentials, nvd_get_cves for a batch. Cached for 24 hours; on an NVD outage the stale copy is returned with a warning in meta.warnings.

nvd_get_cve_summaryA

Return a compact view of one CVE: id, timestamps, status, English summary, primary CVSS score, CWEs, affected products, KEV flag and reference count. Configurations, references and the raw payload are omitted - use nvd_get_cve for those. Derived from the cached record, so it shares the same 24 hour freshness window.

nvd_get_cvesA

Return summaries for up to 100 CVE identifiers in one call. Identifiers are uppercased and de-duplicated; only missing or stale ones are fetched, in one batch. Reports foundIds, missingIds and meta.requested/found/missing; use nvd_get_cve for a full record.

nvd_search_cvesA

Search CVE records with the NVD 2.0 filters: keyword, CVE IDs, CPE name or match string, CWE, source identifier, vuln statuses, published/last-modified windows, KEV window, CVSS metrics and CERT flags. Rules: keywordExactMatch requires keyword; isVulnerable requires cpeName; cpeName and virtualMatchString are mutually exclusive; date windows are limited to 120 days. NVD evaluates every filter, so totalResults is the exact upstream total. Cached for 15 minutes; paginate by passing pagination.nextCursor back as cursor with the same filters and pageSize.

nvd_get_cve_historyA

Return the change history of one CVE: "New CVE Received", "Initial Analysis", "CVE Modified", "Rejected" and similar events, with their field-level changes and timestamps. Filter by eventName or changeBetween (maximum 120 days). Cached for 1 hour; paginate with the opaque cursor.

nvd_get_recent_cvesA

Return CVEs ordered by publication date, newest first (ordering "published_desc"). Defaults to the last 7 days: use days or an explicit start+end window (mutually exclusive, maximum 120 days). Cached for 5 minutes; paginate by passing pagination.nextCursor back as cursor with the same filters and pageSize - the resolved window travels inside the cursor, so a relative days window stays stable across pages.

nvd_get_modified_cvesA

Return CVEs ordered by last-modified date, newest first (ordering "last_modified_desc"). Defaults to the last 7 days: use days or an explicit start+end window (mutually exclusive, maximum 120 days). All filters are sent to NVD, so totalResults is the exact upstream total. Cached for 5 minutes; paginate by passing pagination.nextCursor back as cursor with the same filters and pageSize - the resolved window travels inside the cursor, so a relative days window stays stable across pages.

nvd_search_cpesA

Search the NVD Official CPE Dictionary by keyword, match string, criteria UUID, or last-modified window. At least one filter is required; date windows are limited to 120 days. Deprecated CPEs are filtered locally unless includeDeprecated is true. totalResults is the upstream NVD count before local filtering, so it may be greater than returned items or even > 0 with an empty items array when matching entries are filtered out. Results are cached for 24 hours and use opaque cursor pagination; reuse nextCursor with the same filters and pageSize.

nvd_get_cpeA

Return one entry of the NVD Official CPE Dictionary. Provide exactly one of cpeNameId (preferred, exact) or cpeName. cpeName is resolved by upstream pattern search over at most 3 pages; if the exact name is not in that window the tool returns CPE_NOT_FOUND with the scanned/total counts and suggests nvd_search_cpes. That search ignores the deprecation filter, so deprecated entries resolve too. Entries are cached for 7 days.

nvd_search_cpe_matchesA

Search CPE Match Criteria, which link CVEs to CPE names and version ranges. At least one filter is required: cveId, matchCriteriaId, matchStringSearch or lastModified (maximum 120 days). matchStringSearch must be a complete CPE match string such as cpe:2.3:a:vendor:product::::::::; upstream rejects partial keywords and version ranges. Cached for 24 hours; paginate with the opaque cursor.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.3/5.0

Scored across 10 tools

Disambiguation4/5

Tool names and descriptions clearly delineate resource+action, but nvd_get_recent_cves and nvd_get_modified_cves are nearly identical except for ordering, and nvd_get_cve, nvd_get_cve_summary, and nvd_get_cves all target CVE records with overlapping semantics. The descriptions do distinguish scope and detail level, but an agent could easily misselect between the full, summary, and batch variants without careful reading.

Naming Consistency5/5

Every tool follows a consistent nvd_ verb_noun pattern (get, search, and entity names like cve, cves, cpe). Variants like nvd_get_cve_summary and nvd_get_cve_history extend the base name predictably. No mixed conventions or inconsistent casing.

Tool Count5/5

Ten tools is well within the sweet spot for a domain-specific API wrapper. Each tool maps to a distinct NVD endpoint or use case (single record, batch, search, history, CPE dictionary, CPE matches), so the surface feels scoped rather than padded.

Completeness4/5

The surface covers CVE retrieval (single, batch, summary, search, history, recent, modified) and CPE lookup (search, get, matches), which is core NVD functionality. Missing operations like CVE creation or modification don't apply since NVD is read-only, but there is no tool for bulk CPE dictionary listing or NVD API status, which could be minor gaps for some workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues