NVD/NIST MCP server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| LOG_LEVEL | No | Log level: debug | info | warn | error | silent. | info |
| NVD_API_KEY | No | NVD API key, sent as the `apiKey` header only. Optional but recommended; without it the public API allows roughly 5 requests / 30 s. | |
| SQLITE_PATH | No | Database file path. | ./data/nvd.sqlite |
| NVD_BASE_URL | No | Upstream base URL (HTTPS, or HTTP for localhost). | https://services.nvd.nist.gov/rest/json |
| CURSOR_SECRET | No | HMAC key for cursors; set it (>= 16 chars) to keep cursors valid across restarts. | random per process |
| CACHE_DIRECTORY | No | JSON disk cache directory. | ./data/cache |
| NVD_MAX_RETRIES | No | Retries on 429/5xx/network errors. | 4 |
| CURSOR_TTL_SECONDS | No | Cursor lifetime, in seconds. | 1800 |
| NVD_MIN_INTERVAL_MS | No | Minimum gap between upstream requests, in milliseconds. | 6000 |
| NVD_REQUEST_TIMEOUT_MS | No | Per-request timeout, in milliseconds. | 15000 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| nvd_get_cveA | Return the full NVD record for one CVE: description, all CVSS metrics, CWEs, configurations, references and CISA KEV status. Use nvd_get_cve_summary for the essentials, nvd_get_cves for a batch. Cached for 24 hours; on an NVD outage the stale copy is returned with a warning in meta.warnings. |
| nvd_get_cve_summaryA | Return a compact view of one CVE: id, timestamps, status, English summary, primary CVSS score, CWEs, affected products, KEV flag and reference count. Configurations, references and the raw payload are omitted - use nvd_get_cve for those. Derived from the cached record, so it shares the same 24 hour freshness window. |
| nvd_get_cvesA | Return summaries for up to 100 CVE identifiers in one call. Identifiers are uppercased and de-duplicated; only missing or stale ones are fetched, in one batch. Reports foundIds, missingIds and meta.requested/found/missing; use nvd_get_cve for a full record. |
| nvd_search_cvesA | Search CVE records with the NVD 2.0 filters: keyword, CVE IDs, CPE name or match string, CWE, source identifier, vuln statuses, published/last-modified windows, KEV window, CVSS metrics and CERT flags. Rules: keywordExactMatch requires keyword; isVulnerable requires cpeName; cpeName and virtualMatchString are mutually exclusive; date windows are limited to 120 days. NVD evaluates every filter, so totalResults is the exact upstream total. Cached for 15 minutes; paginate by passing pagination.nextCursor back as |
| nvd_get_cve_historyA | Return the change history of one CVE: "New CVE Received", "Initial Analysis", "CVE Modified", "Rejected" and similar events, with their field-level changes and timestamps. Filter by eventName or changeBetween (maximum 120 days). Cached for 1 hour; paginate with the opaque cursor. |
| nvd_get_recent_cvesA | Return CVEs ordered by publication date, newest first (ordering "published_desc"). Defaults to the last 7 days: use |
| nvd_get_modified_cvesA | Return CVEs ordered by last-modified date, newest first (ordering "last_modified_desc"). Defaults to the last 7 days: use |
| nvd_search_cpesA | Search the NVD Official CPE Dictionary by keyword, match string, criteria UUID, or last-modified window. At least one filter is required; date windows are limited to 120 days. Deprecated CPEs are filtered locally unless includeDeprecated is true. totalResults is the upstream NVD count before local filtering, so it may be greater than returned items or even > 0 with an empty items array when matching entries are filtered out. Results are cached for 24 hours and use opaque cursor pagination; reuse nextCursor with the same filters and pageSize. |
| nvd_get_cpeA | Return one entry of the NVD Official CPE Dictionary. Provide exactly one of cpeNameId (preferred, exact) or cpeName. cpeName is resolved by upstream pattern search over at most 3 pages; if the exact name is not in that window the tool returns CPE_NOT_FOUND with the scanned/total counts and suggests nvd_search_cpes. That search ignores the deprecation filter, so deprecated entries resolve too. Entries are cached for 7 days. |
| nvd_search_cpe_matchesA | Search CPE Match Criteria, which link CVEs to CPE names and version ranges. At least one filter is required: cveId, matchCriteriaId, matchStringSearch or lastModified (maximum 120 days). matchStringSearch must be a complete CPE match string such as cpe:2.3:a:vendor:product::::::::; upstream rejects partial keywords and version ranges. Cached for 24 hours; paginate with the opaque cursor. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Tool names and descriptions clearly delineate resource+action, but nvd_get_recent_cves and nvd_get_modified_cves are nearly identical except for ordering, and nvd_get_cve, nvd_get_cve_summary, and nvd_get_cves all target CVE records with overlapping semantics. The descriptions do distinguish scope and detail level, but an agent could easily misselect between the full, summary, and batch variants without careful reading.
Every tool follows a consistent nvd_ verb_noun pattern (get, search, and entity names like cve, cves, cpe). Variants like nvd_get_cve_summary and nvd_get_cve_history extend the base name predictably. No mixed conventions or inconsistent casing.
Ten tools is well within the sweet spot for a domain-specific API wrapper. Each tool maps to a distinct NVD endpoint or use case (single record, batch, search, history, CPE dictionary, CPE matches), so the surface feels scoped rather than padded.
The surface covers CVE retrieval (single, batch, summary, search, history, recent, modified) and CPE lookup (search, get, matches), which is core NVD functionality. Missing operations like CVE creation or modification don't apply since NVD is read-only, but there is no tool for bulk CPE dictionary listing or NVD API status, which could be minor gaps for some workflows.