CVE MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PYTHONPATH | No | The Python path to include the project root directory |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_cve_detailsA | Get detailed information about a specific CVE by its ID. Returns severity, CVSS score, description, and references. |
| search_cvesB | Search CVEs by keyword in description |
| get_statisticsB | Get database stats (count, date range, last update) |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: get_cve_details retrieves specific CVE data, get_statistics provides database metrics, and search_cves finds CVEs by keyword. There is no overlap in functionality, making tool selection straightforward for an agent.
All tool names follow a consistent verb_noun pattern with snake_case: get_cve_details, get_statistics, and search_cves. The naming is predictable and readable, with no deviations in style.
With only 3 tools, the server feels thin for a CVE database server, as it lacks operations like filtering by severity, date, or CVSS score, or updating/listing capabilities. However, the core functions are present, making it borderline appropriate.
The server covers basic retrieval (get details, search) and statistics, but there are notable gaps: no create, update, or delete operations for managing CVEs, and no advanced querying options. This limits functionality but allows for core lookup tasks.