Red Hat Security Data API MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_csafA | Search Red Hat CSAF advisory documents by date, severity, CVE, package, Bugzilla ID, or RHSA ID. Returns a paginated list of advisory summaries. |
| get_csaf_detailsA | Retrieve the full CSAF document for a specific Red Hat Security Advisory (RHSA) by its ID. |
| search_cvesA | Search Red Hat CVEs by date, severity, CVSSv3 score, CWE, package, product, advisory, or Bugzilla ID. Returns a paginated list of CVE summaries. |
| get_cve_detailsA | Retrieve full details for a specific CVE including severity, CVSS scores, affected releases, package state, mitigations, and references. |
| list_oval_streamsB | List available Red Hat OVAL v2 stream files, optionally filtered by product label or modification date. |
| get_oval_streamA | Retrieve OVAL stream data for a specific Red Hat product by base name (e.g. RHEL7, RHEL9). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool targets a distinct resource type and action: CSAF search/detail, CVE search/detail, and OVAL list/retrieve. The resource nouns are explicit, so there is no meaningful overlap between search_csaf and search_cves or between the detail retrieval tools.
All tool names follow a clear verb_noun pattern with search_, get_, and list_ prefixes. The naming is consistent and predictable: search_* for queries, get_*_details/get_*_stream for fetching individual items, and list_* for enumerating available streams.
Six tools is well-scoped for a security data lookup server. The set covers three data types with paired search/list and detail retrieval operations, and every tool maps to a meaningful API action without redundancy or bloat.
The server provides both discovery/search and full-detail access for CSAF advisories, CVEs, and OVAL streams. As a read-only security data API, no create/update/delete operations are expected, and the retrieval lifecycle is effectively complete.