Red Hat Security Data API MCP Server
# Red Hat Security Data API MCP Server
A [Model Context Protocol](https://modelcontextprotocol.io/) (MCP) server that gives LLMs like Claude access to the [Red Hat Security Data API](https://access.redhat.com/hydra/rest/securitydata). Query CSAF advisories, CVEs, and OVAL stream data through natural language.
## What It Does
This server exposes six tools that wrap the Red Hat Security Data API v1.0:
| Tool | Description |
| --- | --- |
| `search_csaf` | Search CSAF advisory documents by date, severity, CVE, package, or RHSA ID |
| `get_csaf_details` | Get the full CSAF document for a specific advisory |
| `search_cves` | Search CVEs by date, severity, CVSS score, CWE, package, or product |
| `get_cve_details` | Get full CVE details including affected releases and mitigations |
| `list_oval_streams` | List available OVAL v2 stream files |
| `get_oval_stream` | Get OVAL stream data for a specific product (e.g. RHEL9) |
## Quick Start
```bash
npm install
npm run build
npm start
```
The server runs over stdio using the MCP protocol. See the docs below for connecting it to Claude Desktop or other MCP clients.
## Documentation
- [Building and Running](docs/building.md) -- Build from source, container (Podman), and environment variables
- [Claude Desktop / Claude Code Setup](docs/claude-desktop-setup.md) -- Configuration for MCP clients
- [Tools Reference](docs/tools.md) -- Parameters and descriptions for all six tools
## Project Structure
```
src/
index.ts MCP server entry point and tool registration
api-client.ts HTTP client for the Red Hat Security Data API
tools/
csaf.ts search_csaf, get_csaf_details
cve.ts search_cves, get_cve_details
oval.ts list_oval_streams, get_oval_stream
Containerfile Multi-stage production build
build.sh Container image build script (Podman)
podman-compose.yml Local testing configuration (podman compose)
```
## License
See [LICENSE](LICENSE).
TDQS
Scored across 6 tools
Each tool targets a distinct resource type and action: CSAF search/detail, CVE search/detail, and OVAL list/retrieve. The resource nouns are explicit, so there is no meaningful overlap between search_csaf and search_cves or between the detail retrieval tools.
All tool names follow a clear verb_noun pattern with search_, get_, and list_ prefixes. The naming is consistent and predictable: search_* for queries, get_*_details/get_*_stream for fetching individual items, and list_* for enumerating available streams.
Six tools is well-scoped for a security data lookup server. The set covers three data types with paired search/list and detail retrieval operations, and every tool maps to a meaningful API action without redundancy or bloat.
The server provides both discovery/search and full-detail access for CSAF advisories, CVEs, and OVAL streams. As a read-only security data API, no create/update/delete operations are expected, and the retrieval lifecycle is effectively complete.