Tenable Security MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| NESSUS_URL | Yes | The URL of the Nessus server (e.g., https://localhost:8834) | |
| NESSUS_ACCESS_KEY | Yes | Nessus API access key | |
| NESSUS_SECRET_KEY | Yes | Nessus API secret key |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| get_nessus_server_infoB | Get basic information about the Nessus server. |
| list_nessus_scansB | List all scans configured in Nessus. |
| get_nessus_scan_detailsC | Get details and latest results for a Nessus scan. |
| get_nessus_scan_statusC | Get the current status of a Nessus scan. |
| get_nessus_host_detailsC | Get vulnerability information for a host in a scan. |
| get_nessus_vulnerability_detailsC | Get detailed information and plugin output for a vulnerability. |
| list_nessus_policiesB | List available Nessus scan policies. |
| list_nessus_foldersB | List Nessus scan folders. |
| list_nessus_agentsC | List Nessus agents. |
| get_nessus_scan_historyC | Get historical runs of a Nessus scan. |
| get_nessus_scan_history_detailsC | Get details for a specific historical scan result. |
| launch_nessus_scanC | Launch a Nessus scan using its configured targets. |
| stop_nessus_scanC | Stop a running Nessus scan. |
| get_nessus_pluginC | Get information about a Nessus plugin. |
| list_nessus_usersB | List users configured in Nessus. |
| find_assets_not_scanned_sinceA | Find Nessus hosts whose latest known scan result is older than the specified number of days. Example: find_assets_not_scanned_since(7) |
| list_nessus_vulnerabilitiesA | List vulnerabilities discovered in a Nessus scan. Optional filters:
|
| get_cve_intelligenceC | Retrieve detailed vulnerability intelligence from NVD. Includes:
|
| get_cisa_kev_statusA | Check whether a CVE is listed in the CISA Known Exploited Vulnerabilities catalog. |
| get_epss_scoreC | Get the current FIRST EPSS score and percentile for a CVE. |
| get_exploit_intelligenceB | Search public GitHub repository metadata for exploit, PoC, scanner and proof-of-concept references related to a CVE. This is intelligence evidence, not proof that an exploit works against a specific target. |
| get_complete_cve_intelligenceB | Combine NVD, CISA KEV, EPSS and public exploit intelligence for one CVE. |
| prioritize_vulnerabilitiesB | Prioritize vulnerabilities from a Nessus scan using:
The score is a deterministic prioritization score and should not be interpreted as an official vendor score. |
| analyze_emerging_threatsB | Identify high-priority emerging vulnerability signals in a Nessus scan. Signals include:
This does NOT claim that an unknown zero-day has been discovered. It identifies vulnerabilities requiring urgent investigation. |
| build_security_contextC | Build a normalized security-intelligence record suitable for downstream RAG or LLM reasoning. |
| get_tenable_cloud_server_infoC | Get information from the configured Tenable cloud environment. Requires TENABLE_CLOUD_ACCESS_KEY and TENABLE_CLOUD_SECRET_KEY. |
| list_tenable_cloud_assetsC | List assets from Tenable Vulnerability Management. |
| list_tenable_cloud_vulnerabilitiesC | List vulnerabilities from Tenable Vulnerability Management. |
| get_tenable_cloud_vulnerabilityC | Get vulnerability information from Tenable Vulnerability Management. |
| get_tenable_cloud_assetC | Get details for a Tenable Vulnerability Management asset. |
| search_security_intelligenceC | Unified security intelligence lookup. Searches:
|
| get_mcp_capabilitiesB | Show the capabilities available through the Tenable Security MCP server. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 32 tools
Most tools target distinct resources or actions, but CVE-intelligence tools overlap heavily: search_security_intelligence, get_complete_cve_intelligence, and the component tools (get_cve_intelligence, get_cisa_kev_status, get_epss_score, get_exploit_intelligence) can be confused. prioritize_vulnerabilities and analyze_emerging_threats also use similar signals for related outputs, though descriptions help separate them.
Tool names consistently use snake_case with predictable verb_noun or verb_resource patterns. Prefixes such as list_, get_, launch_, stop_, and search_ are used throughout, with no mixed camelCase or chaotic naming.
The server exposes 32 tools, which is above the 25+ threshold for being too many and includes several overlapping intelligence and scan-detail operations that could be consolidated. While the domain is broad, the tool count feels excessive rather than tightly scoped.
The surface covers Nessus scan listing, launching, stopping, history, host/vulnerability details, Tenable cloud assets and vulnerabilities, and major CVE intelligence sources. Gaps exist for creating, updating, or deleting scans, policies, users, and reports, but core analysis and scan-control workflows are present.