Skip to main content
Glama
kasireddy-sec

Tenable Security MCP

get_exploit_intelligence

Search public GitHub metadata for exploit, PoC, scanner, and proof-of-concept references tied to a CVE, then use the results as threat intelligence evidence.

Instructions

Search public GitHub repository metadata for exploit, PoC, scanner and proof-of-concept references related to a CVE.

This is intelligence evidence, not proof that an exploit works against a specific target.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cve_idYes

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

B3.3/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the burden, and it does disclose one meaningful trait: the results are intelligence evidence, not proof of exploitability. However, it says nothing about auth requirements, rate limits, or result freshness, so behavioral context remains thin for a no-annotation tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two short sentences with the core purpose front-loaded and the caveat placed after; every phrase earns its place with no padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return values needn't be described, and the single-parameter surface is simple. Still, the definition leaves the agent without guidance on how this differs from the other CVE/intel siblings, which is the main gap for correct selection.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must compensate, and it only implies the parameter is a CVE identifier ("related to a CVE"). The name cve_id is largely self-documenting, but no format, expected pattern, or accepted identifier style is given.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ("Search") and resource ("public GitHub repository metadata for exploit, PoC, scanner and proof-of-concept references") tied to a CVE. The GitHub-source framing distinguishes it from a generic intel search, but it never names or differentiates itself from siblings like get_cve_intelligence, get_complete_cve_intelligence, or search_security_intelligence.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description offers a caveat about what the data means but gives no when-to-use condition, no when-not-to-use, and no routing to the alternative intel tools in the sibling list. An agent still has to guess whether to call this or get_cve_intelligence first.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.