Skip to main content
Glama
kasireddy-sec

Tenable Security MCP

list_nessus_vulnerabilities

Retrieve vulnerabilities from a Nessus scan by scan ID, filtering by severity, CVE, or host to prioritize remediation.

Instructions

List vulnerabilities discovered in a Nessus scan.

Optional filters:

  • severity: info, low, medium, high, critical

  • cve: CVE identifier

  • host: hostname/IP fragment

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cveNo
hostNo
scan_idYes
severityNo

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. 'List' strongly implies a non-destructive read, and the filter list hints at scoping behavior, but the description says nothing about result volume, pagination, or any auth/permission requirements. Adequate but thin for a tool with zero annotation coverage.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

One identifying sentence followed by a compact bulleted filter list. Front-loaded, zero filler, and the enumerated severity values are immediately scannable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be described. Still, for a 4-param tool with 0% schema coverage the description leaves the required scan_id unexplained and gives no routing versus the sibling vulnerability-detail tools, so it is merely adequate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate, and it does document three of four parameters including the enumerated severity values (info/low/medium/high/critical) and the fragment-matching nature of 'host'. It notably omits scan_id, the single required parameter, whose meaning is only obliquely implied by 'in a Nessus scan'.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource: listing vulnerabilities discovered in a Nessus scan, which clearly distinguishes it from mutation tools like launch_nessus_scan. However, it does not differentiate itself from the similarly-named sibling get_nessus_vulnerability_details or list_tenable_cloud_vulnerabilities, leaving the agent to infer the boundary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Implies usage by presenting optional filters and their values, so a caller knows it is a filtered enumeration over a single scan. But there is no explicit when-to-use guidance and no exclusion pointing to get_nessus_vulnerability_details for single-vulnerability lookups or to the cloud equivalents.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.