cybersecurity-vuln-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| NVD_API_KEY | No | Optional NVD API key for higher rate limits |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| vuln_lookup_cveA | Look up a CVE by ID and get enriched intelligence: NVD details (CVSS score, description, references), CISA KEV active exploitation status, EPSS exploitation probability score, and MITRE ATT&CK techniques. |
| vuln_searchB | Search the NIST NVD for CVEs by keyword, severity, and date range. |
| vuln_kev_latestB | Get recently added CISA KEV entries (actively exploited vulnerabilities). |
| vuln_kev_due_soonB | Get CISA KEV vulnerabilities with upcoming remediation deadlines. |
| vuln_epss_topC | Get CVEs with highest EPSS exploitation probability scores. |
| vuln_trendingC | Get recently published critical/high severity CVEs from the NVD. |
| vuln_by_vendorB | Search CVEs for a specific vendor/product, cross-referenced with CISA KEV. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
Tools are mostly distinct, with slight overlap between vuln_kev_due_soon and vuln_kev_latest (both KEV-focused but different filters) and between vuln_trending and vuln_epss_top (different criteria for prioritizing CVEs). Descriptions clarify differences.
All tool names follow the pattern vuln_<descriptive_name>, using underscores and consistent noun/verb structure. No mixing of conventions.
7 tools cover the core vulnerability intelligence domain without being excessive. Each tool serves a clear purpose, and the count is well-scoped.
The surface covers search, lookup, trending, exploitation probability, and KEV monitoring comprehensively. Minor gaps exist, such as no tool for patch or fix version information, but overall the set is complete for its informational purpose.