Skip to main content
Glama
roadwy

cve-search_mcp

by roadwy

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
vul_vendorsC

To get a JSON with all the vendors

vul_vendor_productsC

To get a JSON with all the products associated to a vendor

vul_vendor_product_cveC

To get a JSON with all the vulnerabilities per vendor and a specific product

vul_cve_searchC

To get a JSON of a specific CVE ID

vul_last_cvesC
To get a JSON of the last <number> (5 by default) CVEs including CAPEC, CWE and CPE expansions
vul_db_update_statusC

To get more information about the current databases in use and when it was updated

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 6 tools

Disambiguation5/5

Each tool has a clearly distinct purpose targeting specific CVE-related queries: searching by ID, checking database status, retrieving recent CVEs, finding vulnerabilities by vendor/product, listing products per vendor, and listing all vendors. There is no overlap in functionality, making tool selection unambiguous.

Naming Consistency5/5

All tools follow a consistent 'vul_' prefix and snake_case naming pattern (e.g., vul_cve_search, vul_vendor_products), with clear and descriptive names that indicate the resource and action. This uniformity enhances readability and predictability.

Tool Count5/5

With 6 tools, the server is well-scoped for CVE search and vulnerability management, covering key operations like lookup, updates, recent entries, and vendor/product queries. Each tool serves a specific, non-redundant purpose, making the count appropriate for the domain.

Completeness4/5

The tool set provides comprehensive coverage for querying CVE data, including searches by ID, vendor, product, and recent entries, plus database status. A minor gap is the lack of tools for filtering or sorting beyond basic queries, but core workflows are fully supported without dead ends.

Maintenance

ActivityInactive
ResponsivenessNo issues