An MCP server that provides tools to search GitHub repositories, query NIST NVD for CVE information, and access CISA's Known Exploited Vulnerabilities catalog.
Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
The server defines 3 tools with reasonable naming conventions starting with action verbs (search_, get_, check_). However, critical gaps exist in parameter descriptions, output schema documentation, and error handling guidance. Tool descriptions are adequate (70-90 chars), but parameter descriptions are inconsistent, some parameters lack clarity on constraints and format expectations. No output schemas are documented, forcing LLMs to infer result structure. Error handling exists but does not guide recovery actions. The code shows good input validation logic but does not surface validation rules clearly in descriptions.
Tools (3)
check_cisa_kevread only50/100
Check if a CVE is in CISA's Known Exploited Vulnerabilities catalog.
Output schemas are not documented. Tool descriptions state returns are 'JSON string' but do not specify field names, types, or structure. LLMs must infer result shape, risking misuse and token waste.
Parameter descriptions lack format and constraint details. 'sort' parameter states 'Sort results by...' but does not document which values are actually allowed ('best-match' behavior differs from others). 'per_page' description omits that GitHub API caps at 100. Agents cannot validate inputs without trial.
CVE parameter format is ambiguous. Both tools accept CVE IDs as 'CVE-2023-1234' or '2023-1234', but description does not clarify which format is preferred or if both are truly equivalent. LLMs may pass invalid formats on first attempt.
get_cve_from_nistcheck_cisa_kev
Recommendations
Add explicit output schema documentation to all three tools. Example for search_github_repositories: 'Returns JSON object with fields: search_query (string), total_count (integer), incomplete_results (boolean), repositories (array of objects with: name, full_name, html_url, owner.login, language, stars (integer), forks (integer), created_at (ISO 8601), updated_at (ISO 8601)).'
Clarify sort/order parameter constraints: 'sort: one of best-match (default, relevance-ranked) | stars | forks | help-wanted-issues | updated. Note: best-match ignores order parameter.'
Add format constraint to CVE parameters: 'CVE identifier in format CVE-YYYY-NNNN (e.g., CVE-2023-1234). Both CVE-2023-1234 and 2023-1234 formats accepted; prefer CVE- prefix for consistency.'
Document error scenarios and recovery paths in tool descriptions. Example: 'Errors: If GitHub API returns 403, rate limit is exceeded, provide GITHUB_TOKEN env var for higher limits. If returns 422, search query is invalid, check syntax and try again. If returns 503, service is down, wait a few minutes and retry.'
Document pagination explicitly: 'Results are paginated. Use per_page (1-100, default 5) and page (1+, default 1) to navigate. Returns total_count (total matching repos) and incomplete_results (boolean, true if GitHub halted search due to complexity). Incomplete results occur on broad queries; add qualifiers to narrow scope.'
Add environment variable documentation: 'Optional: Set GITHUB_TOKEN environment variable to a GitHub personal access token. With token, rate limit is 30 requests/minute per user; without token, 10 requests/minute per IP. NIST and CISA endpoints have no rate limit but may be slow. No credentials needed for public GitHub/NIST/CISA endpoints.'
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
Error messages exist in code but do not guide recovery. ValueError and RuntimeError messages are present (e.g., 'GitHub API service unavailable', 'NIST API rate limit exceeded') but tool descriptions do not document what errors are possible or what the LLM should do if they occur (retry later? call a different tool? ask user?).
No documentation of pagination behavior or result limits. search_github_repositories defaults to 5 results per page; no mention of what happens if total_count exceeds 1000. No guidance on when to paginate or how to retrieve all results. For NIST and CISA tools, no mention of whether they return single results or lists.
Dependencies and prerequisites not documented. search_github_repositories optionally uses GITHUB_TOKEN from environment; no description notes this or explains that rate limits are higher with a token. NIST tool mentions 'Consider using an API key' in error message but not in tool description. CISA tool downloads global catalog on init, no mention in description of this one-time cost.
Secrets in code but not as parameters (good). However, API keys (GITHUB_TOKEN, NIST API key) are referenced but not documented in tool descriptions. If a user wants to provide credentials, there is no clear guidance on how to configure them.
search_github_repositoriesget_cve_from_nist
Split check_cisa_kev into two tools if needed: check_cisa_kev (checks a single CVE) + list_cisa_kev (returns all exploited vulnerabilities with pagination). Currently, if a user asks 'show me all actively exploited vulnerabilities', the tool cannot do it, all vulnerabilities are cached but only one CVE can be checked at a time.
Add validation constraints to tool parameters: document that per_page must be 1-100, page must be >= 1, sort and order must be valid enums. Make these constraints machine-readable in the schema if not already present.
Document what CVE not found looks like. For get_cve_from_nist: 'If CVE not found, returns None. If found, returns JSON object with vulnerabilities array (may contain multiple records for same CVE across database versions). If NIST API returns 403, rate limit is exceeded, wait before retrying.'
For check_cisa_kev: document cache behavior. 'On server startup, downloads CISA Known Exploited Vulnerabilities catalog (JSON feed, ~300-500 entries). Checks if supplied CVE is in that list. Catalog is cached in memory; does not refresh during runtime. For most recent exploited vulnerabilities, use NIST or CISA website directly.'