Advanced CVE Intelligence MCP Server providing comprehensive CVE vulnerability intelligence with advanced search, analysis, and tracking capabilities
CVE-MCP provides three tools with reasonable descriptions and partial schema definitions. All tools follow a read-only pattern (appropriate for CVE intelligence). However, there are significant gaps: parameter descriptions lack constraints and format guidance, output schemas are not explicitly documented, and error handling lacks recovery guidance. The server is functional but would benefit from LLM-optimized descriptions and complete schema documentation.
Analyze trends in CVE data including severity distribution, yearly distribution, and total count
Get detailed information about a specific CVE including descriptions, metrics, weaknesses, configurations, and references
Search CVEs using NVD API with various filters including keyword, vendor, product, severity, and date range
Output schemas are not documented. LLMs cannot predict the structure, field names, or types of responses. For search_cves, the pagination format is invisible. For get_cve_details, the nested 'metrics' and 'references' structure is a black box. For analyze_cve_trends, the format of 'severity_distribution' is unknown.
Parameter constraints and enums are missing. 'severity' parameter accepts free-form strings ('LOW, MEDIUM, HIGH, CRITICAL' listed as examples, not enums), inviting hallucinated values like 'SEVERE' or 'LOW_RISK'. 'page_size' lacks min/max bounds. 'last_days' lacks numeric range documentation.
Descriptions lack actionable format and constraint information. The 'cve_id' parameter description is just 'The CVE identifier (e.g., CVE-2024-1234)', no mention that it must match the regex CVE-YYYY-#### or whether lowercase is acceptable. 'limit' says 'default: 100' but NVD API caps results at 2000; LLMs may pass 5000 expecting all results.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 22 | - | v1 |
Error handling provides no recovery guidance. If search_cves returns a 429 (rate limit) or 400 (invalid CVE ID), the server likely returns a raw HTTP error. No guidance for LLMs: 'Retry in 60 seconds' or 'Use cve_id matching CVE-YYYY-#### format' or 'Call list_available_vendors first to validate vendor name'.
Tool composition could be improved. Users often want to search CVEs, then analyze trends, but analyze_cve_trends requires an array of CVE objects as input, LLMs must manually construct this array from search_cves results. A batch variant like 'analyze_cves_from_search(search_filters...)' would reduce round-trips and token usage.
Response filtering is incomplete. The code strips some fields (e.g., audit metadata) but returns verbose CVSS structures and full description text. For CVE search with 100+ results, token overhead is significant. Consider returning summaries in search_cves and full details only in get_cve_details.