A Model Context Protocol server providing tools for CVE vulnerability information queries
The CVE MCP server has a single tool with critical definition quality gaps. The tool `query_cve` lacks a meaningful description (null in schema), parameter descriptions are missing entirely, and the output schema is undocumented. While the tool name is reasonably clear (starts with verb 'query'), the implementation exposes fundamental issues: the parameter has no description, error handling is minimal, and there is no documentation of what the JSON response contains. The server uses FastMCP which should support proper schema registration, but the definitions are incomplete.
Tool description is null/missing. FastMCP decorator has no docstring or description passed to @mcp.tool().
Parameter 'cve_id' lacks a description. The schema shows {"type":"string","description":null}, violating the requirement that every parameter must have a non-empty description so LLMs understand what to pass.
Output schema is undocumented. The tool returns json.dumps(cve.get_cve()), which could be None or a dict with unknown fields (e.g., 'nuclei_poc' is added dynamically). LLMs cannot plan downstream actions without knowing the response structure.
No error handling guidance. If cve.get_cve() returns None (CVE not found or error), the tool serializes null to JSON string 'null'. LLMs receive no actionable error message indicating whether to retry, check the CVE ID, or try a different approach.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 30 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 44 | - | v1 |
No input validation or format specification. The 'cve_id' parameter accepts any string. Should specify format (e.g., 'CVE-YYYY-NNNNN') and validate before calling external API.
Response may include irrelevant metadata. The MITRE CVE API returns verbose data (references, metrics, configurations). No filtering or result limiting is applied, potentially bloating context window.
HTTP timeouts not configured. Requests to external APIs (MITRE CVE, nuclei POC GitHub) lack explicit timeout parameters, risking hung tool calls that block the agent.
Tool name 'query_cve' is slightly ambiguous. Better alternatives: 'get_cve_details' or 'search_cve_info' to match production baselines where 'get' and 'search' are most common first words.