Multi-source CVE intelligence for AI-powered security operations. Combines 3 FREE data sources (NVD, CISA KEV, EPSS) to provide comprehensive vulnerability intelligence with CVSS scores, exploit probability, and active exploitation status.
The CVE Intelligence MCP server demonstrates good definition quality with well-structured tool designs aligned to a single security domain. All 4 tools have clear, descriptive docstrings explaining WHAT they do and WHEN to use them. Parameter schemas are present with types and descriptions. However, output schemas are not formally documented, tool responses are returned as JSON strings without explicit schema declarations. Tool names follow the verb_noun pattern (cve_lookup, cve_search, cve_recent_kev, cve_epss_score) and are action-oriented. Error handling is minimal, no recovery guidance or error classification is visible. Security and composition are appropriate for read-only domain tools.
Get the EPSS (Exploit Prediction Scoring System) score for a CVE. EPSS provides a probability (0-100%) that a CVE will be exploited in the wild within the next 30 days. This is different from CVSS which measures severity — EPSS measures likelihood of exploitation. Use this tool when: - User wants to know HOW LIKELY a CVE will be exploited (not just how severe) - User asks "should I prioritize this CVE?" - User is comparing which CVEs to patch first - User asks about exploit probability or prediction
Get comprehensive intelligence for a specific CVE from multiple sources. Combines data from NVD (CVSS score, description), CISA KEV (active exploitation status), and EPSS (exploit probability in next 30 days) into a single actionable report with a risk verdict. Use this tool when: - User asks about a specific CVE (e.g., "Tell me about CVE-2024-3094") - User wants to know if a vulnerability is critical or actively exploited - User needs a risk assessment for a specific vulnerability - Incident response / triage requires quick CVE context
Get the most recently added Known Exploited Vulnerabilities from CISA. These are CVEs that are CONFIRMED to be actively exploited in the wild. Organizations should prioritize patching these immediately. Use this tool when: - User asks "what's being actively exploited right now?" - User wants to know the latest critical threats - User needs to prioritize patching based on active exploitation - SOC analyst needs current threat awareness
Search for CVEs by keyword in the National Vulnerability Database. Use this tool when: - User asks about vulnerabilities in a specific product (e.g., "Apache Log4j vulnerabilities") - User wants to find CVEs related to a technology or vendor - User asks "what vulnerabilities exist for [product]?"
Output schemas not formally documented. Tools return JSON strings but no explicit schema or field definitions are provided to guide LLM extraction and downstream tool chaining.
Error handling lacks recovery guidance. Tool docstrings do not document failure modes (e.g., CVE not found, API rate limit, malformed CVE ID) or what the LLM should do next.
cve_search and cve_recent_kev have limit parameters but lack explicit range constraints in descriptions. The code enforces min(limit, 20), but LLMs are not told why passing 100+ is unsafe.
Parameter descriptions include example values (e.g., 'CVE-2024-3094', 'CVE-2021-44228') which LLMs may reuse literally in real calls. Prefer format/pattern constraints in schema instead.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 76 | <=2025-11-25 | v2 |