Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,524Letters: 13Defects: 1,322counted just now
teppi

Server definition

Hash
sha256:503bfdc4e418d0a9f2d14100cbe16093f33ca02a5c01aa7112df8a22168398ac
What it is
What a remote MCP server returned when asked what it offers: 5 tools

The blob, as servednamed by its sha256

{ "instructions": "This server provides read-only access to the NIST National Vulnerability Database (NVD).\n- Use nvd_search_cves to discover CVEs by keyword, severity, CWE, date range, or CISA KEV status.\n- Use nvd_get_cve for full CVSS details on specific CVE IDs (up to 100 per call).\n- Use nvd_search_cpes to find the correct CPE name for a product before auditing.\n- Use nvd_audit_cpe to find all CVEs affecting a specific product version.\n- Use nvd_get_cve_history to track when a CVE was re-scored or escalated.\n- Rate limit: 5 req/30s without API key, 50 req/30s with NVD_API_KEY.", "tools": [ { "description": "Find all CVEs affecting a specific product and version using CPE (Common Platform Enumeration). Requires either an exact CPE name (cpeName) or a partial match string (virtualMatchString) with optional version range bounds. With cpeName, NVD scopes results to configurations where the product is directly vulnerable, not merely referenced as a dependency. Use nvd_search_cpes first to resolve the correct CPE string for a product. Returns full CVE records.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "allLanguages": { "default": false, "description": "When true, keeps every localized description NVD supplies on each record. Default keeps English only.", "type": "boolean" }, "cpeName": { "description": "Full CPEv2.3 name (e.g., \"cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*\"). NVD adds isVulnerable automatically. Mutually exclusive with virtualMatchString.", "type": "string" }, "limit": { "default": 20, "description": "Maximum number of CVEs to return (default 20, max 2000).", "maximum": 2000, "minimum": 1, "type": "integer" }, "offset": { "default": 0, "description": "Zero-based page offset for pagination. Page through totalCount with a modest limit rather than raising limit — this tool returns full CVE records, so a large limit is a large response.", "maximum": 9007199254740991, "minimum": 0, "type": "integer" }, "severityMin": { "description": "Filter out CVEs below this severity level. Applied after NVD returns the page, so it can only drop CVEs within limit — raise limit to widen what it sees.", "enum": [ "LOW", "MEDIUM", "HIGH", "CRITICAL" ], "type": "string" }, "versionEnd": { "description": "Upper version bound. Requires virtualMatchString.", "type": "string" }, "versionEndType": { "default": "including", "description": "Whether the upper version bound is inclusive or exclusive.", "enum": [ "including", "excluding" ], "type": "string" }, "versionStart": { "description": "Lower version bound. Requires virtualMatchString.", "type": "string" }, "versionStartType": { "default": "including", "description": "Whether the lower version bound is inclusive or exclusive.", "enum": [ "including", "excluding" ], "type": "string" }, "virtualMatchString": { "description": "Partial CPE match pattern (e.g., \"cpe:2.3:a:apache:http_server:*\"). Use with versionStart/versionEnd for version range audits. Mutually exclusive with cpeName.", "type": "string" } }, "type": "object" }, "name": "nvd_audit_cpe", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "cves", "totalCount", "returned", "offset", "auditTarget" ] }, { "required": [ "error" ] } ], "properties": { "auditTarget": { "description": "The CPE name or virtual match string used for this audit.", "type": "string" }, "cves": { "description": "Full CVE records for CVEs affecting the specified product.", "items": { "additionalProperties": false, "description": "Full CVE record for one vulnerability affecting the product.", "properties": { "cisaKev": { "additionalProperties": false, "description": "CISA KEV fields. Present only when CVE is in the KEV catalog.", "properties": { "actionDueDate": { "description": "Federal agency remediation deadline.", "type": "string" }, "exploitAddDate": { "description": "Date added to CISA KEV catalog.", "type": "string" }, "requiredAction": { "description": "Required remediation steps.", "type": "string" }, "vulnerabilityName": { "description": "CISA's vulnerability name.", "type": "string" } }, "required": [ "exploitAddDate", "actionDueDate", "requiredAction", "vulnerabilityName" ], "type": "object" }, "configurationNodes": { "description": "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together.", "items": { "additionalProperties": false, "description": "One affected product configuration node, tagged with the group it came from.", "properties": { "cpeMatch": { "description": "This node's CPE match criteria, in the order NVD lists them.", "items": { "additionalProperties": false, "description": "One CPE match criterion.", "properties": { "criteria": { "description": "CPEv2.3 match criteria string.", "type": "string" }, "versionEndExcluding": { "description": "Exclusive upper version bound.", "type": "string" }, "versionEndIncluding": { "description": "Inclusive upper version bound.", "type": "string" }, "versionStartExcluding": { "description": "Exclusive lower version bound.", "type": "string" }, "versionStartIncluding": { "description": "Inclusive lower version bound.", "type": "string" }, "vulnerable": { "description": "Whether this CPE is the vulnerable component or only the context it runs in.", "type": "boolean" } }, "required": [ "vulnerable", "criteria" ], "type": "object" }, "type": "array" }, "groupIndex": { "description": "Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator.", "type": "number" }, "groupOperator": { "description": "Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An \"AND\" means every node in the group must match for the CVE to apply — e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.", "type": "string" }, "nodeOperator": { "description": "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine.", "type": "string" } }, "required": [ "groupIndex", "cpeMatch" ], "type": "object" }, "type": "array" }, "cveId": { "description": "CVE identifier (e.g., \"CVE-2021-44228\").", "type": "string" }, "cvssScores": { "description": "All available CVSS scores across versions.", "items": { "additionalProperties": false, "description": "One CVSS score entry.", "properties": { "baseScore": { "description": "Base score (0.0–10.0).", "type": "number" }, "severity": { "description": "Severity label: CRITICAL, HIGH, MEDIUM, or LOW.", "type": "string" }, "sourceType": { "description": "Score source: \"Primary\" = NVD, \"Secondary\" = CNA.", "type": "string" }, "vectorString": { "description": "CVSS vector string.", "type": "string" }, "version": { "description": "CVSS version (e.g., \"2.0\", \"3.1\", \"4.0\").", "type": "string" } }, "required": [ "version", "sourceType", "baseScore", "severity" ], "type": "object" }, "type": "array" }, "descriptions": { "description": "CVE descriptions by language.", "items": { "additionalProperties": false, "description": "One localized CVE description.", "properties": { "lang": { "description": "Language code.", "type": "string" }, "value": { "description": "CVE description.", "type": "string" } }, "required": [ "lang", "value" ], "type": "object" }, "type": "array" }, "lastModified": { "description": "ISO 8601 last-modified datetime.", "type": "string" }, "published": { "description": "ISO 8601 publication datetime.", "type": "string" }, "references": { "description": "External references.", "items": { "additionalProperties": false, "description": "One external reference.", "properties": { "source": { "description": "Who contributed the reference, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.", "type": "string" }, "tags": { "description": "Classification tags.", "items": { "description": "One classification tag.", "type": "string" }, "type": "array" }, "url": { "description": "Reference URL.", "type": "string" } }, "required": [ "url" ], "type": "object" }, "type": "array" }, "severity": { "additionalProperties": false, "description": "Top severity. Absent if no CVSS scores present.", "properties": { "fromVersion": { "description": "Which CVSS version this top score came from.", "type": "string" }, "label": { "description": "Highest severity label across all CVSS versions.", "type": "string" }, "score": { "description": "Highest base score (0.0–10.0).", "type": "number" } }, "required": [ "label", "score", "fromVersion" ], "type": "object" }, "vulnStatus": { "description": "NVD analysis status.", "type": "string" }, "weaknesses": { "description": "CWE weakness classifications.", "items": { "additionalProperties": false, "description": "One weakness classification entry.", "properties": { "cweIds": { "description": "CWE identifiers for this source.", "items": { "description": "One CWE identifier.", "type": "string" }, "type": "array" }, "source": { "description": "Who classified the weakness, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.", "type": "string" } }, "required": [ "source", "cweIds" ], "type": "object" }, "type": "array" } }, "required": [ "cveId", "vulnStatus", "published", "lastModified", "descriptions", "cvssScores", "weaknesses", "configurationNodes" ], "type": "object" }, "type": "array" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `missing_cpe_input`: Neither cpeName nor virtualMatchString was provided. `conflicting_cpe_inputs`: Both cpeName and virtualMatchString were provided simultaneously. `version_range_without_match_string`: versionStart or versionEnd was provided without virtualMatchString. `invalid_cpe_format`: cpeName or virtualMatchString does not start with \"cpe:2.3:\", or NVD rejected it as a malformed CPE parameter — cpeName rejects anything short of a complete CPEv2.3 name, virtualMatchString only genuinely malformed characters. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.", "examples": [ "missing_cpe_input", "conflicting_cpe_inputs", "version_range_without_match_string", "invalid_cpe_format", "rate_limited" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "filteredCount": { "description": "CVEs dropped by the severityMin filter from the page NVD returned. Present whenever severityMin is set; 0 means the filter dropped nothing, so a narrow result reflects totalCount and limit instead. This is not totalCount minus returned — CVEs beyond limit were never fetched and so were never evaluated against the filter.", "type": "number" }, "notice": { "description": "Guidance on the shape of this page. When no CVEs came back it distinguishes a target NVD holds no CVEs for from a severityMin filter that dropped everything on the page, from an offset past the result set, from an empty page NVD returned inside a range it says has matches. On a partial page it names the offset that reaches the next one.", "type": "string" }, "offset": { "description": "Page offset used in this query.", "type": "number" }, "returned": { "description": "Number of CVE records returned.", "type": "number" }, "severityMin": { "description": "The client-side minimum severity filter applied. Absent when none was set.", "type": "string" }, "totalCount": { "description": "Total CVEs matched before pagination.", "type": "number" } }, "type": "object" } }, { "description": "Fetch one or more CVEs by ID from the NIST National Vulnerability Database. Returns CVSS scores across all available versions (v2.0, v3.0, v3.1, v4.0), CWE weakness classifications, affected CPE configurations, CISA KEV fields, and references. Up to 100 CVE IDs per call. For bulk lookups of more than 10 IDs, use brief: true — full records for 100 CVEs can exceed 1MB and exhaust context budgets.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "allLanguages": { "default": false, "description": "When true, keeps every localized description NVD supplies on each record, and full records render all of them. Default keeps English only, falling back to whatever exists if a record has no English entry. Brief records always carry a single truncated description.", "type": "boolean" }, "brief": { "default": false, "description": "When true, returns trimmed records (ID, status, top CVSS score, KEV name, published date, and a truncated description) instead of full detail. Recommended for batches of more than 10 IDs.", "type": "boolean" }, "cveIds": { "anyOf": [ { "description": "A single CVE ID (e.g., \"CVE-2021-44228\").", "type": "string" }, { "description": "An array of CVE IDs — at least 1, up to 100 per call.", "items": { "type": "string" }, "maxItems": 100, "minItems": 1, "type": "array" } ], "description": "One CVE ID or an array of up to 100 CVE IDs to fetch." }, "includeReferences": { "default": true, "description": "When false, omits the references array to reduce response size.", "type": "boolean" } }, "required": [ "cveIds" ], "type": "object" }, "name": "nvd_get_cve", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "brief", "cves", "requested", "returned" ] }, { "required": [ "error" ] } ], "properties": { "brief": { "description": "Whether brief or full records were returned.", "type": "boolean" }, "cves": { "description": "CVE records — full detail by default, trimmed rows when brief is true.", "items": { "additionalProperties": {}, "description": "One CVE record. Every field beyond cveId, vulnStatus, and published depends on the mode: full mode (the default) carries all of them except description and cisaVulnerabilityName, which are the brief-mode substitutes for descriptions and cisaKev.", "properties": { "cisaKev": { "additionalProperties": false, "description": "CISA KEV fields. Present only when CVE is in the KEV catalog.", "properties": { "actionDueDate": { "description": "Federal agency remediation deadline.", "type": "string" }, "exploitAddDate": { "description": "Date added to CISA KEV catalog.", "type": "string" }, "requiredAction": { "description": "Required remediation steps.", "type": "string" }, "vulnerabilityName": { "description": "CISA's vulnerability name.", "type": "string" } }, "required": [ "exploitAddDate", "actionDueDate", "requiredAction", "vulnerabilityName" ], "type": "object" }, "cisaVulnerabilityName": { "description": "CISA KEV vulnerability name. Present only when in the KEV catalog.", "type": "string" }, "configurationNodes": { "description": "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together.", "items": { "additionalProperties": false, "description": "One affected product configuration node, tagged with the group it came from.", "properties": { "cpeMatch": { "description": "This node's CPE match criteria, in the order NVD lists them.", "items": { "additionalProperties": false, "description": "One CPE match criterion.", "properties": { "criteria": { "description": "CPEv2.3 match criteria string.", "type": "string" }, "versionEndExcluding": { "description": "Exclusive upper version bound.", "type": "string" }, "versionEndIncluding": { "description": "Inclusive upper version bound.", "type": "string" }, "versionStartExcluding": { "description": "Exclusive lower version bound.", "type": "string" }, "versionStartIncluding": { "description": "Inclusive lower version bound.", "type": "string" }, "vulnerable": { "description": "Whether this CPE is the vulnerable component or only the context it runs in.", "type": "boolean" } }, "required": [ "vulnerable", "criteria" ], "type": "object" }, "type": "array" }, "groupIndex": { "description": "Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator.", "type": "number" }, "groupOperator": { "description": "Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An \"AND\" means every node in the group must match for the CVE to apply — e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.", "type": "string" }, "nodeOperator": { "description": "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine.", "type": "string" } }, "required": [ "groupIndex", "cpeMatch" ], "type": "object" }, "type": "array" }, "cveId": { "description": "CVE identifier (e.g., \"CVE-2021-44228\").", "type": "string" }, "cvssScores": { "description": "All available CVSS scores across versions.", "items": { "additionalProperties": false, "description": "One CVSS score entry.", "properties": { "baseScore": { "description": "Base score (0.0–10.0).", "type": "number" }, "severity": { "description": "Severity label: CRITICAL, HIGH, MEDIUM, or LOW.", "type": "string" }, "sourceType": { "description": "Score source: \"Primary\" = NVD, \"Secondary\" = CNA.", "type": "string" }, "vectorString": { "description": "CVSS vector string.", "type": "string" }, "version": { "description": "CVSS version (e.g., \"2.0\", \"3.1\", \"4.0\").", "type": "string" } }, "required": [ "version", "sourceType", "baseScore", "severity" ], "type": "object" }, "type": "array" }, "description": { "description": "Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.", "type": "string" }, "descriptions": { "description": "CVE descriptions by language.", "items": { "additionalProperties": false, "description": "One localized CVE description.", "properties": { "lang": { "description": "Language code.", "type": "string" }, "value": { "description": "CVE description.", "type": "string" } }, "required": [ "lang", "value" ], "type": "object" }, "type": "array" }, "lastModified": { "description": "ISO 8601 last-modified datetime.", "type": "string" }, "published": { "description": "ISO 8601 publication datetime.", "type": "string" }, "references": { "description": "External references.", "items": { "additionalProperties": false, "description": "One external reference.", "properties": { "source": { "description": "Who contributed the reference, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.", "type": "string" }, "tags": { "description": "Classification tags.", "items": { "description": "One classification tag.", "type": "string" }, "type": "array" }, "url": { "description": "Reference URL.", "type": "string" } }, "required": [ "url" ], "type": "object" }, "type": "array" }, "severity": { "additionalProperties": false, "description": "Top severity. Absent if no CVSS scores present.", "properties": { "fromVersion": { "description": "Which CVSS version this top score came from.", "type": "string" }, "label": { "description": "Highest severity label across all CVSS versions.", "type": "string" }, "score": { "description": "Highest base score (0.0–10.0).", "type": "number" } }, "required": [ "label", "score", "fromVersion" ], "type": "object" }, "vulnStatus": { "description": "NVD analysis status.", "type": "string" }, "weaknesses": { "description": "CWE weakness classifications.", "items": { "additionalProperties": false, "description": "One weakness classification entry.", "properties": { "cweIds": { "description": "CWE identifiers for this source.", "items": { "description": "One CWE identifier.", "type": "string" }, "type": "array" }, "source": { "description": "Who classified the weakness, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.", "type": "string" } }, "required": [ "source", "cweIds" ], "type": "object" }, "type": "array" } }, "required": [ "cveId", "vulnStatus", "published" ], "type": "object" }, "type": "array" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: One or more CVE IDs fail format validation (NVD returns HTTP 404 for malformed IDs). `cve_not_found`: A valid-format CVE ID returns no results — the ID is well-formed but does not exist in NVD. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.", "examples": [ "invalid_cve_id_format", "cve_not_found", "rate_limited" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "missingIds": { "description": "CVE IDs requested but not found in NVD. Absent when all IDs matched.", "items": { "description": "A CVE ID not found in NVD.", "type": "string" }, "type": "array" }, "requested": { "description": "Number of CVE IDs requested.", "type": "number" }, "returned": { "description": "Number of CVE records returned.", "type": "number" } }, "type": "object" } }, { "description": "Retrieve the change history for a single CVE — CVSS score revisions, reference additions, status transitions (e.g., \"Received\" → \"Analyzed\"), and CPE configuration updates. Use when tracking a CVE's escalation or investigating when a score changed. Events are returned newest-first by default; pass order=\"oldest\" for the CVE's earliest events. For the current record, call nvd_get_cve instead. The NVD history endpoint is significantly slower than other NVD endpoints, especially without an API key — set NVD_API_KEY for reliable operation.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "cveId": { "description": "CVE identifier to retrieve history for (e.g., \"CVE-2021-44228\").", "type": "string" }, "limit": { "default": 20, "description": "Maximum number of change events to return (default 20, max 2000).", "maximum": 2000, "minimum": 1, "type": "integer" }, "offset": { "default": 0, "description": "Zero-based offset for paginating through change events, counted from whichever end order anchors to: offset 0 is the newest event under the default order=\"newest\", and the oldest event under order=\"oldest\".", "maximum": 9007199254740991, "minimum": 0, "type": "integer" }, "order": { "default": "newest", "description": "Which end of the history to page from. Default \"newest\" returns the most recent events first, which is what escalation and re-score questions need. \"oldest\" returns NVD's native order (the CVE's first events first) and costs one upstream request, or two when the offset overruns the history; \"newest\" costs up to two on any history longer than limit.", "enum": [ "oldest", "newest" ], "type": "string" } }, "required": [ "cveId" ], "type": "object" }, "name": "nvd_get_cve_history", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "cveId", "changes", "totalCount", "returned", "offset", "order" ] }, { "required": [ "error" ] } ], "properties": { "changes": { "description": "CVE change events ordered to match the requested order — newest first by default, oldest first when order=\"oldest\".", "items": { "additionalProperties": false, "description": "One CVE change event with its field-level details.", "properties": { "changeDate": { "description": "ISO 8601 datetime when this change occurred.", "type": "string" }, "details": { "description": "Individual change detail entries within this event.", "items": { "additionalProperties": false, "description": "One field-level change within this event.", "properties": { "action": { "description": "The action taken (e.g., \"Added\", \"Changed\", \"Removed\").", "type": "string" }, "newValue": { "description": "The value after the change. Structured upstream values (e.g. \"Affected\", \"SSVC\" details) arrive as a JSON string — parse it to read the fields.", "type": "string" }, "oldValue": { "description": "The value before the change. Structured upstream values (e.g. \"Affected\", \"SSVC\" details) arrive as a JSON string — parse it to read the fields.", "type": "string" }, "type": { "description": "The type of data changed (e.g., \"CVSS V3.1\", \"CWE\", \"Reference\").", "type": "string" } }, "type": "object" }, "type": "array" }, "eventName": { "description": "Name of the change event (e.g., \"CVE Modified\", \"Initial Analysis\").", "type": "string" } }, "required": [ "changeDate", "details" ], "type": "object" }, "type": "array" }, "cveId": { "description": "The CVE ID for which history was retrieved.", "type": "string" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: The CVE ID fails format validation (NVD returns HTTP 404 for malformed IDs). `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.", "examples": [ "invalid_cve_id_format", "rate_limited" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "notice": { "description": "Guidance on the shape of this page. When no events came back it distinguishes an offset past the end of the history, from an empty page NVD returned inside a range it says has events, from a CVE NVD holds no history for — the last of which covers both a record it has never revised and a CVE ID it does not hold. On a partial page it names the offset that reaches the next one, counted from the same end order anchors to.", "type": "string" }, "offset": { "description": "Page offset used in this query.", "type": "number" }, "order": { "description": "Which end of the history this page was anchored to.", "enum": [ "oldest", "newest" ], "type": "string" }, "returned": { "description": "Number of change events returned in this response.", "type": "number" }, "totalCount": { "description": "Total change events on record for this CVE.", "type": "number" } }, "type": "object" } }, { "description": "Search the NVD CPE (Common Platform Enumeration) dictionary by product keyword or partial match string. Returns CPE names, human-readable titles, and deprecation status. Use before nvd_audit_cpe to resolve the correct CPE name for a product — CPE strings are precise identifiers (e.g., cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*) and must match exactly to audit the right product.", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "cpeMatchString": { "description": "Partial CPEv2.3 pattern (e.g., \"cpe:2.3:a:apache:http_server\"). At least one of keyword or cpeMatchString is required.", "type": "string" }, "keyword": { "description": "Product name or vendor keyword (e.g., \"apache http server\", \"openssl\", \"nginx\"). At least one of keyword or cpeMatchString is required.", "type": "string" }, "limit": { "default": 20, "description": "Maximum number of CPE entries to return (default 20, max 10000).", "maximum": 10000, "minimum": 1, "type": "integer" }, "offset": { "default": 0, "description": "Zero-based page offset for pagination. When totalCount exceeds offset + returned, raise offset to reach the rest — a vendor-level keyword has nothing left to narrow toward.", "maximum": 9007199254740991, "minimum": 0, "type": "integer" } }, "type": "object" }, "name": "nvd_search_cpes", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "cpes", "totalCount", "returned", "offset" ] }, { "required": [ "error" ] } ], "properties": { "cpes": { "description": "Matching CPE dictionary entries.", "items": { "additionalProperties": false, "description": "One CPE dictionary entry.", "properties": { "cpeName": { "description": "Full CPEv2.3 name (use this as the cpeName in nvd_audit_cpe).", "type": "string" }, "deprecated": { "description": "Whether this CPE has been deprecated in the NVD dictionary.", "type": "boolean" }, "deprecatedBy": { "description": "CPE names that supersede this deprecated entry.", "items": { "description": "Superseding CPE name.", "type": "string" }, "type": "array" }, "lastModified": { "description": "ISO 8601 datetime when this CPE was last modified.", "type": "string" }, "title": { "description": "Human-readable product title. Absent when NVD has no English title.", "type": "string" } }, "required": [ "cpeName", "deprecated" ], "type": "object" }, "type": "array" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `missing_search_input`: Neither keyword nor cpeMatchString was provided. `invalid_cpe_format`: The cpeMatchString does not start with \"cpe:2.3:\", or NVD rejected it as a malformed CPE parameter. A merely truncated prefix is a legitimate partial match and returns an empty page instead. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.", "examples": [ "missing_search_input", "invalid_cpe_format", "rate_limited" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "notice": { "description": "Guidance when no CPEs matched, the offset ran past the result set, NVD returned an empty page inside a range it says has matches, or entries remain beyond this page.", "type": "string" }, "offset": { "description": "Page offset used in this query.", "type": "number" }, "returned": { "description": "Number of entries returned in this response.", "type": "number" }, "totalCount": { "description": "Total matching CPE entries before the limit was applied.", "type": "number" } }, "type": "object" } }, { "description": "Search CVEs by keyword, severity, CWE, date range, or CISA KEV status. The primary discovery tool for vulnerability surveillance and triage workflows. pubDays and lastModDays are convenience shorthands that expand to date pairs; values over 120 days are clamped to the NVD maximum and reported in the response enrichment. Returns brief summaries — call nvd_get_cve for full detail on specific IDs. At least one filter is recommended; omitting all filters returns CVEs in default NVD index order (oldest first by CVE ID).", "inputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "properties": { "cweId": { "description": "Filter by CWE weakness ID (e.g., \"CWE-79\", \"NVD-CWE-Other\").", "type": "string" }, "exactPhrase": { "default": false, "description": "When true, keyword matches as an exact phrase rather than ANDing its words independently. Requires keyword.", "type": "boolean" }, "kevOnly": { "default": false, "description": "When true, filters results to CVEs in the CISA Known Exploited Vulnerabilities catalog.", "type": "boolean" }, "keyword": { "description": "Full-text search across CVE descriptions (AND-semantics across words).", "type": "string" }, "lastModDays": { "description": "CVEs last modified in the last N days (max 120; values over 120 are clamped). Mutually exclusive with lastModStartDate/lastModEndDate.", "exclusiveMinimum": 0, "maximum": 9007199254740991, "type": "integer" }, "lastModEndDate": { "description": "ISO 8601 datetime for last-modified range end. Both required together.", "type": "string" }, "lastModStartDate": { "description": "ISO 8601 datetime for last-modified range start. Both required together. Mutually exclusive with lastModDays.", "type": "string" }, "limit": { "default": 20, "description": "Maximum number of results to return (default 20, max 2000).", "maximum": 2000, "minimum": 1, "type": "integer" }, "noRejected": { "default": true, "description": "When true (default), excludes CVEs with REJECT/Rejected status.", "type": "boolean" }, "offset": { "default": 0, "description": "Zero-based page offset for pagination.", "maximum": 9007199254740991, "minimum": 0, "type": "integer" }, "pubDays": { "description": "CVEs published in the last N days (max 120; values over 120 are clamped). Mutually exclusive with pubStartDate/pubEndDate.", "exclusiveMinimum": 0, "maximum": 9007199254740991, "type": "integer" }, "pubEndDate": { "description": "ISO 8601 datetime for publication range end. Both pubStartDate and pubEndDate required together.", "type": "string" }, "pubStartDate": { "description": "ISO 8601 datetime for publication range start. Both pubStartDate and pubEndDate required together. Mutually exclusive with pubDays.", "type": "string" }, "severity": { "description": "Filter to CVEs in exactly this CVSS severity band — NVD matches the one band, not a floor. Covering several bands (e.g. HIGH and CRITICAL) takes one call per band.", "enum": [ "LOW", "MEDIUM", "HIGH", "CRITICAL" ], "type": "string" }, "severityVersion": { "default": "v3", "description": "CVSS version to use for the severity filter. Default: v3 (maps to cvssV3Severity).", "enum": [ "v2", "v3", "v4" ], "type": "string" } }, "type": "object" }, "name": "nvd_search_cves", "outputSchema": { "$schema": "https://json-schema.org/draft/2020-12/schema", "additionalProperties": false, "anyOf": [ { "not": { "required": [ "error" ] }, "required": [ "cves", "totalCount", "returned", "offset" ] }, { "required": [ "error" ] } ], "properties": { "cves": { "description": "Matching CVE summaries. Call nvd_get_cve for full detail on specific IDs.", "items": { "additionalProperties": false, "description": "Brief summary for one matching CVE.", "properties": { "cisaVulnerabilityName": { "description": "CISA KEV vulnerability name. Present only when in the KEV catalog.", "type": "string" }, "cveId": { "description": "CVE identifier (e.g., \"CVE-2021-44228\").", "type": "string" }, "description": { "description": "Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.", "type": "string" }, "filteredSeverity": { "additionalProperties": false, "description": "Severity at the CVSS version the severity filter matched this CVE on. Present only when a severity filter was supplied and that version disagrees with the cross-version top severity above — e.g. a CVE scored v2 10.0 (HIGH) and v3.1 9.8 (CRITICAL) headlines as HIGH but matched a CRITICAL v3 query on the 9.8.", "properties": { "fromVersion": { "description": "The CVSS version the severity filter matched on.", "type": "string" }, "label": { "description": "Severity label at the CVSS version the severity filter used.", "type": "string" }, "score": { "description": "Base score at that CVSS version (0.0–10.0).", "type": "number" } }, "required": [ "label", "score", "fromVersion" ], "type": "object" }, "published": { "description": "ISO 8601 publication datetime.", "type": "string" }, "severity": { "additionalProperties": false, "description": "Top severity. Absent if no CVSS scores are present.", "properties": { "fromVersion": { "description": "CVSS version this score came from.", "type": "string" }, "label": { "description": "Highest severity label across all CVSS versions.", "type": "string" }, "score": { "description": "Highest base score (0.0–10.0).", "type": "number" } }, "required": [ "label", "score", "fromVersion" ], "type": "object" }, "vulnStatus": { "description": "NVD analysis status.", "type": "string" } }, "required": [ "cveId", "vulnStatus", "published" ], "type": "object" }, "type": "array" }, "datesClamped": { "description": "Entries for any pubDays/lastModDays values that exceeded 120 and were auto-clamped. Absent when no clamping occurred.", "items": { "additionalProperties": false, "description": "A single clamping event for one convenience date parameter.", "properties": { "clamped": { "description": "The clamped value used (max 120).", "type": "number" }, "original": { "description": "The original value supplied.", "type": "number" }, "param": { "description": "The parameter that was clamped (pubDays or lastModDays).", "type": "string" } }, "required": [ "param", "original", "clamped" ], "type": "object" }, "type": "array" }, "error": { "additionalProperties": {}, "description": "Present when the call failed. Absent on success.", "properties": { "code": { "description": "JSON-RPC error code for this failure.", "maximum": 9007199254740991, "minimum": -9007199254740991, "type": "integer" }, "data": { "additionalProperties": {}, "properties": { "reason": { "description": "Machine-readable failure mode. Declared by this tool: `exact_phrase_without_keyword`: exactPhrase was set without a keyword. It selects how keyword matches and has nothing to modify on its own; NVD rejects the underlying flag on the same grounds. `mutually_exclusive_params`: Both pubDays and pubStartDate/pubEndDate provided, or both lastModDays and lastModStartDate/lastModEndDate. `missing_date_pair`: Only one of pubStartDate/pubEndDate (or lastModStartDate/lastModEndDate) was provided — NVD requires both. `date_range_inverted`: The end date is before the start date. `date_range_exceeds_max`: Explicit pubStartDate/pubEndDate or lastModStartDate/lastModEndDate span more than 120 days. `invalid_date_format`: A date string provided for pubStartDate, pubEndDate, lastModStartDate, or lastModEndDate is not a valid ISO 8601 datetime. `invalid_severity_for_version`: severity=\"CRITICAL\" was specified with severityVersion=\"v2\" — CVSS v2 has no CRITICAL tier. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.", "examples": [ "exact_phrase_without_keyword", "mutually_exclusive_params", "missing_date_pair", "date_range_inverted", "date_range_exceeds_max", "invalid_date_format", "invalid_severity_for_version", "rate_limited" ], "type": "string" }, "recovery": { "additionalProperties": {}, "description": "Actionable next step for the caller.", "properties": { "hint": { "type": "string" } }, "required": [ "hint" ], "type": "object" }, "retryable": { "description": "Whether retrying may succeed.", "type": "boolean" } }, "type": "object" }, "message": { "description": "Human-readable description of what went wrong.", "type": "string" } }, "required": [ "code", "message" ], "type": "object" }, "filtersApplied": { "additionalProperties": false, "description": "The non-default filters this query actually applied — the ones that can account for an empty or unexpectedly narrow result set. Absent when the query ran unfiltered, which is itself the answer when a result set is unexpectedly broad.", "properties": { "cweId": { "description": "The CWE weakness filter that was applied.", "type": "string" }, "exactPhrase": { "description": "Present as true when the keyword was matched as an exact phrase rather than word-by-word.", "type": "boolean" }, "kevOnly": { "description": "Present as true when results were limited to the CISA KEV catalog.", "type": "boolean" }, "keyword": { "description": "The keyword filter that was applied.", "type": "string" }, "noRejected": { "description": "Present as false when rejected CVEs were left in the results.", "type": "boolean" }, "severity": { "description": "The exact CVSS severity band that was applied — results are limited to this band alone, so higher bands are not included.", "type": "string" }, "severityVersion": { "description": "The CVSS version the severity filter matched on. Present only alongside severity.", "type": "string" } }, "type": "object" }, "notice": { "description": "Guidance when no CVEs were returned — distinguishes a query nothing matched from an offset past the result set from an empty page NVD returned inside a range it says has matches — or, on a partial page, the offset that reaches the next one.", "type": "string" }, "offset": { "description": "Page offset used in this query.", "type": "number" }, "returned": { "description": "Number of CVEs returned in this response.", "type": "number" }, "totalCount": { "description": "Total matching CVEs in NVD before pagination.", "type": "number" } }, "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:503bfdc4e418d0a9f2d14100cbe16093f33ca02a5c01aa7112df8a22168398ac | sha256sum