Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,536Letters: 14Defects: 1,322counted 4 min ago
teppi

Server definition

Hash
sha256:768b5efd4126ab683abf7271026f70676a3b25bed1139838f6db1f7ef32b5b99
What it is
What a remote MCP server returned when asked what it offers: 1 tools

The blob, as servednamed by its sha256

{ "instructions": "Query Microsoft security updates (Patch Tuesday) from the official MSRC Security Update Guide API. Use msrc_search to find, filter, and retrieve vulnerabilities and their fixes. Look up a specific CVE with cve='CVE-...' (full detail, works across all months), find what a KB fixes with kb='5094123' — or pass a list (kb=['5094123', ...], up to 30) to resolve a whole machine's update list in one call — or filter the latest month by product, severity, exploited=True, or min_cvss. Scope any search to a product watchlist with product_profile='identity-core' (built-ins: identity-core, endpoint, server-infrastructure; extend via a JSON file at MSRC_PROFILES_PATH) or ad-hoc products=[...] / product_families=[...] lists — matching is local and profile contents never leave the host. Results are enriched with EPSS exploitation probabilities and CISA KEV catalog status: filter with kev=True (confirmed exploited, federal due dates), ransomware=True (known ransomware campaign use), min_epss=0.5 (EPSS >= 50%), or exploitation_likely=True (Microsoft's own 'Exploitation More Likely' assessment). Filter by weakness class with cwe='CWE-416'. Add include_chain=True to a kb= lookup to walk Microsoft-stated supersedence links (which KBs it replaces), include_kb_details=True for per-KB fixed builds and restart requirements, include_known_issues=True for the issues Microsoft has publicly confirmed the update introduces (symptoms, workarounds, resolving KB), best-effort from the KB's support page — published mainly for Windows updates; other products usually report none_published — and include_update_summary=True for what an update changes (the KB page's summary and improvements highlights, same page, one fetch). Set include_stats=True with limit=0 for a month overview (counts by severity, impact, product family, exploited, KEV). Use list_months=True to discover available monthly releases. When no month is given, results default to the most recent release whose Patch Tuesday has occurred; the upcoming month's pre-release document (early/out-of-band entries only) is available via month=. A guided analyst workflow is available as the monthly_triage prompt.", "tools": [ { "description": "Search Microsoft security updates (Patch Tuesday) from the official MSRC API.\n\nCombines keyword search, CVE/KB lookup, and product/severity/exploitation\nfiltering into a single flexible tool. All filter parameters are optional\nand can be combined. When no filters are provided, returns the most urgent\nvulnerabilities from the most recent *released* Patch Tuesday (CISA-KEV-\nlisted or exploited first, then by EPSS exploitation probability, severity,\nand CVSS score). The upcoming month's document exists before its Patch\nTuesday but only holds early Chromium/third-party and out-of-band entries;\nit is skipped by default and served only when requested via month=.\nResults are enriched with EPSS scores (FIRST.org daily exploit\nprediction, 0-1) and CISA KEV (Known Exploited Vulnerabilities) catalog\ndata when available.\n\nUse this tool to:\n- Get the latest Patch Tuesday overview (include_stats=True, limit=0)\n- Browse the most urgent fixes this month (no filters)\n- Look up a specific CVE with full detail (cve=\"CVE-2026-41108\") -- works\n across all months, returns KBs, affected products, CVSS, description,\n FAQs, EPSS score, and KEV status\n- Find which CVEs a KB article fixes (kb=\"5094123\" or kb=\"KB5094123\") --\n scans recent months, or a specific month when combined with month=\n- Look up many KBs in one call (kb=[\"5094123\", \"KB5094127\", ...], up to\n 30) -- e.g. a machine's installed-update list; returns one grouped\n per-KB result entry each, with per-KB found/not-found status\n- Check whether a KB has been superseded by newer patches (kb=\"5087538\",\n include_chain=True) -- walks Microsoft-stated supersedence links\n- See what Microsoft has confirmed an update breaks (kb=...,\n include_known_issues=True) -- known issues from the KB's public support\n page: symptoms, workarounds, and the resolving update when stated\n- See what an update changes (kb=..., include_update_summary=True) -- the\n KB support page's summary and improvements highlights, beyond the\n security fixes already listed in the MSRC data\n- Find KEV-listed CVEs this month (kev=True) -- confirmed exploited, with\n federal remediation due dates\n- High exploitation probability (min_epss=0.5) -- EPSS >= 50%\n- Search by keyword (query=\"Exchange\" or query=\"DNS spoofing\")\n- Filter to a product (product=\"Windows Server 2022\") -- partial match\n- Filter to a product watchlist (product_profile=\"identity-core\", or\n products=[\"Exchange Server\", \"Windows Server\"] /\n product_families=[\"Windows\", \"Azure\"]) -- keeps vulns matching any listed\n product or family; matching is local and profiles never leave the host\n- Filter by severity (severity=\"Critical\") -- Critical/Important/Moderate/Low\n- Find actively exploited vulnerabilities (exploited=True)\n- Find publicly disclosed zero-days (publicly_disclosed=True)\n- Filter by CVSS score (min_cvss=8.0)\n- Look at a past month (month=\"2026-Apr\" or month=\"2026-04\")\n- Combine filters (product=\"Exchange\" + severity=\"Critical\" + month=\"2026-05\")\n- Search a historical range (query=\"HTTP.sys\" + months_back=6, or\n start_month=\"2026-Jan\" + end_month=\"2026-Jun\") -- aggregates matching\n CVEs across released months with per-month trend counts\n- Paginate with offset (offset=10, limit=10 for page 2)\n\nArgs:\n query: Optional keyword; case-insensitive match across CVE ID, title,\n description, component tag, and affected product names.\n cve: Optional CVE ID (e.g. \"CVE-2026-41108\"). Fast path: ignores other\n filters and returns full detail for that single CVE, searching\n across all months automatically.\n kb: Optional KB article number (e.g. \"5094123\" or \"KB5094123\") or a\n list of up to 30 of them for a batched lookup. Fast path: returns\n the CVEs fixed by that KB, scanning the most recent months (up to\n 6), or only the given month when month= is also set. A list input\n returns a grouped response instead: a results array with one entry\n per KB (\"kb\", \"found\", and on success the same body as a\n single-KB lookup; on a miss \"error\"/\"error_kind\"), deduplicated,\n order preserved. limit/offset apply per KB; other filters are\n ignored. Accepts numeric KB ids only (any malformed list entry\n fails the whole call); kb_articles in results may also contain\n non-KB vendor-fix labels such as \"Release Notes\", which cannot be\n looked up here.\n month: Optional monthly release to search, formatted \"2026-Apr\" or\n \"2026-04\". Defaults to the most recent release whose Patch\n Tuesday (second Tuesday of the month) has already occurred; pass\n the upcoming month explicitly to see its pre-release entries.\n Combined with kb=, restricts the KB lookup to that month.\n product: Optional product name filter (case-insensitive partial match\n against affected product names, e.g. \"Windows Server 2022\").\n product_profile: Optional named watchlist (e.g. \"identity-core\") that\n expands locally into product/family matchers. Built-in profiles can\n be overridden/extended via a JSON file at MSRC_PROFILES_PATH. An\n unknown name returns an invalid_input error listing the available\n profiles. Profile contents are matched locally and never sent to\n MSRC, FIRST.org, CISA, or telemetry.\n products: Optional list of product-name partial matchers. A vulnerability\n is kept if any entry matches one of its affected products.\n product_families: Optional list of product-family partial matchers. A\n vulnerability is kept if any entry matches one of its product\n families. Combined with products/product_profile as a union (match\n any listed product OR family).\n severity: Optional maximum-severity filter. Valid values: Critical,\n Important, Moderate, Low.\n exploited: Optional filter for vulnerabilities known to be exploited\n in the wild (True) or not (False), per Microsoft's assessment.\n publicly_disclosed: Optional filter for publicly disclosed\n vulnerabilities.\n kev: Optional filter for CVEs on (True) or off (False) the CISA Known\n Exploited Vulnerabilities catalog.\n ransomware: Optional filter for CVEs whose CISA KEV entry reports\n known ransomware campaign use (True) or not / not on KEV (False).\n exploitation_likely: Optional filter on Microsoft's latest-release\n exploitation assessment: True matches \"Exploitation More Likely\"\n or \"Exploitation Detected\"; False matches everything else\n (including unassessed entries). Matching results include an\n exploitation_assessment field.\n cwe: Optional weakness filter; case-insensitive substring match\n against CWE entries (e.g. \"CWE-416\" or \"use after free\").\n Matching results include their cwe list.\n min_epss: Optional minimum EPSS score (0-1), the probability of\n exploitation in the next 30 days (e.g. 0.5 for >= 50%).\n min_cvss: Optional minimum CVSS base score (0-10).\n attack_vector: Optional CVSS attack-vector filter, one of N (network),\n A (adjacent), L (local), P (physical). Matches the parsed CVSS v3.x\n vector; entries without a parseable vector are excluded.\n privileges_required: Optional CVSS privileges-required filter, one of\n N (none), L (low), H (high).\n user_interaction: Optional CVSS user-interaction filter, one of\n N (none), R (required).\n scope: Optional CVSS scope filter, one of U (unchanged), C (changed).\n include_chain: When True together with kb=, adds a supersedence_chain\n showing which KBs this KB replaces (newest to oldest), walked from\n Microsoft-stated supersedence links. Ignored without kb=.\n include_guidance: When True together with cve=, adds a guidance list to\n the CVE detail output with any Microsoft-provided mitigations,\n workarounds, and will-not-fix advisories (type/description/url).\n Omitted by default to keep responses lean. Ignored without cve=.\n include_references: When True, adds deterministic reference links\n (MSRC, NVD, EPSS, and KEV when listed) to each result row in\n month/KB/trend lists. CVE detail lookups always include them.\n include_kb_details: When True, kb_articles entries become full objects\n (per-KB url, fixed_build, supersedence, sub_type, and\n restart_required) instead of bare KB numbers; on cve= lookups it\n additionally adds restart_required to each KB entry.\n include_kev_details: When True, KEV-listed rows carry the full KEV\n entry (due_date, ransomware_use, required_action, vendor_project,\n product, vulnerability_name) instead of a boolean flag; on cve=\n lookups it extends the kev block with the extra catalog fields.\n include_known_issues: When True together with kb=, adds a known_issues\n block per KB with the issues Microsoft has publicly confirmed for\n that update (title, symptoms, workaround, and the resolving KB\n when stated), scraped best-effort from the KB's support page on\n support.microsoft.com. This reports what Microsoft has confirmed\n breaks -- it does not predict behavior in a specific environment.\n The block's status field is honest about coverage: \"published\"\n (issues listed), \"none_published\" (Microsoft publishes no\n known-issues data for this KB -- the norm for most non-Windows\n products; Windows cumulative/preview updates are the main\n source), or \"unavailable\" (the page could not be fetched or\n parsed; NOT the same as no issues). Attached even when the KB is\n not found in MSRC security releases (e.g. preview-only updates).\n Ignored without kb=.\n include_update_summary: When True together with kb=, adds an\n update_summary block per KB describing what the update changes,\n scraped best-effort from the same support.microsoft.com KB page:\n the page's Summary/Highlights text plus its Improvements bullet\n list (size-capped; truncated=True marks a capped block). The\n status field is honest like known_issues: \"published\" (a summary\n exists), \"none_published\" (Microsoft publishes no summary section\n for this KB), or \"unavailable\" (the page could not be fetched or\n parsed; NOT the same as no summary). Attached even when the KB is\n not found in MSRC security releases; combines freely with\n include_known_issues -- both blocks are served by a single fetch\n of the same page. Ignored without kb=.\n include_temporal: When True, cvss blocks gain the CVSS temporal score\n Microsoft publishes (exploit-code maturity adjusted). Applies to\n cve= detail and to list rows that carry a cvss block.\n list_months: When True, ignore other filters and return the catalog of\n available monthly releases (id, title, initial/current release\n dates, newest first) — useful for discovering valid month= values\n and spotting same-month revisions.\n format: Output format for a monthly/filtered search: \"json\" (default,\n most complete), \"markdown\", or \"csv\". \"markdown\" adds a prioritized\n triage briefing (executive summary + table) under a markdown key;\n \"csv\" adds a spreadsheet-ready table under a csv key plus a columns\n list. The JSON vulnerabilities list is always included. Ignored for\n cve=/kb= fast-path lookups.\n report: Optional report profile for format=\"markdown\"/\"csv\". Currently\n only \"triage\" (the default rendering) is supported; reserved for\n future report shapes.\n force_refresh: When True, bypass the in-process caches for this request\n and re-fetch the MSRC document and EPSS/KEV enrichment from source.\n Use to pick up a same-day MSRC revision or fresh EPSS/KEV data.\n Only the data needed for this request is refreshed; unrelated cached\n months are left intact.\n include_freshness: When True (or when force_refresh is used), add a\n freshness block to the response reporting the cache age and TTL of\n the MSRC document and the EPSS/KEV enrichment data.\n months_back: Optional historical-trend control; search the N most recent\n released months (N >= 1) instead of a single month, aggregating\n matches with per-month counts. Mutually exclusive with\n start_month/end_month. Capped at 12 months per request.\n start_month: Optional start of a historical-trend range (e.g. \"2026-Jan\"\n or \"2026-01\"), inclusive. When end_month is omitted the range runs\n through the latest released month. Capped at 12 months.\n end_month: Optional end of a historical-trend range (inclusive); requires\n start_month (or months_back). Pre-release months are excluded.\n limit: Maximum number of results to return (default: 10, max: 100).\n Set to 0 with include_stats=True for a stats-only month overview.\n offset: Number of results to skip for pagination (default: 0).\n include_stats: When True, includes aggregate counts (by severity,\n impact, product family, exploited, KEV, publicly disclosed) for\n the filtered result set.\n\nReturns:\n Dictionary with:\n - month: Release ID (e.g. \"2026-Jun\") and title/release date\n - total_found: Number of vulnerabilities matching the filters\n - vulnerabilities: List of compact vulnerability summaries (up to\n limit) with epss_score and kev flag when available; full detail\n (epss_percentile, KEV due dates) returned for cve= lookups\n - filters_applied: Summary of which filters were used\n - stats: (only when include_stats=True) aggregate counts\n - supersedence_chain / chain_complete: (only for kb= lookups with\n include_chain=True) the walked chain, newest to oldest\n - known_issues: (only for kb= lookups with include_known_issues=True)\n per-KB block with status (\"published\" / \"none_published\" /\n \"unavailable\"), an issues list (title, symptoms, workaround,\n resolution, resolved_by) when published, a note otherwise, and the\n source_url of the Microsoft support page\n - update_summary: (only for kb= lookups with\n include_update_summary=True) per-KB block with status (\"published\"\n / \"none_published\" / \"unavailable\"), the page title, a summary\n string and an improvements list of what the update changes when\n published (truncated=True when size caps trimmed content), a note\n otherwise, and the source_url of the Microsoft support page\n - total_kbs / results: (only when kb= is a list) grouped batch output;\n results holds one entry per KB with kb, found, and either the\n single-KB response body or a per-KB error/error_kind, while the\n top-level total_found sums across all KBs\n - guidance: (only for cve= lookups with include_guidance=True) list of\n mitigation/workaround/will-not-fix advisories, when Microsoft\n provides them\n - format / markdown / csv / columns: (only when format=\"markdown\" or\n \"csv\") the chosen format plus the rendered triage view; csv also\n carries the stable column-name list\n - freshness: (only with include_freshness=True or force_refresh=True)\n cache age/TTL for the MSRC document and EPSS/KEV enrichment\n - range / months_searched / trend: (only for historical-trend searches\n via months_back or start_month/end_month) the resolved month range,\n the number of months searched, and per-month aggregate counts\n (total, by_severity, exploited, publicly_disclosed, kev)\n - available_months: (only with list_months=True) the release catalog,\n newest first\n - error / error_kind: (only on failure) a message plus a category\n (invalid_input, not_found, upstream, internal)\n - note: (when relevant) explains month selection, e.g. that a newer\n pre-Patch-Tuesday document was skipped, or (with\n release_status=\"pre-patch-tuesday\") that the requested month has\n not had its Patch Tuesday yet", "inputSchema": { "properties": { "attack_vector": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "cve": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "cwe": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "end_month": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "exploitation_likely": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ], "default": null }, "exploited": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ], "default": null }, "force_refresh": { "default": false, "type": "boolean" }, "format": { "default": "json", "type": "string" }, "include_chain": { "default": false, "type": "boolean" }, "include_freshness": { "default": false, "type": "boolean" }, "include_guidance": { "default": false, "type": "boolean" }, "include_kb_details": { "default": false, "type": "boolean" }, "include_kev_details": { "default": false, "type": "boolean" }, "include_known_issues": { "default": false, "type": "boolean" }, "include_references": { "default": false, "type": "boolean" }, "include_stats": { "default": false, "type": "boolean" }, "include_temporal": { "default": false, "type": "boolean" }, "include_update_summary": { "default": false, "type": "boolean" }, "kb": { "anyOf": [ { "type": "string" }, { "items": { "type": "string" }, "type": "array" }, { "type": "null" } ], "default": null }, "kev": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ], "default": null }, "limit": { "default": 10, "maximum": 100, "minimum": 0, "type": "integer" }, "list_months": { "default": false, "type": "boolean" }, "min_cvss": { "anyOf": [ { "maximum": 10, "minimum": 0, "type": "number" }, { "type": "null" } ], "default": null }, "min_epss": { "anyOf": [ { "maximum": 1, "minimum": 0, "type": "number" }, { "type": "null" } ], "default": null }, "month": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "months_back": { "anyOf": [ { "type": "integer" }, { "type": "null" } ], "default": null }, "offset": { "default": 0, "minimum": 0, "type": "integer" }, "privileges_required": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "product": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "product_families": { "anyOf": [ { "items": { "type": "string" }, "type": "array" }, { "type": "null" } ], "default": null }, "product_profile": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "products": { "anyOf": [ { "items": { "type": "string" }, "type": "array" }, { "type": "null" } ], "default": null }, "publicly_disclosed": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ], "default": null }, "query": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "ransomware": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ], "default": null }, "report": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "scope": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "severity": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "start_month": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null }, "user_interaction": { "anyOf": [ { "type": "string" }, { "type": "null" } ], "default": null } }, "type": "object" }, "name": "msrc_search", "outputSchema": { "additionalProperties": true, "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:768b5efd4126ab683abf7271026f70676a3b25bed1139838f6db1f7ef32b5b99 | sha256sum