Server definition
- Hash
- sha256:9e6b6f6b52a81399c42b97c29ae18aab081746c7a404b4b25cf8caae94e1a047
- What it is
- What a remote MCP server returned when asked what it offers: 4 tools
The blob, as servednamed by its sha256
{
"instructions": "MacTech Solutions STIG server: 2029 DISA STIG hardening rules across RHEL 8/9, Windows 11, Windows Server 2022, and Cisco IOS Router NDM - searchable, with full check and fix text per rule and NIST control mappings. Use search_stig to find rules, get_stig_rule for implementation detail, list_stig_benchmarks for coverage, and export_stig_checklist to produce a DISA .ckl.",
"tools": [
{
"description": "Generate a DISA STIG Viewer checklist (.ckl XML) for a benchmark, optionally filtered by severity and pre-populated with findings. This is the artifact an assessment actually hands over - STIG Viewer opens it, eMASS ingests it, and a POA&M is written from it. Rules you do not supply a status for come out as Not_Reviewed. Call this when the user wants a checklist, a scan result recorded, or evidence to submit, rather than just to read a rule.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"findings": {
"description": "Per-rule results. Anything omitted stays Not_Reviewed - an unreviewed rule must never be reported as passing.",
"items": {
"properties": {
"comments": {
"description": "Assessor justification",
"type": "string"
},
"finding_details": {
"description": "What was actually observed",
"type": "string"
},
"status": {
"description": "Open = failed, NotAFinding = passed, Not_Applicable = out of scope",
"enum": [
"Open",
"NotAFinding",
"Not_Applicable",
"Not_Reviewed"
],
"type": "string"
},
"sv_id": {
"type": "string"
}
},
"required": [
"sv_id",
"status"
],
"type": "object"
},
"type": "array"
},
"host_fqdn": {
"type": "string"
},
"host_ip": {
"type": "string"
},
"host_name": {
"description": "Asset hostname recorded in the checklist",
"type": "string"
},
"product": {
"description": "Which benchmark to build the checklist from",
"enum": [
"cisco_ios_router_ndm",
"cisco_ios_router_rtr",
"cisco_ios_switch_l2s",
"cisco_ios_switch_ndm",
"cisco_ios_switch_rtr",
"cisco_ise_nac",
"cisco_ise_ndm",
"cisco_nxos_switch_l2s",
"cisco_nxos_switch_ndm",
"cisco_nxos_switch_rtr",
"ubuntu2204",
"rhel8",
"rhel9",
"windows11",
"windows2022"
],
"type": "string"
},
"severity": {
"description": "Limit to one severity, e.g. high for a CAT I-only checklist",
"enum": [
"high",
"medium",
"low"
],
"type": "string"
}
},
"required": [
"product"
],
"type": "object"
},
"name": "export_stig_checklist",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"benchmark": {
"type": "string"
},
"ckl": {
"description": "The .ckl XML. Write it to filename rather than pasting it into a reply.",
"type": "string"
},
"filename": {
"type": "string"
},
"note": {
"type": "string"
},
"rule_count": {
"type": "number"
},
"status_counts": {
"additionalProperties": false,
"properties": {
"NotAFinding": {
"type": "number"
},
"Not_Applicable": {
"type": "number"
},
"Not_Reviewed": {
"type": "number"
},
"Open": {
"type": "number"
}
},
"required": [
"Open",
"NotAFinding",
"Not_Applicable",
"Not_Reviewed"
],
"type": "object"
}
},
"required": [
"benchmark",
"rule_count",
"status_counts",
"filename",
"note",
"ckl"
],
"type": "object"
}
},
{
"description": "Get the complete detail for one DISA STIG rule by its SV id (from search_stig): the requirement discussion, the exact check procedure an assessor runs, the fix text, severity, NIST control mapping, and whether it is SCAP-automatable. Call this when the user needs to implement or verify a specific rule.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"sv_id": {
"description": "Rule id, e.g. \"SV-257777r991589_rule\" (fragments matched if unique)",
"type": "string"
}
},
"required": [
"sv_id"
],
"type": "object"
},
"name": "get_stig_rule",
"outputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"automation_level": {
"type": "string"
},
"automation_source": {
"type": "string"
},
"benchmark": {
"type": "string"
},
"category": {
"type": "string"
},
"check_text": {
"description": "DISA's own check procedure - quote it rather than paraphrasing.",
"type": "string"
},
"description": {
"type": "string"
},
"fix_text": {
"type": "string"
},
"nist_id": {
"description": "CCI identifier, e.g. CCI-000366.",
"type": "string"
},
"product": {
"type": "string"
},
"severity": {
"type": "string"
},
"severity_category": {
"description": "CAT I / II / III, the vocabulary assessors use.",
"type": "string"
},
"sv_id": {
"type": "string"
},
"title": {
"type": "string"
}
},
"required": [
"sv_id",
"nist_id",
"severity",
"severity_category",
"title",
"description",
"check_text",
"fix_text",
"product",
"benchmark",
"category",
"automation_level",
"automation_source"
],
"type": "object"
}
},
{
"description": "List the DISA STIG benchmarks this server covers, with versions, rule counts, and severity breakdowns. Call this first when unsure whether a platform is covered.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {},
"type": "object"
},
"name": "list_stig_benchmarks",
"outputSchema": null
},
{
"description": "Search DISA STIG hardening rules across RHEL 8, RHEL 9, Windows 11, Windows Server 2022, and Cisco IOS Router NDM benchmarks - by keyword (matched against rule IDs and titles first, then descriptions), filterable by product, severity (high/medium/low, mapping to CAT I/II/III), category, and automation level. Call this when the user asks how to harden one of these platforms, what a STIG requires, or which rules cover a topic like SSH, passwords, or auditing. Returns summaries; use get_stig_rule for full check and fix text.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"automation": {
"enum": [
"automated",
"manual_only"
],
"type": "string"
},
"format": {
"description": "\"summary\" (default) returns each rule inline as JSON. \"links\" returns MCP resource links, which hosts can render as pickable items the user opens on demand. Not smaller - the title and severity you need in order to choose are the bulk of either shape - so choose on how the client presents results, not to save tokens.",
"enum": [
"summary",
"links"
],
"type": "string"
},
"limit": {
"description": "Max results per page (default 20)",
"maximum": 50,
"minimum": 1,
"type": "integer"
},
"offset": {
"description": "Skip this many matches. Pass the next_offset from a previous response to reach results beyond the first page.",
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"product": {
"description": "Limit to one benchmark",
"enum": [
"cisco_ios_router_ndm",
"cisco_ios_router_rtr",
"cisco_ios_switch_l2s",
"cisco_ios_switch_ndm",
"cisco_ios_switch_rtr",
"cisco_ise_nac",
"cisco_ise_ndm",
"cisco_nxos_switch_l2s",
"cisco_nxos_switch_ndm",
"cisco_nxos_switch_rtr",
"ubuntu2204",
"rhel8",
"rhel9",
"windows11",
"windows2022"
],
"type": "string"
},
"query": {
"description": "Keyword or rule id fragment, e.g. \"ssh banner\" or \"SV-257777\"",
"type": "string"
},
"severity": {
"description": "high=CAT I, medium=CAT II, low=CAT III",
"enum": [
"high",
"medium",
"low"
],
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "search_stig",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:9e6b6f6b52a81399c42b97c29ae18aab081746c7a404b4b25cf8caae94e1a047 | sha256sum