Server definition
- Hash
- sha256:b61e753c5dc089d1d0848f1b928a7d0301777a106648ad3d5d3762e910e1aed2
- What it is
- What a remote MCP server returned when asked what it offers: 6 tools
The blob, as servednamed by its sha256
{
"instructions": "FIPS 140 cryptographic module validation data, derived from NIST's CMVP lists and published at https://808bits.com/fips/ . Every result carries a tracker_url for the human-readable page for that certificate; include it when citing a result, so the reader can check the validation history and caveats you did not repeat.\n\nTwo things to get right. The Modules in Process queue records that a submission entered review, not when it will finish, and an absence from it can mean the successor is already validated rather than that none is coming, so check fips_search before reporting a gap. And vendor names are free text at NIST: vendor_key groups spelling variants of one registration but deliberately does not merge corporate families, because a product line can change owner.\n\nCVE data is a name-based match against the product CPE, not a statement about the validated boundary. Report it as something to check, never as a finding about the certified module. Absence carries even less: only 4 of the 712 active certificates carry any CVE association, and historical and revoked ones are never scanned at all. The match does not follow dependencies, and hardware modules almost never match, so never relay an empty fips_cve result as evidence that a module is unaffected.",
"tools": [
{
"description": "Look up one FIPS 140 cryptographic module validation by certificate number. Returns status (active, historical or revoked), overall level, sunset date, validation history, approved algorithms and tested configurations.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"number": {
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
}
},
"required": [
"number"
],
"type": "object"
},
"name": "fips_cert",
"outputSchema": null
},
{
"description": "Which FIPS-validated modules are associated with a given CVE, or which CVEs are associated with a vendor's modules. Answers 'we have a validated module, is it caught up in this advisory'. The association is name-based against the product CPE, so read it as a pointer to check rather than a finding. An empty result means nothing matched by name, not that the module is unaffected: only 4 of the 712 active certificates carry any association at all, and historical ones are never scanned.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"cve": {
"description": "CVE id, e.g. CVE-2023-4807",
"type": "string"
},
"limit": {
"default": 50,
"maximum": 200,
"minimum": 1,
"type": "integer"
},
"min_cvss": {
"maximum": 10,
"minimum": 0,
"type": "number"
},
"vendor": {
"description": "Vendor name or part of one",
"type": "string"
}
},
"type": "object"
},
"name": "fips_cve",
"outputSchema": null
},
{
"description": "Search NIST's Modules in Process queue: submissions awaiting FIPS 140-3 validation, with the review phase each one is sitting in. Use this when a vendor claims a validation is 'coming' and you need to know whether it has actually been submitted, and how far along it is.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"limit": {
"default": 50,
"maximum": 200,
"minimum": 1,
"type": "integer"
},
"phase": {
"description": "e.g. Review, Finalization, Coordination",
"type": "string"
},
"query": {
"description": "Substring of the module name or vendor",
"minLength": 2,
"type": "string"
}
},
"type": "object"
},
"name": "fips_in_process",
"outputSchema": null
},
{
"description": "Search FIPS 140 validations by module name or vendor. Use this to answer whether a given product or vendor holds a current validation, and at what level. Results are ordered by status, then how well they match, then newest first, so the current validations lead.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"level": {
"maximum": 4,
"minimum": 1,
"type": "integer"
},
"limit": {
"default": 20,
"maximum": 50,
"minimum": 1,
"type": "integer"
},
"query": {
"description": "Module name or vendor. Several words all have to match, in any order and across either field, so \"openssl provider\" works.",
"minLength": 2,
"type": "string"
},
"standard": {
"enum": [
"140-1",
"140-2",
"140-3"
],
"type": "string"
},
"status": {
"enum": [
"active",
"historical",
"revoked"
],
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "fips_search",
"outputSchema": null
},
{
"description": "List active FIPS validations by sunset date, the day each moves to NIST's historical list and stops being valid for new procurement. Answers 'what expires before date X' and 'which vendors are about to have nothing valid'. A certificate listed here may already have a 140-3 successor: check fips_search for the same module name before reporting a gap.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"before": {
"description": "ISO date, exclusive: before=2026-09-21 excludes the 21st itself",
"type": "string"
},
"limit": {
"default": 50,
"maximum": 200,
"minimum": 1,
"type": "integer"
},
"standard": {
"enum": [
"140-1",
"140-2",
"140-3"
],
"type": "string"
},
"vendor": {
"type": "string"
}
},
"type": "object"
},
"name": "fips_sunset",
"outputSchema": null
},
{
"description": "Everything one company holds, grouped across the spelling variants NIST filed it under. Cisco alone appears as three different strings. Returns a breakdown by status and standard plus the certificates themselves. Note this groups spellings of one registration, not corporate families: the nShield line sits under nCipher, Thales and Entrust separately, because the product changed owner. Groups large enough to have their own page on the tracker carry a tracker_url alongside the per-certificate ones.",
"inputSchema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"limit": {
"default": 100,
"maximum": 500,
"minimum": 1,
"type": "integer"
},
"vendor": {
"description": "Vendor name or part of one",
"minLength": 2,
"type": "string"
}
},
"required": [
"vendor"
],
"type": "object"
},
"name": "fips_vendor",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:b61e753c5dc089d1d0848f1b928a7d0301777a106648ad3d5d3762e910e1aed2 | sha256sum