cisa-cybersecurity-mcp-server
このMCPでできること
Searches CISA's Known Exploited Vulnerabilities catalog and industrial control system advisories, checks CVE status, and applies CISA SSVC remediation timelines.
ツール
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['cveIds'], 'properties': {'cveIds': {'type': 'array', 'items': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'One CVE identifier, e.g. CVE-2025-39964. Case and surrounding whitespace are normalized.'}, 'maxItems': 200, 'minItems': 1, 'description': 'CVE identifiers to check, up to 200 per call. The whole batch costs zero upstream requests, so a full CVE alias list from a dependency audit can be checked in one call â\x80\x94 pair a large batch with detail "summary".'}, 'detail': {'enum': ['full', 'summary'], 'type': 'string', 'default': 'full', 'description': 'full returns every field of each in-KEV entry. summary returns only cveId, inKev, dateAdded, dueDate, daysUntilDue, overdue, directive, vendorProject, product, knownRansomwareCampaignUse, and forensicTriage â\x80\x94 the triage view for a large batch. Not-in-KEV results are the same under both.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['results', 'foundCount', 'notFoundCount', 'catalog', 'asOf']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'asOf': {'type': 'string', 'description': 'The UTC date daysUntilDue and overdue were computed against, YYYY-MM-DD.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['catalog_unavailable'], 'description': 'Machine-readable failure mode. Declared by this tool: `catalog_unavailable`: No KEV catalog snapshot is held and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Guidance when none of the supplied CVE IDs are in the catalog.'}, 'catalog': {'type': 'object', 'required': ['catalogVersion', 'dateReleased', 'count', 'fetchedAt'], 'properties': {'count': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Entries in the loaded snapshot.'}, 'fetchedAt': {'type': 'string', 'description': 'When this server fetched the snapshot, ISO 8601.'}, 'dateReleased': {'type': 'string', 'description': 'Release timestamp the snapshot carries.'}, 'catalogVersion': {'type': 'string', 'description': 'Version string of the loaded catalog snapshot.'}}, 'description': 'Which catalog snapshot answered this call.', 'additionalProperties': False}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'inKev'], 'properties': {'cwes': {'type': 'array', 'items': {'type': 'string', 'pattern': '^CWE-[0-9]+$', 'description': 'One CWE identifier.'}, 'description': 'Associated CWEs. Empty on some entries, and a CWE filter excludes those. Absent under detail "summary".'}, 'cveId': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'The CVE identifier that was looked up.'}, 'inKev': {'type': 'boolean', 'description': 'Whether the CVE is in the KEV catalog. False is a normal result, not an error.'}, 'kevUrl': {'type': 'string', 'description': 'Absolute URL of the KEV catalog page for this CVE. Absent under detail "summary".'}, 'dueDate': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Federal remediation deadline CISA assigned, YYYY-MM-DD.'}, 'overdue': {'type': 'boolean', 'description': 'True when the due date is strictly before the echoed asOf date.'}, 'product': {'type': 'string', 'description': "CISA's own product label â\x80\x94 free text, not a CPE."}, 'dateAdded': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Date CISA added the entry to the catalog, YYYY-MM-DD.'}, 'directive': {'anyOf': [{'enum': ['BOD 26-04', 'BOD 22-01'], 'type': 'string'}, {'type': 'null'}], 'description': 'The binding operational directive the entry cites, or null when it cites neither â\x80\x94 most entries name none, and none is never inferred from age.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'url'], 'properties': {'url': {'type': 'string', 'description': 'Absolute reference URL, verbatim from the notes field.'}, 'kind': {'enum': ['nvd', 'cisa', 'bod_guidance', 'forensic_triage', 'vendor', 'other'], 'type': 'string', 'description': 'What the link points at: the NVD detail record, a cisa.gov page, BOD 26-04 guidance, the forensic-triage requirements, a vendor page, or an unclassifiable URL.'}, 'label': {'type': 'string', 'description': "CISA's own label for the segment, when the notes entry carried one."}}, 'description': 'One reference URL parsed from the entry notes.', 'additionalProperties': False}, 'description': 'Every reference URL in the notes field, in notes order, each classified by kind. Absent under detail "summary".'}, 'daysUntilDue': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Whole days from the echoed asOf date to the due date; negative once overdue.'}, 'vendorProject': {'type': 'string', 'description': "CISA's own vendor label â\x80\x94 free text, not a CPE vendor component."}, 'forensicTriage': {'enum': ['Yes', 'No'], 'type': 'string', 'description': 'Whether the entry falls in the BOD 26-04 three-day forensic-triage tier.'}, 'requiredAction': {'type': 'string', 'description': 'CISA\'s required-action text for the entry, verbatim. Absent under detail "summary".'}, 'notesCommentary': {'type': 'string', 'description': 'The prose segments of the notes field, verbatim with any URLs they contain; present when the notes carry prose. Absent under detail "summary".'}, 'shortDescription': {'type': 'string', 'description': 'CISA\'s one-paragraph description. Absent under detail "summary".'}, 'vulnerabilityName': {'type': 'string', 'description': 'CISA\'s short name for the vulnerability. Absent under detail "summary".'}, 'knownRansomwareCampaignUse': {'enum': ['Known', 'Unknown'], 'type': 'string', 'description': 'Whether CISA has linked the vulnerability to a ransomware campaign. Unknown means no link on record, not that none exists.'}}, 'description': 'One KEV catalog entry, or a not-in-KEV result carrying only cveId and inKev. Under cisa_check_cve_status detail "summary" an entry carries only cveId, inKev, the dates and deadline status, directive, vendor and product labels, and the ransomware and forensic-triage flags.', 'additionalProperties': False}, 'description': 'One result per requested CVE, in the order supplied.'}, 'foundCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How many of the requested CVEs are in the catalog.'}, 'summaryNote': {'type': 'string', 'description': 'Present only under detail "summary": which fields each in-KEV result omits and how to restore them.'}, 'notFoundCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How many of the requested CVEs are not in the catalog.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['advisoryId'], 'properties': {'cves': {'type': 'array', 'items': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'One CVE identifier the advisory covers, e.g. CVE-2023-3935. Case and surrounding whitespace are normalized.'}, 'description': 'Narrow the vulnerabilities section to these CVE IDs; the outline lists the ones the advisory holds. Alone, it selects the vulnerabilities section; with sections, that list must include "vulnerabilities".'}, 'sections': {'type': 'array', 'items': {'enum': ['advisory', 'summary', 'products', 'vulnerabilities', 'revisionHistory', 'references', 'acknowledgments'], 'type': 'string', 'description': 'One section name, as the outline reports it.'}, 'description': 'Sections to return. Omit for the whole document, or for its outline when the document overflows the inline budget.'}, 'advisoryId': {'type': 'string', 'pattern': '^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[A-Z]|-\\d+)?$', 'description': 'Advisory identifier, e.g. ICSA-26-260-07 or ICSMA-26-253-02, with an optional revision suffix: a single letter A-F or a numeric -N. Case, surrounding whitespace, and a trailing .json are normalized.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['found']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'kind': {'enum': ['full', 'outline'], 'type': 'string', 'description': 'full when the document is returned; outline when only the section listing is.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['mirror_not_ready', 'mirror_unavailable', 'unknown_section', 'cves_need_vulnerabilities_section', 'unknown_cve'], 'description': 'Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `mirror_unavailable`: The advisory index store cannot be opened: its location is not writable, is read-only, runs through a missing directory or a file, or holds a file that is not a SQLite database. `unknown_section`: A requested section is one this advisory does not carry. `cves_need_vulnerabilities_section`: cves is set but sections does not include "vulnerabilities", so there is nothing for cves to narrow. `unknown_cve`: A cves entry names a CVE this advisory does not cover. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'found': {'type': 'boolean', 'description': 'Whether an advisory with that ID is in the index.'}, 'summary': {'type': 'object', 'required': ['sectors'], 'properties': {'sectors': {'type': 'array', 'items': {'type': 'string', 'description': 'One canonical sector name.'}, 'description': 'Normalized sector names. Empty when the advisory carries no sector note.'}, 'sectorsRaw': {'type': 'string', 'description': 'The sector note verbatim, when present.'}, 'summaryText': {'type': 'string', 'description': 'The advisory summary or overview note.'}, 'headquarters': {'type': 'string', 'description': 'The company-headquarters-location note.'}, 'exploitability': {'type': 'string', 'description': 'The exploitability note, when present.'}, 'riskEvaluation': {'type': 'string', 'description': 'The risk-evaluation note, when present.'}, 'countriesDeployed': {'type': 'string', 'description': 'The countries/areas-deployed note.'}}, 'description': 'Narrative notes and sector classification.', 'additionalProperties': False}, 'advisory': {'type': 'object', 'required': ['advisoryId', 'title', 'series', 'status', 'csafVersion', 'published', 'revised', 'revision', 'publisherCategory', 'publisherName', 'url', 'csafUrl', 'attribution'], 'properties': {'url': {'type': 'string', 'description': 'Absolute URL of the cisa.gov web version of the advisory.'}, 'title': {'type': 'string', 'description': 'The advisory title.'}, 'series': {'enum': ['ICSA', 'ICSMA'], 'type': 'string', 'description': 'Advisory series.'}, 'status': {'type': 'string', 'description': 'CSAF tracking status, e.g. final or interim.'}, 'csafUrl': {'type': 'string', 'description': 'Absolute URL of the raw CSAF JSON document.'}, 'revised': {'type': 'string', 'description': 'Current release date, ISO 8601.'}, 'revision': {'type': 'string', 'description': 'Document revision number.'}, 'published': {'type': 'string', 'description': 'Initial release date, ISO 8601.'}, 'advisoryId': {'type': 'string', 'pattern': '^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[A-Z]|-\\d+)?$', 'description': 'The advisory identifier.'}, 'attribution': {'type': 'string', 'description': 'Who authored the text and under what terms it may be redistributed.'}, 'csafVersion': {'type': 'string', 'description': 'CSAF schema version the document declares.'}, 'publisherName': {'type': 'string', 'description': 'Publisher name as the document records it.'}, 'publisherCategory': {'type': 'string', 'description': 'coordinator for CISA-authored, other for a republished vendor advisory.'}}, 'description': 'Advisory identity, dates, and attribution. Always kept, including on a section selection.', 'additionalProperties': False}, 'guidance': {'type': 'string', 'description': 'What to do instead, present when found is false: how current the index is, and whether the advisory may be newer than it.'}, 'products': {'type': 'object', 'required': ['vendorCount', 'productCount', 'vendors', 'shownProducts'], 'properties': {'vendors': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'products'], 'properties': {'name': {'type': 'string', 'description': 'Vendor label as the advisory spells it.'}, 'products': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'versions'], 'properties': {'name': {'type': 'string', 'description': 'Product name.'}, 'family': {'type': 'string', 'description': 'Product family, when the tree names one.'}, 'versions': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'value', 'productId'], 'properties': {'kind': {'type': 'string', 'description': 'CSAF branch category this entry came from, e.g. product_version or product_version_range.'}, 'value': {'type': 'string', 'description': 'The version or version-range expression.'}, 'productId': {'type': 'string', 'description': 'The CSAFPID token vulnerability entries reference â\x80\x94 how a CVE maps to exact affected versions.'}}, 'description': 'One affected version or version range.', 'additionalProperties': False}, 'description': 'Version entries under this product.'}}, 'description': 'One product under the vendor.', 'additionalProperties': False}, 'description': 'Products under this vendor.'}}, 'description': 'One vendor and its products.', 'additionalProperties': False}, 'description': 'Vendors flattened out of the CSAF product tree.'}, 'truncated': {'type': 'boolean', 'description': 'True only on a copy stored by an older index build that capped product rows; the index re-ingests on its next start and then returns every row. Absent otherwise.'}, 'vendorCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Distinct vendors in the product tree.'}, 'productCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Flattened product entries in the whole product tree.'}, 'shownProducts': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Flattened version rows returned â\x80\x94 equal to productCount except on a truncated copy.'}}, 'description': 'Affected products and version ranges.', 'additionalProperties': False}, 'sections': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'bytes'], 'properties': {'cves': {'type': 'array', 'items': {'type': 'string', 'description': 'One CVE identifier.'}, 'description': 'On the vulnerabilities section only: the CVE IDs it holds, in document order. Pass any of them in cves to cisa_get_advisory to read just those entries.'}, 'name': {'type': 'string', 'description': 'Section identifier â\x80\x94 pass in `sections` to retrieve it'}, 'bytes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'Serialized byte size of the section'}}, 'description': 'One section this advisory carries, with its serialized byte size.', 'additionalProperties': False}, 'description': 'Outline arm â\x80\x94 the sections available, largest first, with their byte sizes and, for vulnerabilities, its CVE IDs.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'url'], 'properties': {'url': {'type': 'string', 'description': 'The reference URL.'}, 'summary': {'type': 'string', 'description': 'Reference summary, when present.'}, 'category': {'type': 'string', 'description': 'CSAF reference category, e.g. self or external.'}}, 'description': 'One document-level reference.', 'additionalProperties': False}, 'description': 'Document-level references.'}, 'outlineNotice': {'type': 'string', 'description': 'Outline arm â\x80\x94 how to call cisa_get_advisory for specific sections.'}, 'acknowledgments': {'type': 'array', 'items': {'type': 'object', 'required': ['names'], 'properties': {'names': {'type': 'array', 'items': {'type': 'string', 'description': 'One acknowledged person.'}, 'description': 'Acknowledged people.'}, 'summary': {'type': 'string', 'description': 'What the acknowledgment records.'}, 'organization': {'type': 'string', 'description': 'Acknowledged organization, when named.'}}, 'description': 'One acknowledgment entry.', 'additionalProperties': False}, 'description': 'Acknowledgment entries.'}, 'indexCheckpoint': {'type': ['string', 'null'], 'description': 'Present when found is false: the newest revision timestamp the index holds, or null if none.'}, 'revisionHistory': {'type': 'array', 'items': {'type': 'object', 'required': ['number', 'date', 'summary'], 'properties': {'date': {'type': 'string', 'description': 'Revision date, ISO 8601.'}, 'number': {'type': 'string', 'description': 'Revision number.'}, 'summary': {'type': 'string', 'description': 'What changed in this revision.'}, 'legacyVersion': {'type': 'string', 'description': 'Legacy version label, when the entry carries one.'}}, 'description': 'One revision-history entry.', 'additionalProperties': False}, 'description': 'Revision history, oldest first as published.'}, 'vulnerabilities': {'type': 'array', 'items': {'type': 'object', 'required': ['cve', 'scores', 'remediations', 'productStatus', 'notes'], 'properties': {'cve': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'The CVE identifier.'}, 'cweId': {'type': 'string', 'description': 'CWE identifier, when the entry carries one.'}, 'notes': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'text'], 'properties': {'text': {'type': 'string', 'description': 'Note text, verbatim.'}, 'title': {'type': 'string', 'description': 'Note title, when present.'}, 'category': {'type': 'string', 'description': 'CSAF note category.'}}, 'description': 'One note attached to the vulnerability.', 'additionalProperties': False}, 'description': 'Notes attached to the vulnerability. CVSS v4 appears here as prose â\x80\x94 it is never parsed into a score field.'}, 'title': {'type': 'string', 'description': 'Vulnerability title, when the entry carries one.'}, 'scores': {'type': 'array', 'items': {'type': 'object', 'required': ['version', 'baseScore', 'baseSeverity', 'severityDerived', 'vectorString', 'productIds'], 'properties': {'version': {'type': 'string', 'description': 'CVSS version of this score.'}, 'baseScore': {'type': 'number', 'description': 'CVSS base score, 0.0 through 10.0.'}, 'productIds': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products this score applies to.'}, 'baseSeverity': {'type': 'string', 'description': 'Severity band for the score.'}, 'vectorString': {'type': 'string', 'description': 'The full CVSS vector string.'}, 'severityDerived': {'type': 'boolean', 'description': 'True when the band was derived here rather than published upstream.'}}, 'description': 'One CVSS score.', 'additionalProperties': False}, 'description': 'CVSS scores. Empty on the 431 vulnerability objects that carry none.'}, 'cweName': {'type': 'string', 'description': 'CWE name, when the entry carries one.'}, 'remediations': {'type': 'array', 'items': {'type': 'object', 'required': ['category', 'details', 'productIds'], 'properties': {'url': {'type': 'string', 'description': 'Vendor link for the remediation, when present.'}, 'details': {'type': 'string', 'description': 'The remediation instructions, verbatim.'}, 'category': {'type': 'string', 'description': 'CSAF remediation category: mitigation, vendor_fix, workaround, none_available, or no_fix_planned.'}, 'productIds': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products this remediation applies to.'}, 'restartRequired': {'type': 'string', 'description': 'Restart category the remediation requires, when stated.'}}, 'description': 'One remediation entry.', 'additionalProperties': False}, 'description': 'Remediations for this vulnerability.'}, 'productStatus': {'type': 'object', 'required': ['known_affected', 'fixed', 'known_not_affected', 'recommended'], 'properties': {'fixed': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products already fixed.'}, 'recommended': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products recommended by the publisher.'}, 'known_affected': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products known to be affected.'}, 'known_not_affected': {'type': 'array', 'items': {'type': 'string', 'description': 'One CSAFPID token.'}, 'description': 'Products known not to be affected.'}}, 'description': 'Per-product status buckets, as CSAF names them.', 'additionalProperties': False}}, 'description': 'One vulnerability the advisory covers.', 'additionalProperties': False}, 'description': 'Vulnerabilities the advisory covers, with scores, remediations, and product status.'}, 'indexLastSyncedAt': {'type': ['string', 'null'], 'description': 'Present when found is false: when the index last completed a sync, ISO 8601, or null if never.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'feed': {'enum': ['advisories', 'alerts', 'ics'], 'type': 'string', 'default': 'advisories', 'description': 'Which feed to read: advisories (all.xml, ~8 days of coverage), alerts (alerts.xml, ~8 weeks), or ics (ics-advisories.xml, ~2.5 weeks).'}, 'limit': {'type': 'integer', 'default': 30, 'maximum': 30, 'minimum': 1, 'description': 'Maximum items to return. The 30 ceiling is the upstream window, not a server choice.'}, 'since': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Keep only items published on or after this date, YYYY-MM-DD. Filters within the fetched window; it cannot reach back beyond it.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['feed', 'feedUrl', 'feedTitle', 'items', 'window', 'windowCaveat']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cap': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'The limit that was applied.'}, 'feed': {'enum': ['advisories', 'alerts', 'ics'], 'type': 'string', 'description': 'The feed that was read.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['feed_unavailable'], 'description': 'Machine-readable failure mode. Declared by this tool: `feed_unavailable`: The feed fetch failed or returned a body that carried no RSS channel. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'items': {'type': 'array', 'items': {'type': 'object', 'required': ['title', 'link', 'pubDate', 'summary', 'summaryTruncated', 'guid'], 'properties': {'guid': {'type': 'string', 'description': 'The upstream guid â\x80\x94 a node path such as /node/25513, not a URL and not a permalink.'}, 'link': {'type': 'string', 'description': 'Absolute URL of the canonical page for the item.'}, 'title': {'type': 'string', 'description': 'Item title, trimmed â\x80\x94 upstream carries trailing whitespace.'}, 'pubDate': {'type': 'string', 'description': 'Publication timestamp, ISO 8601. Upstream publishes RFC 822 with a two-digit year.'}, 'summary': {'type': 'string', 'description': 'Item description with HTML stripped and entities decoded, capped at 1,200 characters.'}, 'advisoryId': {'type': 'string', 'pattern': '^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[A-Z]|-\\d+)?$', 'description': 'Present for ICS advisory items; chains straight into cisa_get_advisory.'}, 'summaryTruncated': {'type': 'boolean', 'description': 'True when the summary was capped.'}}, 'description': 'One feed item.', 'additionalProperties': False}, 'description': 'Items from the current window, newest first as published.'}, 'shown': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Items returned.'}, 'notice': {'type': 'string', 'description': 'Guidance when the since filter excluded every item.'}, 'window': {'type': 'object', 'required': ['itemCount', 'oldest', 'newest', 'upstreamWindowSize'], 'properties': {'newest': {'type': ['string', 'null'], 'description': 'Publication date of the newest item in the fetched window; null when empty.'}, 'oldest': {'type': ['string', 'null'], 'description': 'Publication date of the oldest item in the fetched window; null when empty.'}, 'itemCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Items returned after limit and since were applied.'}, 'upstreamWindowSize': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Items the upstream feed serves â\x80\x94 a fixed ceiling, not a server choice.'}}, 'description': 'What the fetched window covers.', 'additionalProperties': False}, 'feedUrl': {'type': 'string', 'description': 'The absolute feed URL this window came from.'}, 'feedTitle': {'type': 'string', 'description': 'The channel title the feed declares.'}, 'truncated': {'type': 'boolean', 'description': 'True when the limit capped the returned items.'}, 'windowCaveat': {'type': 'string', 'description': 'That the feed has no history, no pagination, and no date query.'}, 'effectiveQuery': {'type': 'string', 'description': 'The since filter as applied, and how many window items it excluded.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['cveIds'], 'properties': {'cveIds': {'type': 'array', 'items': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'One CVE identifier, e.g. CVE-2025-39964. Case and surrounding whitespace are normalized.'}, 'maxItems': 50, 'minItems': 1, 'description': "CVE identifiers to look up, up to 50 per call â\x80\x94 lower than cisa_check_cve_status's 200-CVE cap because each CVE needs its own live enrichment lookup rather than a cached batch check."}, 'assetExposure': {'enum': ['publicly_exposed', 'not_publicly_exposed', 'unknown'], 'type': 'string', 'default': 'unknown', 'description': 'Whether the affected asset is reachable by unauthenticated or untrusted entities over public networks. The one BOD 26-04 decision point CISA cannot publish. "unknown" returns both arms so the spread is visible without guessing.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['results', 'foundCount', 'notFoundCount', 'echo']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'echo': {'type': 'object', 'required': ['assetExposure', 'requested'], 'properties': {'requested': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How many CVE IDs were requested.'}, 'assetExposure': {'type': 'string', 'description': 'The asset exposure the server applied.'}}, 'description': 'The request as the server parsed it.', 'additionalProperties': False}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['enrichment_source_unavailable'], 'description': 'Machine-readable failure mode. Declared by this tool: `enrichment_source_unavailable`: Every per-CVE fetch failed with a transport or 5xx error. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Guidance when nothing was enriched, or when a decision timestamp predates KEV.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'found', 'cwes', 'inKev', 'sourceUrl'], 'properties': {'cvss': {'type': 'object', 'required': ['version', 'baseScore', 'baseSeverity', 'vectorString'], 'properties': {'version': {'type': 'string', 'description': 'CVSS version of the contributed score.'}, 'baseScore': {'type': 'number', 'description': 'CVSS base score, 0.0 through 10.0.'}, 'baseSeverity': {'type': 'string', 'description': 'Qualitative severity band as published.'}, 'vectorString': {'type': 'string', 'description': 'The full CVSS vector string.'}}, 'description': 'The CVSS score CISA contributed through its ADP container, when present.', 'additionalProperties': False}, 'cwes': {'type': 'array', 'items': {'type': 'object', 'required': ['cweId', 'description'], 'properties': {'cweId': {'type': 'string', 'pattern': '^CWE-[0-9]+$', 'description': 'CWE identifier.'}, 'description': {'type': 'string', 'description': 'CWE name as published.'}}, 'description': 'One CWE from the CISA-authored container.', 'additionalProperties': False}, 'description': 'CWEs CISA contributed. Empty when none were published.'}, 'cveId': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'The CVE identifier that was looked up.'}, 'found': {'type': 'boolean', 'description': 'Whether CISA has published SSVC decision points for this CVE.'}, 'inKev': {'type': 'boolean', 'description': "Whether the CVE is in this server's KEV catalog snapshot."}, 'bod2604': {'type': 'object', 'required': ['timelines', 'basis', 'caveat'], 'properties': {'basis': {'type': 'string', 'description': 'The decision table the timeline was resolved against.'}, 'caveat': {'type': 'string', 'description': 'What the computation is and is not. Fixed text on every result.'}, 'timelines': {'type': 'array', 'items': {'type': 'object', 'required': ['assetExposure', 'tableRow', 'timelineLabel', 'remediationTimelineDays', 'forensicTriageRequired'], 'properties': {'tableRow': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'BOD 26-04 Table 1 row number, 1 to 16.'}, 'assetExposure': {'enum': ['publicly_exposed', 'not_publicly_exposed'], 'type': 'string', 'description': 'The exposure arm this timeline applies to.'}, 'timelineLabel': {'type': 'string', 'description': "The agency timeline in the directive's own wording."}, 'forensicTriageRequired': {'type': 'boolean', 'description': 'Whether a forensic triage of the asset is also required.'}, 'remediationTimelineDays': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Calendar days allowed, or null for "Fix on system upgrade".'}}, 'description': 'One computed remediation timeline.', 'additionalProperties': False}, 'description': 'One timeline per exposure arm â\x80\x94 one when the caller stated an exposure, both when it is unknown.'}}, 'description': 'The BOD 26-04 timeline implied by the published decision points.', 'additionalProperties': False}, 'guidance': {'type': 'string', 'description': 'What to do instead, present on every result where found is false.'}, 'ssvcRole': {'type': 'string', 'description': 'The SSVC role CISA recorded, e.g. CISA Coordinator.'}, 'sourceUrl': {'type': 'string', 'description': 'The Vulnrichment record URL this result was read from.'}, 'automatable': {'type': 'string', 'description': 'The SSVC Automatable value (yes or no).'}, 'kevAssigned': {'type': 'object', 'required': ['dateAdded', 'dueDate', 'daysFromAdd', 'forensicTriage', 'directive'], 'properties': {'dueDate': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Federal remediation deadline CISA assigned.'}, 'dateAdded': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Date CISA added the CVE to the KEV catalog.'}, 'directive': {'anyOf': [{'enum': ['BOD 26-04', 'BOD 22-01'], 'type': 'string'}, {'type': 'null'}], 'description': 'The directive the KEV entry cites, or null when it cites neither.'}, 'daysFromAdd': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Calendar days from dateAdded to dueDate.'}, 'forensicTriage': {'enum': ['Yes', 'No'], 'type': 'string', 'description': 'Whether the KEV entry is in the three-day forensic-triage tier.'}}, 'description': "CISA's own assignment for this CVE, reported alongside the computation.", 'additionalProperties': False}, 'ssvcVersion': {'type': 'string', 'description': 'SSVC schema version CISA published against.'}, 'exploitation': {'type': 'string', 'description': 'The SSVC Exploitation value (none, poc, or active). Values outside that set are passed through verbatim.'}, 'ssvcTimestamp': {'type': 'string', 'description': 'When CISA published these decision points, ISO 8601.'}, 'technicalImpact': {'type': 'string', 'description': 'The SSVC Technical Impact value (partial or total).'}, 'assignmentAgrees': {'type': 'boolean', 'description': "Whether CISA's assigned deadline matches the computed timeline. Present only when the CVE is in KEV and an exposure was stated. Reported, never reconciled."}}, 'description': 'One SSVC lookup result.', 'additionalProperties': False}, 'description': 'One result per requested CVE, in the order supplied.'}, 'foundCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How many CVEs carry published SSVC decision points.'}, 'notFoundCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'How many CVEs do not.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['topic'], 'properties': {'topic': {'enum': ['directives', 'kev_fields', 'ssvc_values', 'sectors', 'advisory_id_formats', 'severity_bands', 'sources'], 'type': 'string', 'description': 'Which reference block to return: directives (BOD 26-04 Table 1 and its definitions), kev_fields, ssvc_values, sectors, advisory_id_formats, severity_bands, or sources (what this server currently holds).'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['topic', 'title', 'summary', 'entries']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'description': 'Machine-readable failure mode.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'title': {'type': 'string', 'description': 'Human-readable title for the topic.'}, 'topic': {'enum': ['directives', 'kev_fields', 'ssvc_values', 'sectors', 'advisory_id_formats', 'severity_bands', 'sources'], 'type': 'string', 'description': 'The topic that was decoded.'}, 'entries': {'type': 'array', 'items': {'type': 'object', 'required': ['key', 'label', 'description'], 'properties': {'key': {'type': 'string', 'description': 'Stable identifier for the term.'}, 'label': {'type': 'string', 'description': 'Human-readable name for the term.'}, 'values': {'type': 'array', 'items': {'type': 'string', 'description': 'One accepted value.'}, 'description': 'The value domain, when the term has a closed or enumerated one.'}, 'description': {'type': 'string', 'description': 'What the term means and how it affects a query.'}}, 'description': 'One decoded term within the topic.', 'additionalProperties': False}, 'description': 'The decoded terms for this topic.'}, 'sources': {'type': 'object', 'required': ['kev', 'csafMirror', 'vulnrichment', 'feeds'], 'properties': {'kev': {'type': 'object', 'required': ['catalogVersion', 'dateReleased', 'count', 'lastCheckedAt', 'lastModified', 'refreshCron'], 'properties': {'count': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Entry count the loaded snapshot carries; null before the first load.'}, 'refreshCron': {'type': 'string', 'description': 'Cron expression the refresh poll runs on, or off when it is disabled.'}, 'dateReleased': {'type': ['string', 'null'], 'description': 'Release timestamp the loaded snapshot carries; null before the first load.'}, 'lastModified': {'type': ['string', 'null'], 'description': 'Upstream Last-Modified of the loaded snapshot, used for the conditional poll.'}, 'lastCheckedAt': {'type': ['string', 'null'], 'description': 'When the refresh poll last reached the origin, ISO 8601; null if never.'}, 'catalogVersion': {'type': ['string', 'null'], 'description': 'Catalog version of the loaded snapshot; null before the first load lands.'}}, 'description': 'The in-memory KEV catalog snapshot.', 'additionalProperties': False}, 'feeds': {'type': 'object', 'required': ['windowItems', 'cached'], 'properties': {'cached': {'type': 'array', 'items': {'type': 'object', 'required': ['feed', 'oldest', 'newest', 'fetchedAt'], 'properties': {'feed': {'enum': ['advisories', 'alerts', 'ics'], 'type': 'string', 'description': 'Which feed this cached window belongs to.'}, 'newest': {'type': ['string', 'null'], 'description': 'Publication date of the newest item in the cached window.'}, 'oldest': {'type': ['string', 'null'], 'description': 'Publication date of the oldest item in the cached window.'}, 'fetchedAt': {'type': 'string', 'description': 'When this window was fetched, ISO 8601.'}}, 'description': 'One cached feed window.', 'additionalProperties': False}, 'description': 'Feed windows currently held in memory; empty before any feed is read.'}, 'windowItems': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Items each feed serves â\x80\x94 a fixed upstream ceiling, not a server choice.'}}, 'description': 'The RSS feed tier.', 'additionalProperties': False}, 'csafMirror': {'type': 'object', 'required': ['ready', 'documentCount', 'checkpoint', 'syncStatus', 'lastCompletedAt'], 'properties': {'ready': {'type': 'boolean', 'description': 'True once a full sync has ever completed; stays true during a refresh.'}, 'checkpoint': {'type': ['string', 'null'], 'description': 'Durable high-water mark â\x80\x94 the newest current_release_date ingested.'}, 'syncStatus': {'type': 'string', 'description': 'Lifecycle state: pending, in_progress, complete, error, or unavailable.'}, 'documentCount': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Advisories held in the index; null before the first sync completes.'}, 'lastCompletedAt': {'type': ['string', 'null'], 'description': 'When a full sync last completed, ISO 8601; null if never.'}, 'unavailableReason': {'enum': ['not_writable', 'read_only', 'missing_directory', 'not_a_directory', 'not_a_database'], 'type': 'string', 'description': 'Present only when the index cannot be opened: its location is not writable, is read-only, has a missing directory, runs through a file, or holds a file that is not a SQLite database. Fixed by CISA_CSAF_MIRROR_PATH, not by waiting.'}}, 'description': 'The local ICS advisory index.', 'additionalProperties': False}, 'vulnrichment': {'type': 'object', 'required': ['mode', 'cacheTtlSeconds'], 'properties': {'mode': {'type': 'string', 'const': 'on_demand', 'description': 'Access mode â\x80\x94 fetched per CVE on demand; the repository is not mirrored.'}, 'cacheTtlSeconds': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'TTL for a cached record; negative results use one sixth of it.'}}, 'description': 'The per-CVE SSVC enrichment tier.', 'additionalProperties': False}}, 'description': 'Topic sources only â\x80\x94 what this server currently holds, read from in-process state.', 'additionalProperties': False}, 'summary': {'type': 'string', 'description': 'What this topic covers and when to reach for it.'}, 'supersedes': {'type': 'array', 'items': {'type': 'object', 'required': ['directive', 'issued', 'note'], 'properties': {'note': {'type': 'string', 'description': 'What the superseded directive covered.'}, 'issued': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Issue date, YYYY-MM-DD.'}, 'directive': {'type': 'string', 'description': 'The superseded directive identifier.'}}, 'description': 'One directive that BOD 26-04 supersedes and revokes.', 'additionalProperties': False}, 'description': 'Topic directives only â\x80\x94 the directives BOD 26-04 supersedes and revokes.'}, 'definitions': {'type': 'array', 'items': {'type': 'object', 'required': ['term', 'definition'], 'properties': {'term': {'type': 'string', 'description': 'The defined term.'}, 'definition': {'type': 'string', 'description': "The directive's own definition of the term."}}, 'description': 'One supporting definition from the directive text.', 'additionalProperties': False}, 'description': 'Topic directives only â\x80\x94 supporting definitions from the directive text.'}, 'timelineTable': {'type': 'array', 'items': {'type': 'object', 'required': ['row', 'publiclyExposed', 'inKev', 'automatable', 'technicalImpact', 'timelineLabel', 'remediationTimelineDays', 'forensicTriageRequired'], 'properties': {'row': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Table 1 row number, 1 through 16.'}, 'inKev': {'type': 'boolean', 'description': 'Whether the CVE is in the CISA KEV catalog.'}, 'automatable': {'type': 'boolean', 'description': 'The SSVC Automatable decision point for this row.'}, 'timelineLabel': {'type': 'string', 'description': "The agency timeline in the directive's own wording."}, 'publiclyExposed': {'type': 'boolean', 'description': 'Whether the asset is reachable by unauthenticated or untrusted entities.'}, 'technicalImpact': {'enum': ['partial', 'total'], 'type': 'string', 'description': 'The SSVC Technical Impact decision point for this row.'}, 'forensicTriageRequired': {'type': 'boolean', 'description': 'Whether the row additionally requires a forensic triage of the asset.'}, 'remediationTimelineDays': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'Calendar days allowed, or null for the "Fix on system upgrade" rows.'}}, 'description': 'One row of BOD 26-04 Appendix A, Table 1.', 'additionalProperties': False}, 'description': 'Topic directives only â\x80\x94 all sixteen rows of BOD 26-04 Appendix A, Table 1.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'q': {'type': 'string', 'minLength': 2, 'description': 'Full-text search over advisory titles, vendor names, and product names. Tokens are AND-combined; FTS5 operators in the input are neutralized rather than honored, and a token with no letter or digit is ignored. Needs at least one word or number.'}, 'cve': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'Exact CVE membership, e.g. CVE-2021-44228. Case and surrounding whitespace are normalized.'}, 'cwe': {'type': 'string', 'pattern': '^CWE-[0-9]+$', 'description': 'Exact CWE identifier, e.g. CWE-787, matched against every vulnerability entry in the advisory. Case and surrounding whitespace are normalized. A parent class does not match its children.'}, 'inKev': {'type': 'boolean', 'description': 'true selects advisories covering at least one CVE in the CISA Known Exploited Vulnerabilities catalog; false selects advisories covering none. Checked against every CVE an advisory covers, not only the twenty listed per result.'}, 'limit': {'type': 'integer', 'default': 20, 'maximum': 50, 'minimum': 1, 'description': 'Maximum advisories per page.'}, 'order': {'enum': ['asc', 'desc'], 'type': 'string', 'default': 'desc', 'description': 'Sort direction. Under relevance, desc means most relevant first.'}, 'cursor': {'type': 'string', 'description': 'Opaque pagination cursor from a previous call. Omit for the first page.'}, 'sector': {'enum': ['Chemical', 'Commercial Facilities', 'Communications', 'Critical Manufacturing', 'Dams', 'Defense Industrial Base', 'Emergency Services', 'Energy', 'Financial Services', 'Food and Agriculture', 'Government Facilities', 'Healthcare and Public Health', 'Information Technology', 'Nuclear Reactors, Materials, and Waste', 'Transportation Systems', 'Water and Wastewater Systems', 'Multiple'], 'type': 'string', 'description': 'Critical-infrastructure sector, matched against the normalized sector set. Multiple is the sentinel the corpus uses for an advisory affecting many sectors.'}, 'series': {'enum': ['ICSA', 'ICSMA'], 'type': 'string', 'description': 'Advisory series: ICSA industrial control system advisories, or ICSMA medical-device advisories, a small minority of the corpus.'}, 'sortBy': {'enum': ['relevance', 'published', 'revised', 'maxCvss'], 'type': 'string', 'default': 'revised', 'description': 'Field to sort by. relevance requires q and ranks by FTS5 bm25.'}, 'vendor': {'type': 'string', 'minLength': 2, 'description': 'Case-insensitive substring of a vendor label, matched literally â\x80\x94 % and _ are ordinary characters. Vendor names are unnormalized upstream â\x80\x94 the same company appears under several spellings â\x80\x94 so this is substring, not exact.'}, 'cvssMax': {'type': 'number', 'maximum': 10, 'minimum': 0, 'description': "Maximum value of the advisory's maximum CVSS base score, inclusive."}, 'cvssMin': {'type': 'number', 'maximum': 10, 'minimum': 0, 'description': "Minimum value of the advisory's maximum CVSS base score, inclusive."}, 'product': {'type': 'string', 'minLength': 2, 'description': 'Case-insensitive substring of a product name, matched literally â\x80\x94 % and _ are ordinary characters.'}, 'severity': {'enum': ['NONE', 'LOW', 'MEDIUM', 'HIGH', 'CRITICAL'], 'type': 'string', 'description': "Severity band of the advisory's maximum CVSS score."}, 'publisher': {'enum': ['coordinator', 'other'], 'type': 'string', 'description': 'coordinator selects CISA-authored advisories; other selects vendor advisories CISA republished, over a quarter of the corpus.'}, 'revisedTo': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Latest current release date, inclusive, YYYY-MM-DD.'}, 'publishedTo': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Latest initial release date, inclusive, YYYY-MM-DD.'}, 'revisedFrom': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Earliest current release date, inclusive, YYYY-MM-DD.'}, 'publishedFrom': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Earliest initial release date, inclusive, YYYY-MM-DD.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['results', 'hasMore', 'totalCount', 'appliedFilters', 'mirror']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cap': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'The page limit that was applied.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['mirror_not_ready', 'mirror_unavailable', 'invalid_cvss_range', 'invalid_date_range', 'relevance_sort_without_query', 'empty_search_text', 'catalog_unavailable'], 'description': 'Machine-readable failure mode. Declared by this tool: `mirror_not_ready`: The advisory index has never completed a full sync. `mirror_unavailable`: The advisory index store cannot be opened: its location is not writable, is read-only, runs through a missing directory or a file, or holds a file that is not a SQLite database. `invalid_cvss_range`: cvssMin exceeds cvssMax. `invalid_date_range`: A From bound is later than its matching To bound. `relevance_sort_without_query`: sortBy is relevance but no q was supplied, so there is no bm25 rank to sort by. `empty_search_text`: q contains no word or number once quotes and punctuation are removed, so there is nothing to search for. `catalog_unavailable`: inKev is set, no KEV catalog snapshot is held, and the fetch from cisa.gov failed. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'shown': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Advisories returned on this page.'}, 'cursor': {'type': 'string', 'description': 'Opaque cursor for the next page. Absent when this is the last page.'}, 'mirror': {'type': 'object', 'required': ['documentCount', 'checkpoint', 'lastRefreshedAt'], 'properties': {'checkpoint': {'type': 'string', 'description': 'Newest current_release_date ingested, or "none".'}, 'documentCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Advisories held in the local index.'}, 'lastRefreshedAt': {'type': 'string', 'description': 'When a full sync last completed, or "never".'}}, 'description': 'Which index state answered this call.', 'additionalProperties': False}, 'notice': {'type': 'string', 'description': 'Guidance when nothing matched â\x80\x94 the filter that matches no advisory on its own and what dropping it restores, or the filters whose removal restores results and how many â\x80\x94 when a page was capped, when KEV membership was not evaluated, or when a cwe result may be incomplete.'}, 'hasMore': {'type': 'boolean', 'description': 'Whether more matches exist beyond this page.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['advisoryId', 'title', 'series', 'vendors', 'vendorCount', 'productCount', 'cves', 'cveCount', 'sectors', 'published', 'revised', 'revision', 'publisherCategory', 'url', 'csafUrl', 'attribution'], 'properties': {'url': {'type': 'string', 'description': 'Absolute URL of the cisa.gov web version of the advisory.'}, 'cves': {'type': 'array', 'items': {'type': 'string', 'description': 'One CVE identifier.'}, 'description': 'Up to twenty CVEs; cveCount carries the full count.'}, 'title': {'type': 'string', 'description': 'The advisory title.'}, 'series': {'enum': ['ICSA', 'ICSMA'], 'type': 'string', 'description': 'Advisory series.'}, 'csafUrl': {'type': 'string', 'description': 'Absolute URL of the raw CSAF JSON document.'}, 'kevCves': {'type': 'array', 'items': {'type': 'string', 'description': 'One CVE identifier.'}, 'description': 'Every CVE this advisory covers that is in the KEV catalog, drawn from its full CVE list rather than the twenty in cves. Empty when none is; absent when KEV membership could not be evaluated.'}, 'maxCvss': {'type': 'object', 'required': ['score', 'severity', 'version', 'severityDerived'], 'properties': {'score': {'type': 'number', 'description': 'Highest CVSS base score in the advisory.'}, 'version': {'type': 'string', 'description': 'CVSS version the highest score was published under.'}, 'severity': {'enum': ['NONE', 'LOW', 'MEDIUM', 'HIGH', 'CRITICAL'], 'type': 'string', 'description': 'Severity band for that score.'}, 'severityDerived': {'type': 'boolean', 'description': 'True when the band was derived from a CVSS v2 score rather than published upstream.'}}, 'description': 'Highest CVSS score across the advisory. Absent when the advisory carries no CVSS score.', 'additionalProperties': False}, 'revised': {'type': 'string', 'description': 'Current release date, ISO 8601.'}, 'sectors': {'type': 'array', 'items': {'type': 'string', 'description': 'One canonical sector name.'}, 'description': 'Normalized sector names. Empty when the advisory carries no sector note.'}, 'vendors': {'type': 'array', 'items': {'type': 'string', 'description': 'One vendor label.'}, 'description': 'Up to ten vendor labels; vendorCount carries the full count.'}, 'cveCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Distinct CVEs the advisory covers.'}, 'revision': {'type': 'string', 'description': 'Document revision number.'}, 'published': {'type': 'string', 'description': 'Initial release date, ISO 8601.'}, 'advisoryId': {'type': 'string', 'pattern': '^ICS(A|MA)-\\d{2}-\\d{3}-\\d{2}(?:[A-Z]|-\\d+)?$', 'description': 'The advisory identifier, e.g. ICSA-26-260-07. Pass it to cisa_get_advisory.'}, 'sectorsRaw': {'type': 'string', 'description': 'The sector note verbatim, when the advisory carries one.'}, 'attribution': {'type': 'string', 'description': 'Who authored the text and under what terms it may be redistributed.'}, 'vendorCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Distinct vendors named in the product tree.'}, 'productCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Flattened product entries in the product tree.'}, 'publisherCategory': {'type': 'string', 'description': 'coordinator for CISA-authored, other for a republished vendor advisory.'}}, 'description': 'One matching advisory.', 'additionalProperties': False}, 'description': 'Matching advisories for this page.'}, 'truncated': {'type': 'boolean', 'description': 'True when the page limit capped this result.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Total matches before paging.'}, 'cvssCoverage': {'type': 'string', 'description': 'Disclosure of derived-band and no-score coverage under a score filter.'}, 'appliedFilters': {'type': 'object', 'description': 'The filters the server actually applied.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string', 'description': 'The filter value as the server parsed it.'}}, 'sectorCoverage': {'type': 'string', 'description': 'Disclosure of how many advisories a sector filter can never match.'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cwe': {'type': 'string', 'pattern': '^CWE-[0-9]+$', 'description': 'Exact CWE identifier, e.g. CWE-362. Case and surrounding whitespace are normalized. Entries with no CWEs never match.'}, 'limit': {'type': 'integer', 'default': 25, 'maximum': 100, 'minimum': 1, 'description': 'Maximum entries per page.'}, 'order': {'enum': ['asc', 'desc'], 'type': 'string', 'default': 'desc', 'description': 'Sort direction.'}, 'cursor': {'type': 'string', 'description': 'Opaque pagination cursor from a previous call. Omit for the first page.'}, 'sortBy': {'enum': ['dueDate', 'dateAdded'], 'type': 'string', 'default': 'dateAdded', 'description': 'Field to sort by.'}, 'overdue': {'type': 'boolean', 'description': 'True selects entries whose due date is strictly before the echoed asOf date.'}, 'product': {'type': 'string', 'minLength': 2, 'description': "Case-insensitive substring of CISA's own product label."}, 'dueAfter': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Earliest due date, inclusive, YYYY-MM-DD.'}, 'directive': {'enum': ['BOD 26-04', 'BOD 22-01', 'none'], 'type': 'string', 'description': 'Which directive the entry cites. "none" selects the entries citing neither.'}, 'dueBefore': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Latest due date, inclusive, YYYY-MM-DD.'}, 'ransomware': {'type': 'boolean', 'description': 'True selects entries CISA has linked to ransomware campaigns.'}, 'cveIdPrefix': {'type': 'string', 'pattern': '^CVE-[0-9]{4}$', 'description': 'Year scope for the CVE ID, e.g. CVE-2026. Case and surrounding whitespace are normalized.'}, 'dateAddedTo': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Latest date added, inclusive, YYYY-MM-DD.'}, 'nameContains': {'type': 'string', 'minLength': 2, 'description': 'Strict token match over the vulnerability name and short description: every token must appear. Matching folds case and accents, spells letters such as Ã\x9f, æ, ø, þ, and Å\x82 as ss, ae, o, th, and l, and keeps only the letters a-z and the digits 0-9; a word carrying any other letter or digit, such as one in another script, loses those characters and the response names it, and a value left with none of them is rejected. No fuzzy fallback.'}, 'dateAddedFrom': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Earliest date added, inclusive, YYYY-MM-DD.'}, 'vendorProject': {'type': 'string', 'minLength': 2, 'description': "Case-insensitive substring of CISA's own vendor label."}, 'forensicTriage': {'type': 'boolean', 'description': 'True selects the BOD 26-04 three-day forensic-triage tier.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['results', 'hasMore', 'totalCount', 'catalog', 'asOf', 'appliedFilters']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'cap': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'The page limit that was applied.'}, 'asOf': {'type': 'string', 'description': 'The UTC date overdue and daysUntilDue were computed against, YYYY-MM-DD.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['catalog_unavailable', 'invalid_date_range', 'empty_search_text'], 'description': 'Machine-readable failure mode. Declared by this tool: `catalog_unavailable`: No KEV catalog snapshot is held and the fetch from cisa.gov failed. `invalid_date_range`: A From bound is later than its matching To bound. `empty_search_text`: nameContains holds no letter a-z or digit 0-9 once case, accents, and letters such as Ã\x9f and ø are folded and punctuation is removed, so there is nothing to search for. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'shown': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Entries returned on this page.'}, 'cursor': {'type': 'string', 'description': 'Opaque cursor for the next page. Absent when this is the last page.'}, 'notice': {'type': 'string', 'description': 'Guidance when nothing matched, when a page was capped, or when nameContains dropped characters it cannot match.'}, 'catalog': {'type': 'object', 'required': ['catalogVersion', 'dateReleased', 'count', 'fetchedAt'], 'properties': {'count': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Entries in the loaded snapshot.'}, 'fetchedAt': {'type': 'string', 'description': 'When this server fetched the snapshot, ISO 8601.'}, 'dateReleased': {'type': 'string', 'description': 'Release timestamp the snapshot carries.'}, 'catalogVersion': {'type': 'string', 'description': 'Version string of the loaded catalog snapshot.'}}, 'description': 'Which catalog snapshot answered this call.', 'additionalProperties': False}, 'hasMore': {'type': 'boolean', 'description': 'Whether more matches exist beyond this page.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['cveId', 'inKev'], 'properties': {'cwes': {'type': 'array', 'items': {'type': 'string', 'pattern': '^CWE-[0-9]+$', 'description': 'One CWE identifier.'}, 'description': 'Associated CWEs. Empty on some entries, and a CWE filter excludes those. Absent under detail "summary".'}, 'cveId': {'type': 'string', 'pattern': '^CVE-[0-9]{4}-[0-9]{4,19}$', 'description': 'The CVE identifier that was looked up.'}, 'inKev': {'type': 'boolean', 'description': 'Whether the CVE is in the KEV catalog. False is a normal result, not an error.'}, 'kevUrl': {'type': 'string', 'description': 'Absolute URL of the KEV catalog page for this CVE. Absent under detail "summary".'}, 'dueDate': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Federal remediation deadline CISA assigned, YYYY-MM-DD.'}, 'overdue': {'type': 'boolean', 'description': 'True when the due date is strictly before the echoed asOf date.'}, 'product': {'type': 'string', 'description': "CISA's own product label â\x80\x94 free text, not a CPE."}, 'dateAdded': {'type': 'string', 'pattern': '^\\d{4}-\\d{2}-\\d{2}$', 'description': 'Date CISA added the entry to the catalog, YYYY-MM-DD.'}, 'directive': {'anyOf': [{'enum': ['BOD 26-04', 'BOD 22-01'], 'type': 'string'}, {'type': 'null'}], 'description': 'The binding operational directive the entry cites, or null when it cites neither â\x80\x94 most entries name none, and none is never inferred from age.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['kind', 'url'], 'properties': {'url': {'type': 'string', 'description': 'Absolute reference URL, verbatim from the notes field.'}, 'kind': {'enum': ['nvd', 'cisa', 'bod_guidance', 'forensic_triage', 'vendor', 'other'], 'type': 'string', 'description': 'What the link points at: the NVD detail record, a cisa.gov page, BOD 26-04 guidance, the forensic-triage requirements, a vendor page, or an unclassifiable URL.'}, 'label': {'type': 'string', 'description': "CISA's own label for the segment, when the notes entry carried one."}}, 'description': 'One reference URL parsed from the entry notes.', 'additionalProperties': False}, 'description': 'Every reference URL in the notes field, in notes order, each classified by kind. Absent under detail "summary".'}, 'daysUntilDue': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Whole days from the echoed asOf date to the due date; negative once overdue.'}, 'vendorProject': {'type': 'string', 'description': "CISA's own vendor label â\x80\x94 free text, not a CPE vendor component."}, 'forensicTriage': {'enum': ['Yes', 'No'], 'type': 'string', 'description': 'Whether the entry falls in the BOD 26-04 three-day forensic-triage tier.'}, 'requiredAction': {'type': 'string', 'description': 'CISA\'s required-action text for the entry, verbatim. Absent under detail "summary".'}, 'notesCommentary': {'type': 'string', 'description': 'The prose segments of the notes field, verbatim with any URLs they contain; present when the notes carry prose. Absent under detail "summary".'}, 'shortDescription': {'type': 'string', 'description': 'CISA\'s one-paragraph description. Absent under detail "summary".'}, 'vulnerabilityName': {'type': 'string', 'description': 'CISA\'s short name for the vulnerability. Absent under detail "summary".'}, 'knownRansomwareCampaignUse': {'enum': ['Known', 'Unknown'], 'type': 'string', 'description': 'Whether CISA has linked the vulnerability to a ransomware campaign. Unknown means no link on record, not that none exists.'}}, 'description': 'One KEV catalog entry, or a not-in-KEV result carrying only cveId and inKev. Under cisa_check_cve_status detail "summary" an entry carries only cveId, inKev, the dates and deadline status, directive, vendor and product labels, and the ransomware and forensic-triage flags.', 'additionalProperties': False}, 'description': 'Matching KEV entries for this page.'}, 'truncated': {'type': 'boolean', 'description': 'True when the page limit capped this result.'}, 'totalCount': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'Total matches before paging.'}, 'appliedFilters': {'type': 'object', 'description': 'The filters the server actually applied, as it parsed them.', 'propertyNames': {'type': 'string'}, 'additionalProperties': {'type': 'string', 'description': 'The filter value as the server parsed it.'}}, 'snapshotCaveat': {'type': 'string', 'description': 'Disclosure that additions are queryable but revisions are not detectable.'}}, 'additionalProperties': False}
最近のツール変更
類似のMCPサーバー
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…