ZEN SecDB

ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.

Sollte ich dies verwenden

Qualität und Sicherheit

B
Qualität der Beschreibung
98%
Vollständigkeit des Schemas
86%
Qualität der Benennung
80%
Risiko der Vergiftung
60%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (4)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool 'sightings_search' description contains placeholder textin sightings_search
  • LOWTool description contains negative instruction about its own usein feed_report
  • INFOTool description contains placeholder or incomplete textin sightings_search

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~7,103Tokens (Tool-Definitionen)
~2.5 KBTypische Antwortgröße
Erhebliche Auswirkung auf die Aufmerksamkeit (5.55% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "zen-secdb": {
      "url": "https://secdb.nttzen.cloud/mcp"
    }
  }
}

Remote-Endpunkte

https://secdb.nttzen.cloud/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (11)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢epss_timeseries(cve_id)

Get the historical EPSS time series for a specific CVE. ## What this tool does Returns the historical EPSS score, percentile, and model version available for a CVE across time, ordered by date. Useful for analyzing how exploitability likelihood has evolved over time. ## When to use this tool Use this tool when the user asks about: - EPSS trend over time - how exploitability probability changed - whether EPSS spiked or dropped - historical comparison of risk If the user only wants the current EPSS score, use `vulnerability_score` instead. ## Inputs - **cve_id**: valid CVE identifier (`CVE-YYYY-NNNNN`). ## Outputs - **series**: array of objects, each containing: - `date`: measurement date in ISO format - `score`: EPSS score - `percentile`: EPSS percentile - `model`: EPSS model version ## LLM usage guidelines - Never guess EPSS values-use this tool for all EPSS time-series questions. - If `cve_id` is malformed or incomplete, ask the user to correct it before calling. - If the user mentions multiple CVEs, call the tool once per CVE as needed. - If no historical data is available, return an empty series and state that no EPSS history was found.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "cve_id": {
      "description": "CVE identification (CVE-YYYY-NNNNN)",
      "type": "string"
    }
  },
  "required": [
    "cve_id"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "series": {
      "items": {
        "properties": {
          "date": {
            "description": "Date (YYYY-MM-DD)",
            "type": "string"
          },
          "model": {
            "description": "Model version",
            "type": "string"
          },
          "percentile": {
            "description": "Percentile (%)",
            "type": "string"
          },
          "score": {
            "description": "Score (%)",
            "type": "string"
          }
        },
        "type": "object"
      },
      "type": "array"
    }
  }
}
🟢linux_audit(os, packages, version)

Perform a Linux package vulnerability audit using SecDB. ## What this tool does Analyzes the installed packages of a Linux system-identified by OS and OS version-and returns vulnerability information plus a Markdown summary. The audit results are based exclusively on the package list provided by the user. ## When to use this tool Use this tool when the user wants to determine: - whether installed packages contain known vulnerabilities - whether a host, VM, container, or base image is affected by security advisories - which packages require patching or upgrading If the user does not know the valid values for `os` or `version`, first call the `linux_os` tool to retrieve the exact supported combinations. ## Inputs - **os**: Linux distribution identifier supported by SecDB (use `linux_os` to obtain allowed values). - **version**: OS version or codename corresponding to the selected distribution. - **packages**: list of installed packages, **one per line**, generated using the appropriate system command: ### For RPM-based distributions (RHEL, CentOS, Rocky, Alma, SUSE) rpm -qa --qf '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' ### For DEB-based distributions (Ubuntu, Debian) dpkg-query -W -f='${Package} ${Version} ${Architecture}\n' ### For Alpine Linux apk list -I The raw output of these commands can be passed directly as the `packages` input (one package per line). ... python3 3.12.3-0ubuntu2.1 amd64 systemd 255.4-1ubuntu8.10 amd64 tmux 3.4-1ubuntu0.1 amd64 ... ## Outputs - **report**: structured objects describing the advisories affecting the audited packages. - **summary**: Markdown summary including total vulnerabilities, severity breakdown, and key findings. ## LLM usage guidelines - Never guess whether a package is vulnerable-always call this tool for Linux audits. - If `os` or `version` is unclear or missing, call `linux_os` and ask the user to choose a valid combination. - Normalize the package list to “one entry per line” if the user provides unstructured output. - The `summary` is already Markdown and can be shown directly. - Use `report` when deeper technical analysis is required.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "os": {
      "description": "Linux distribution identifier supported by SecDB (use `linux_os` to obtain allowed values)",
      "type": "string"
    },
    "packages": {
      "description": "list of installed packages, **one per line**, generated using the appropriate system command",
      "type": "string"
    },
    "version": {
      "description": "OS version or codename corresponding to the selected distribution",
      "type": "string"
    }
  },
  "required": [
    "os",
    "version",
    "packages"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "report": {
      "items": {
        "description": "structured objects describing the advisories affecting the audited packages",
        "type": "object"
      },
      "type": "array"
    },
    "summary": {
      "description": "Markdown summary including total vulnerabilities, severity breakdown, and key findings",
      "type": "string"
    }
  }
}
🟢linux_os

List supported Linux operating systems and their corresponding versions for use with the `linux_audit` tool. ## What this tool does Returns an array of supported OS/version pairs, each in the form: {"os":"name", "versions":["version or codename"]} This allows the LLM and the user to know exactly which inputs are valid for the `linux_audit` tool. ## When to use this tool Use this tool when: - the user does not know which OS names or versions are supported - the user provides unclear or ambiguous OS information - you need to validate `os`/`version` before performing a Linux audit This tool should typically be called **before `linux_audit`** whenever parameters are uncertain. ## Inputs This tool does not require any input. ## Outputs Returns an array of objects: - **os**: supported Linux distribution identifier - **versions**: corresponding list of supported release or codename Example: [ {"os": "ubuntu", "versions": ["noble","focal"]}, {"os": "debian", "versions": ["bookworm","sid"]}, {"os": "redhat", "version": ["redhat-9.0"]} ] ## LLM usage guidelines - Use this tool to validate or suggest correct OS/version combinations before calling `linux_audit`. - If the user provides invalid or misspelled OS names, retrieve the official list here and ask them to select one. - Do not guess operating system identifiers-always rely on this tool to confirm correctness.

Eingabe-Schema

{
  "type": "object",
  "required": []
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "supported": {
      "items": {
        "properties": {
          "os": {
            "description": "OS",
            "type": "string"
          },
          "versions": {
            "items": {
              "description": "Version",
              "type": "string"
            },
            "type": "array"
          }
        },
        "type": "object"
      },
      "type": "array"
    }
  }
}
🟢sightings_search(category, cve_id, query, status)

Search real-world vulnerability sightings in SecDB. ## What this tool does Retrieves information about where and how a vulnerability appears in the real world, including: - Exploit-DB, Metasploit modules, PoCs - Scanner plugins (Nessus, OpenVAS/Greenbone) - Vendor advisories - Social/media references (Reddit, Mastodon, Bluesky) - MISP threat-intel sightings ## When to use this tool Use this tool when the user asks: - "Is this CVE exploited in the wild?" - "Is there a PoC or exploit available?" - "Does Nessus or OpenVAS have a plugin for this CVE?" - "Is this vulnerability being discussed online?" - "Show me all advisories/exploits for this CVE/product." ## Inputs Any of the following may be used: - **cve_id**: search by specific CVE - **query**: full-text search (name, product, advisory ID, exploit reference, etc.) - **category**: filter sightings by type (e.g., `exploit`, `nasl`, `advisory`, `scanner`, `poc`, `social`, `misp`) - **status**: filter by sighting state (`exploited`, `mitigated`, `seen`, `confirmed`, etc.) ## Outputs Returns an array of sightings, typically containing: - `cve_id` - `status` - `category` - `reference` - `details` (object with additional structured data) ## LLM usage guidelines - Use `cve_id` when the question targets a specific vulnerability. - Use `query` for broad or exploratory searches. - Only use valid enum values for `category` and `status`. - Use this tool instead of assuming exploitation, PoCs, or plugin availability.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "category": {
      "description": "Sighting category (scanner, exploit, advisory, nasl, etc.)",
      "enum": [
        "advisory",
        "nasl",
        "exploit",
        "misp",
        "scanner",
        "poc",
        "social"
      ],
      "type": "string"
    },
    "cve_id": {
      "description": "CVE identification (CVE-YYYY-NNNN)",
      "type": "string"
    },
    "query": {
      "description": "Full-text-search for vulnerability name, CVE ID or Advisory ID, categories, etc.",
      "type": "string"
    },
    "status": {
      "description": "Sighting status",
      "enum": [
        "seen",
        "confirmed",
        "exploited",
        "patched",
        "not-exploited",
        "not-confirmed",
        "not-patched",
        "exploitable",
        "mentioned",
        "mitigated"
      ],
      "type": "string"
    }
  },
  "required": []
}
🟢ssvc_calculator(cve_id, mission_prevalence, public_well_being_impact)

Compute CISA SSVC (Stakeholder-Specific Vulnerability Categorization) for a CVE. ## What this tool does Calculates the SSVC decision (Track, Track*, Attend, Act) using: - exploitation status - technical impact - automatable exploitation - mission prevalence (user-provided) - public well-being impact (user-provided) This reflects CISA's official SSVC prioritization model. ## When to use this tool Use this tool when the user asks about: - how urgently a CVE should be remediated - CISA SSVC priority or risk category - a structured decision model for remediation ## Inputs - **cve_id**: the vulnerability to evaluate (`CVE-YYYY-NNNNN`) - **mission_prevalence**: `M`, `S`, or `E` (must be provided by the user) - **public_well_being_impact**: `M`, `A`, or `I` (must be provided by the user) ## Outputs - `decision`: one of **Track**, **Track\***, **Attend**, **Act** - `exploitation` - `technical_impact` - `automatable` - `mission_prevalence` - `public_well_being_impact` - `mission_and_well_being_impact_value` - `vector_string` - `summary`: Markdown explanation of the outcome ## LLM usage guidelines - Always ask the user for **mission_prevalence** (M/S/E) and **public_well_being_impact** (M/A/I) before calling. - Never guess these values—SSVC depends on user context. - Use the `summary` to explain clearly why the decision was returned. - Combine with `vulnerability_score` or `sightings_search` if the user needs additional context.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "cve_id": {
      "description": "CVE ID",
      "type": "string"
    },
    "mission_prevalence": {
      "description": "# Mission Prevalence\n\nA mission essential function (MEF) is a function directly related to\naccomplishing the organization's mission as set forth in its statutory or\nexecutive charter. Identifying MEFs is part of business continuity planning\nor crisis planning. In contrast to non-essential functions, an organization\nmust perform a [MEF] during a disruption to normal operations. The mission\nis the reason an organization exists, and MEFs are how that mission is\nrealized. Non- essential functions support the smooth delivery or success\nof MEFs rather than directly supporting the mission.\n\n## Possible values\n\n- \"M\" or \"Minimal\"\n\nNeither support nor essential apply. The vulnerable component may be used\nwithin the entities, but it is not used as a mission-essential component,\nnor does it provide impactful support to mission-essential functions.\n\n- \"S\" or \"Support\"\n\nThe vulnerable component only supports MEFs for two or more entities.\n\n- \"E\" or \"Essential\"\n\nThe vulnerable component directly provides capabilities that constitute at\nleast one MEF for at least one entity; component failure may (but does not\nnecessarily) lead to overall mission failure.\n\n## Instructions for LLM\n\nAsk the user for the \"Mission Prevalence\" value before calling the tool.\n",
      "type": "string"
    },
    "public_well_being_impact": {
      "description": "# Public Well-being Impact\n\n## Possible values\n\n- \"M\" or \"Minimal\"\n\n**Type of Harm -> All**, The effect is below the threshold for all aspects\ndescribed in material.\n\n- \"A\" or \"Material\"\n\n**Type of Harm -> Physical harm**, Does one or more of the following:\n\n- Causes physical distress or injury to system users.\n- Introduces occupational safety hazards.\n- Reduces and/or results in failure of cyber-physical system safety margins.\n\n**Type of Harm -> Environment**, Major externalities (property damage,\nenvironmental damage, etc.) are imposed on other parties.\n\n**Type of Harm -> Financial**, Financial losses likely lead to bankruptcy of\nmultiple persons.\n\n**Type of Harm -> Psychological**, Widespread emotional or psychological harm,\nsufficient to necessitate counseling or therapy, impact populations of people.\n\n- \"I\" or \"Irreversible\"\n\n**Type of Harm -> Physical harm**, One or both of the following are true:\n\n- Multiple fatalities are likely.\n- The cyber-physical system, of which the vulnerable component is a part, isl\nikely lost or destroyed.\n\n**Type of Harm -> Environment**, Extreme or serious externalities (immediate\npublic health threat, environmental damage leading to small ecosystem collapse,\netc.) are imposed on other parties.\n\n**Type of Harm -> Financial**, Social systems (elections, financial grid, etc.)\nsupported by the software are destabilized and potentially collapse.\n\n**Type of Harm -> Psychological\tN/A\n\n\n## Instructions for LLM\n\nAsk the user for the \"Public Well-being Impact\" value before calling the tool.\n",
      "type": "string"
    }
  },
  "required": [
    "cve_id",
    "mission_prevalence",
    "public_well_being_impact"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "automatable": {
      "description": "Automatable",
      "type": "string"
    },
    "decision": {
      "description": "Decision",
      "type": "string"
    },
    "exploitation": {
      "description": "State of Exploitation (Evidence of Active Exploitation of a Vulnerability)",
      "type": "string"
    },
    "mission_and_well_being_impact_value": {
      "description": "Mission and Well-Being Impact Value",
      "type": "string"
    },
    "mission_prevalence": {
      "description": "Mission Prevalence (Impact on Mission Essential Functions of Relevant Entities)",
      "type": "string"
    },
    "public_well_being_impact": {
      "description": "Public Well-being Impact",
      "type": "string"
    },
    "summary": {
      "description": "Summary",
      "type": "string"
    },
    "technical_impact": {
      "description": "Technical Impact (Technical Impact of Exploiting the Vulnerability)",
      "type": "string"
    },
    "vector_string": {
      "description": "SSVC Vector String",
      "type": "string"
    }
  },
  "required": [
    "exploitation",
    "technical_impact",
    "automatable",
    "mission_prevalence",
    "public_well_being_impact",
    "mission_and_well_being_impact_value",
    "decision",
    "vector_string"
  ]
}
🟡vulnerability_info(cve_id)

Get detailed information about a specific CVE. ## What this tool does Retrieves the full vulnerability record for a CVE from SecDB, including: - official description and summary - CVSS metrics (all versions available) - EPSS metadata (if present) - affected products and versions - vendor/security advisories - references and upstream sources - weakness classification (CWE) - exploit and patch information (if included in the record) All information is returned in a structured Markdown format suitable for direct display. ## When to use this tool Use this tool when the user asks: - "Give me details about CVE-XYZ." - "Which products are affected by this vulnerability?" - "Show me advisories or references for this CVE." - "Explain what this vulnerability is and how serious it is." This tool is ideal for **deep inspection of a single vulnerability**. For multiple CVEs, call the tool once per CVE. ## Inputs - **cve_id**: valid CVE identifier (`CVE-YYYY-NNNNN`). ## Outputs Markdown-formatted vulnerability information including: - detailed description - severity metrics (CVSS, vectors) - affected products list - advisory list - references - weakness (CWE) details - additional structured metadata from SecDB ## LLM usage guidelines - Always prefer this tool when the user needs factual information about a specific CVE. - If multiple CVEs are mentioned, call the tool once per CVE. - Combine with: - **`vulnerability_score`** - to enrich output with numerical CVSS/EPSS metrics - **`sightings_search`** - to check real-world exploitation, PoCs, plugins, advisories - **`ssvc_calculator`** - to compute prioritization based on the vulnerability data - Do not hallucinate product lists, advisories, or details—use what the tool returns.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "cve_id": {
      "description": "CVE identification (CVE-YYYY-NNNNN)",
      "type": "string"
    }
  },
  "required": [
    "cve_id"
  ]
}
🟢vulnerability_score(cve_id)

Get CVSS and current EPSS score for a specific CVE. ## What this tool does Returns a full risk snapshot for a CVE, including: - CVSS version - CVSS base score - CVSS severity - CVSS vector string - human-readable explanation of the CVSS vector - current EPSS score The field **`cvss_explain`** provides a natural-language interpretation of the CVSS vector (attack conditions, privileges, user interaction, impact breakdown). Example: For `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`, the explanation may read: *"The vulnerability can be exploited remotely over the network with low complexity, without authentication and without user interaction. Exploitation may lead to high impact on confidentiality, high impact on integrity, and high impact on availability."* ## When to use this tool Use this tool when the user asks: - "What is the CVSS/EPSS of this CVE?" - "Explain the CVSS vector of this vulnerability." - "What is the severity and why?" - "Give me the risk profile for this CVE." For EPSS historical trends, use `epss_timeseries`. ## Inputs - **cve_id**: valid CVE identifier (`CVE-YYYY-NNNNN`). ## Outputs - `cvss_version` - `cvss_base_score` - `cvss_base_severity` - `cvss_vector_string` - `cvss_explain` - human-readable explanation of the CVSS vector - `epss_score` ## LLM usage guidelines - Never guess CVSS or EPSS values—always call this tool. - Use the `cvss_explain` field directly when the user wants an interpretation of the vector string. - If multiple CVEs are referenced, call the tool once per CVE. - Combine this tool with `sightings_search` or `ssvc_calculator` for more complete risk assessments.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "cve_id": {
      "description": "CVE identification (CVE-YYYY-NNNNN)",
      "type": "string"
    }
  },
  "required": [
    "cve_id"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "cvss_base_score": {
      "description": "CVSS base score",
      "type": "string"
    },
    "cvss_base_severity": {
      "description": "CVSS base severity",
      "type": "string"
    },
    "cvss_explain": {
      "description": "Explain CVSS",
      "type": "string"
    },
    "cvss_vector_string": {
      "description": "CVSS vector string",
      "type": "string"
    },
    "cvss_version": {
      "description": "CVSS version",
      "type": "string"
    },
    "epss_score": {
      "description": "EPSS score",
      "type": "string"
    }
  },
  "required": [
    "cvss_version",
    "cvss_base_score",
    "cvss_base_severity",
    "cvss_vector_string",
    "epss_score"
  ]
}
🟢vulnerability_search(query)

Perform a full-text vulnerability search in SecDB. ## What this tool does Searches across: - CVE entries - Security advisories - Exploit references - Product and vendor vulnerability data Results are formatted in Markdown and include a search summary. ## Searchable fields (Lucene syntax supported): - type: result type - cve, cwe, advisory, nasl, exploitdb, nuclei - id: exact identifier (e.g. id:CVE-2026-12345, id:RHSA-2026:1234) - title: resource title or name - summary: short summary - description: full description text - alias: known vulnerability names (e.g. alias:log4shell) - severity: critical, high, medium, low - kev: true/false — CISA KEV catalog membership - status: NVD status (CVE only) e.g. analyzed, modified - published: publication date (e.g. published:[2026-01-01 TO 2026-12-31]) - modified: last modification date - source: CNA or advisory source (e.g. source:"Red Hat", source:fortinet) - cve: related CVE ID (e.g. cve:CVE-2026-44827) - cwe: related CWE ID (e.g. cwe:CWE-79) - tag: advisory tag (e.g. tag:scada, tag:ics) - attack_vector: network, adjacent, local, physical - cvss_score: CVSS base score (e.g. cvss_score:[7.0 TO 10.0]) Default operator is AND. Use OR for alternatives, quotes for exact phrases, * for wildcards. ## Examples: - "apache struts rce" → RCE vulnerabilities in Apache Struts - "id:CVE-2026-44827" → exact CVE lookup - "source:fortinet AND severity:critical" → critical Fortinet advisories - "alias:log4shell" → Log4Shell by alias - "cve:CVE-2026-44827 AND type:exploitdb" → ExploitDB entries for a CVE - "cvss_score:[9.0 TO 10.0] AND kev:true" → critical KEV CVEs - "tag:scada AND severity:high" → high severity ICS/SCADA advisories ## When to use this tool Use this tool when the user asks: - to look up a CVE, advisory, exploit, or product - "show vulnerabilities for X" - "search for advisories about Y" - exploratory or broad vulnerability discovery ## Inputs - **query**: free-text search term (CVE ID, advisory ID, product name, exploit name, vendor, keyword, etc.) ## Outputs - **results**: array of Markdown-formatted search hits - **summary**: Markdown summary with counts and a link to continue searching on SecDB ## LLM usage guidelines - Use this tool instead of assuming whether a CVE/advisory/exploit exists. - Present `results` and `summary` directly to the user-they are already Markdown. - Combine with `vulnerability_score`, `epss_timeseries`, or `sightings_search` for deeper analysis.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "query": {
      "description": "CVE ID, vulnerability name, Advisory ID, Exploit, etc.",
      "type": "string"
    }
  },
  "required": [
    "query"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "results": {
      "items": {
        "description": "Formatted result in Markdown",
        "type": "string"
      },
      "type": "array"
    },
    "summary": {
      "description": "Search summary with found records (ID) and link for continue the search on SecDB",
      "type": "string"
    }
  }
}
🟢feed_report_catalog

List available public ZEN SecDB feed reports. ## What this tool does Returns the catalog of available ZEN SecDB public feed reports, including their identifiers, descriptions, and supported input parameters. This tool helps discover which reports can be executed through `feed_report`. ## When to use this tool Use this tool when: - the user asks what public reports are available - you need to discover the correct report ID before running a report - you need to inspect supported filters or input parameters - you are unsure which report best matches the user request ## Inputs This tool does not require any input. ## Outputs - **reports**: array of report definitions, each containing: - `report_id`: report identifier - `title`: human-readable report title - `description`: short explanation of what the report returns - `input_schema`: optional JSON schema describing supported input parameters ## LLM usage guidelines - Use this tool before `feed_report` whenever the correct report ID or supported parameters are not already known. - Do not invent report IDs or parameters not present in the catalog. - Prefer the most specific matching report for the user request. - When useful, briefly summarize the most relevant available reports before calling `feed_report`.

Eingabe-Schema

{
  "type": "object",
  "required": []
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "reports": {
      "items": {
        "properties": {
          "description": {
            "description": "short explanation of what the report returns",
            "type": "string"
          },
          "input_schema": {
            "description": "optional JSON schema describing supported input parameters",
            "properties": {
              "additionalProperties": true
            },
            "type": "object"
          },
          "report_id": {
            "description": "Report identifier",
            "type": "string"
          },
          "title": {
            "description": "human-readable report title",
            "type": "string"
          }
        },
        "type": "object"
      },
      "type": "array"
    }
  }
}
🔴feed_report(filters, limit, report_id)

Run a public ZEN SecDB feed report. ## What this tool does Executes a predefined report on ZEN SecDB public feed data and returns structured results for analytics, trends, distributions, and top-N summaries. Supported reports can cover public datasets such as: - CVEs - security advisories - EPSS - weaknesses - CPE vendors and products - exploit references - sightings and IOC-related data Use `feed_report_catalog` to discover the list of available reports and their supported input parameters. ## When to use this tool Use this tool when the user asks about: - distributions, trends, or counts across public vulnerability data - top CVEs, top weaknesses, top vendors, or similar rankings - timeline-based summaries such as yearly or monthly trends - aggregated views over public SecDB feed data Do not use this tool when the user asks for details about a single CVE, advisory, or exploit. Use the dedicated lookup tools instead. ## Inputs - **report_id**: identifier of the report to execute - **filters**: optional object with report-specific filters - **limit**: optional maximum number of results to return, when supported by the selected report ## Outputs - **summary**: Optional Markdown summary of the report results - **report**: structured JSON object containing: - `report_id`: executed report identifier - `filters`: applied filters - `data`: structured report rows or aggregated values ## LLM usage guidelines - Use `feed_report_catalog` when you need to discover which public reports are available or which parameters they support. - Do not guess report IDs-use the catalog when uncertain. - Present `summary` directly to the user-it is already Markdown. - Use `report` for structured follow-up analysis, comparisons, or tool chaining. - If the selected report does not exist, return a clear not-found error instead of guessing an alternative.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "filters": {
      "description": "optional object with report-specific filters",
      "type": "object"
    },
    "limit": {
      "description": "optional maximum number of results to return, when supported by the selected report",
      "type": "string"
    },
    "report_id": {
      "description": "identifier of the report to execute",
      "type": "string"
    }
  },
  "required": [
    "report_id"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "data": {
      "description": "structured report rows or aggregated values",
      "oneOf": [
        {
          "items": {
            "type": "object"
          },
          "type": "array"
        },
        {
          "type": "object"
        }
      ]
    },
    "filters": {
      "description": "optional JSON schema describing supported input parameters",
      "type": "object"
    },
    "report_id": {
      "description": "executed report identifier",
      "type": "string"
    },
    "summary": {
      "description": "Optional Markdown summary of the report results",
      "type": "string"
    }
  },
  "required": [
    "report_id",
    "data"
  ]
}
🟡purl_audit(purls)

Perform a software package vulnerability audit using SecDB. ## What this tool does Analyzes a list of software packages identified by PURL (Package URL) and returns vulnerability information plus a Markdown summary. The audit results are based exclusively on the package list provided. ## When to use this tool Use this tool when the user wants to determine: - whether application dependencies contain known vulnerabilities - whether a project is affected by security advisories - which packages require patching or upgrading ## Supported ecosystems - **npm** - Node.js packages (e.g. pkg:npm/[email protected]) - **maven** - Java/JVM packages (e.g. pkg:maven/org.apache.logging.log4j/[email protected]) - **pypi** - Python packages (e.g. pkg:pypi/[email protected]) - **gem** - Ruby gems (e.g. pkg:gem/[email protected]) - **cargo** - Rust crates (e.g. pkg:cargo/[email protected]) - **nuget** - .NET packages (e.g. pkg:nuget/[email protected]) - **golang** - Go modules (e.g. pkg:golang/github.com/gin-gonic/[email protected]) - **composer** - PHP packages (e.g. pkg:composer/symfony/[email protected]) ## Inputs - **purls**: list of Package URLs, one per entry. Generate them from your project manifest files: - Node.js: package.json / package-lock.json - Python: requirements.txt / Pipfile.lock / pyproject.toml - Ruby: Gemfile.lock - Go: go.mod / go.sum - Rust: Cargo.lock - PHP: composer.lock - Java: pom.xml / build.gradle - .NET: *.csproj / packages.lock.json ## Outputs - **report**: structured JSON objects describing the advisories affecting the audited packages. - **summary**: Markdown summary including total vulnerabilities, severity breakdown, and key findings. ## LLM usage guidelines - Never guess whether a package is vulnerable — always call this tool. - Only submit PURLs from the supported ecosystems listed above; others will be ignored. - The `summary` is already Markdown and can be shown directly. - Use `report` when deeper technical analysis is required.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "purls": {
      "description": "List of Package URLs (PURL) to audit",
      "items": {
        "type": "string"
      },
      "type": "array"
    }
  },
  "required": [
    "purls"
  ]
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "report": {
      "items": {
        "additionalProperties": true,
        "description": "structured objects describing the advisories affecting the audited packages",
        "type": "object"
      },
      "type": "array"
    },
    "summary": {
      "description": "Markdown summary including total vulnerabilities, severity breakdown, and key findings",
      "type": "string"
    }
  }
}

Empfohlene Prompts

search_research
Search for information about [topic] using ZEN SecDB
Erwartete Tools: sightings_search
find_specific
Find [specific item] using ZEN SecDB
Erwartete Tools: sightings_search

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet11 Tools
verifiziertVersion nicht aufgezeichnet11 Tools