About this integration
Queries public CISA cybersecurity data for known exploited vulnerability status, SSVC decision points, industrial control system advisories, and recent publication feeds through a keyless MCP server.
- Transport
- stdio
- Authentication
- none
- Initial setup
- none
- Runtime
- unattended
- Evidence
- documented
- Package
- @cyanheads/cisa-cybersecurity-mcp-server
- Last compatibility test
- Not independently tested
Connect your agent
@cyanheads/cisa-cybersecurity-mcp-serverPinned publisher README and executable npm manifest reviewed. The package and upstream services were not executed or independently security-audited. Qualification covers the documented local stdio connection and keyless, read-only tools; the separately documented HTTP deployment and optional framework storage or authentication modes are outside this record. The publisher warns that parts of the advisory corpus have no declared license and may contain republished vendor material.
Capabilities: Check CVE identifiers against the CISA Known Exploited Vulnerabilities catalog, Search the KEV catalog and industrial control system advisory corpus, Retrieve CISA-published SSVC decision points, Read industrial control system advisories and recent CISA feeds
Connected profiles
Additional details
@cyanheads/cisa-cybersecurity-mcp-server
Source ↗ · Checked 2026-09-200.1.1
Source ↗ · Checked 2026-09-20The publisher states that both resources are fully covered by tools, so a tool-only client loses nothing. The documented keyless, read-only query surface therefore has no runtime human step; this is documentation evidence, not an execution test.
Source ↗ · Checked 2026-09-20No credentials are required for the documented CISA sources. Node.js 24 or Bun 1.4 is a software prerequisite, not an authentication step.
Source ↗ · Checked 2026-09-20The reviewed npm artifact is launched locally over stdio with npx -y @cyanheads/cisa-cybersecurity-mcp-server@latest. Registry naming is treated only as an alias and not as another integration.
Source ↗ · Checked 2026-09-20Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-20