Introduction

The MCP Server for Vulnerability Remediation enables compatible AI clients to discover security patch information and generate BigFix Fixlet XML through the Model Context Protocol (MCP).

The server runs as a standalone service and exposes a streamable HTTP endpoint, normally over HTTPS on port 9495. An MCP client supplies a BigFix REST API bearer token in the HTTP Authorization header. The server validates that token against the configured BigFix Server and uses it to preserve the identity and access controls associated with the caller.

The server provides a guided workflow that can:

  • Look up patch data associated with a CVE.
  • Discover downloadable patch files from supported vendor sources.
  • Select an appropriate embedded BigFix template.
  • Generate BES XML and a supporting result report.
Important:
Review and test the generated content before you deploy it. The server does not create or deploy BigFix actions, modify managed endpoints, or bypass BigFix permissions.

How the server works

The server combines data from security and vendor services with embedded Fixlet templates. Vendor HTTPS connections are restricted by an embedded SHA3-256 Subject Public Key Information (SPKI) pin policy. The BigFix Server uses a separately configured CA certificate because that trust material is owned by the deploying organization.

After authentication and Remediate entitlement validation, the usual workflow is:

  1. Retrieve CVE and patch data.
  2. Retrieve patch file metadata for the selected vendor, product, and architecture.
  3. Review file hashes, download locations, product selection, and warnings.
  4. Generate and review the Fixlet.

For the complete workflow, see Using the server. For trust boundaries and security controls, see Security architecture.