Introduction
The MCP Server for Vulnerability Remediation enables compatible AI clients to discover security patch information and generate BigFix Fixlet XML through the Model Context Protocol (MCP).
The server runs as a standalone service and exposes a streamable HTTP endpoint, normally
over HTTPS on port 9495. An MCP client supplies a BigFix REST API
bearer token in the HTTP Authorization header. The server validates that
token against the configured BigFix Server and
uses it to preserve the identity and access controls associated with the caller.
The server provides a guided workflow that can:
- Look up patch data associated with a CVE.
- Discover downloadable patch files from supported vendor sources.
- Select an appropriate embedded BigFix template.
- Generate BES XML and a supporting result report.
How the server works
The server combines data from security and vendor services with embedded Fixlet templates. Vendor HTTPS connections are restricted by an embedded SHA3-256 Subject Public Key Information (SPKI) pin policy. The BigFix Server uses a separately configured CA certificate because that trust material is owned by the deploying organization.
After authentication and Remediate entitlement validation, the usual workflow is:
- Retrieve CVE and patch data.
- Retrieve patch file metadata for the selected vendor, product, and architecture.
- Review file hashes, download locations, product selection, and warnings.
- Generate and review the Fixlet.
For the complete workflow, see Using the server. For trust boundaries and security controls, see Security architecture.