Tool reference
The server exposes three MCP tools. The input schemas are discoverable through MCP and are summarized here for operational review.
get_cve_patch_data
Retrieves patch and optional CPE enrichment for a CVE.
| Input | Required | Description |
|---|---|---|
cve_id |
Yes | CVE identifier, for example
CVE-2025-21179. |
The result can contain multiple KB or product choices. Observe selection warnings and pass the selected values to later tools.
fetch_patch_files
Retrieves patch file metadata from a supported vendor.
| Input | Required | Description |
|---|---|---|
vendor |
No | microsoft, google_chrome, or
winget. Defaults to
microsoft. |
kb_article_id |
Conditional | Microsoft KB number without the KB prefix. Use this or
catalog_query for Microsoft. |
catalog_query |
Conditional | Microsoft Update Catalog search query. Use this or
kb_article_id for Microsoft. |
architecture |
No | x64, x86, or
arm64. Defaults to
x64. |
channel |
Conditional | Google Chrome release channel. Defaults to
stable where applicable. |
package_id |
Conditional | WinGet package identifier. |
version |
Conditional | Application version used by WinGet or application update flows. |
The result includes file metadata and verification or provenance warnings. Retain those warnings through review.
generate_fixlet
Selects an embedded template and generates BES XML.
| Input | Required | Description |
|---|---|---|
cve_id |
Yes | CVE identifier used in Fixlet metadata. |
kb_article_id |
Conditional | Microsoft KB number without the prefix. Provide this or
fixed_version. |
fixed_version |
Conditional | Fixed application version for non-KB application updates. Provide
this or kb_article_id. |
product_name |
Yes | Selected product name. |
severity |
No | Security severity when available. |
release_date |
No | Patch release date when available. |
fixed_build_number |
No | Fixed OS or product build number when available. |
publisher |
Conditional | Application publisher for application update flows. |
display_name_prefix |
Conditional | Installed application display-name prefix. |
cpe_id |
No | CPE 2.3 identifier when available. |
files |
Yes | One or more patch file objects returned by
fetch_patch_files. |
Each files item supports:
| Field | Required | Description |
|---|---|---|
filename |
Yes | Patch filename. |
sha1 |
Conditional | SHA-1 file hash. Required for KB/MSU generation and BigFix compatibility. |
sha256 |
No | SHA-256 file hash when available. |
size_bytes |
Yes | Exact file size in bytes. |
download_url |
Yes | Vendor download URL. |
prefetch. They are not certificate-pin algorithms. Vendor TLS
certificate pins use SHA3-256.For Microsoft KB generation, the server independently rechecks provenance before rendering. Every CVE must map through MSRC to the submitted KB, product, and architecture, and every submitted file must exactly match the current Microsoft Update Catalog filename, SHA-1, SHA-256, size, URL, count, and order. Generation fails closed if either verification source is unavailable or any value differs.
Application update flows currently enforce trusted HTTPS source hosts and prefetch
integrity fields, but do not have the same end-to-end vendor provenance binding
because generate_fixlet does not yet receive the originating package
ID or channel. Preserve the fetch_patch_files result and its
verification warnings during application review.
Tool failure behavior
Tools fail closed for invalid input, unavailable vendor data, unsupported combinations, or generation validation errors. Treat warnings in successful results as part of the result; success does not mean that generated content is approved for deployment.