Tool reference

The server exposes three MCP tools. The input schemas are discoverable through MCP and are summarized here for operational review.

get_cve_patch_data

Retrieves patch and optional CPE enrichment for a CVE.

Table 1. get_cve_patch_data inputs
Input Required Description
cve_id Yes CVE identifier, for example CVE-2025-21179.

The result can contain multiple KB or product choices. Observe selection warnings and pass the selected values to later tools.

fetch_patch_files

Retrieves patch file metadata from a supported vendor.

Table 2. fetch_patch_files inputs
Input Required Description
vendor No microsoft, google_chrome, or winget. Defaults to microsoft.
kb_article_id Conditional Microsoft KB number without the KB prefix. Use this or catalog_query for Microsoft.
catalog_query Conditional Microsoft Update Catalog search query. Use this or kb_article_id for Microsoft.
architecture No x64, x86, or arm64. Defaults to x64.
channel Conditional Google Chrome release channel. Defaults to stable where applicable.
package_id Conditional WinGet package identifier.
version Conditional Application version used by WinGet or application update flows.

The result includes file metadata and verification or provenance warnings. Retain those warnings through review.

generate_fixlet

Selects an embedded template and generates BES XML.

Table 3. generate_fixlet inputs
Input Required Description
cve_id Yes CVE identifier used in Fixlet metadata.
kb_article_id Conditional Microsoft KB number without the prefix. Provide this or fixed_version.
fixed_version Conditional Fixed application version for non-KB application updates. Provide this or kb_article_id.
product_name Yes Selected product name.
severity No Security severity when available.
release_date No Patch release date when available.
fixed_build_number No Fixed OS or product build number when available.
publisher Conditional Application publisher for application update flows.
display_name_prefix Conditional Installed application display-name prefix.
cpe_id No CPE 2.3 identifier when available.
files Yes One or more patch file objects returned by fetch_patch_files.

Each files item supports:

Table 4. files item fields
Field Required Description
filename Yes Patch filename.
sha1 Conditional SHA-1 file hash. Required for KB/MSU generation and BigFix compatibility.
sha256 No SHA-256 file hash when available.
size_bytes Yes Exact file size in bytes.
download_url Yes Vendor download URL.
Note:
SHA-1 and SHA-256 in this schema are vendor file-integrity fields used by BigFix prefetch. They are not certificate-pin algorithms. Vendor TLS certificate pins use SHA3-256.

For Microsoft KB generation, the server independently rechecks provenance before rendering. Every CVE must map through MSRC to the submitted KB, product, and architecture, and every submitted file must exactly match the current Microsoft Update Catalog filename, SHA-1, SHA-256, size, URL, count, and order. Generation fails closed if either verification source is unavailable or any value differs.

Application update flows currently enforce trusted HTTPS source hosts and prefetch integrity fields, but do not have the same end-to-end vendor provenance binding because generate_fixlet does not yet receive the originating package ID or channel. Preserve the fetch_patch_files result and its verification warnings during application review.

Tool failure behavior

Tools fail closed for invalid input, unavailable vendor data, unsupported combinations, or generation validation errors. Treat warnings in successful results as part of the result; success does not mean that generated content is approved for deployment.