{"servers":[{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.cyanheads/cisa-cybersecurity-mcp-server","description":"CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.","repository":{"url":"https://github.com/cyanheads/cisa-cybersecurity-mcp-server","source":"github"},"version":"0.1.1","packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@cyanheads/cisa-cybersecurity-mcp-server","version":"0.1.1","runtimeHint":"node","transport":{"type":"stdio"},"packageArguments":[{"value":"run","type":"positional"},{"value":"start:stdio","type":"positional"}],"environmentVariables":[{"description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","default":"info","name":"MCP_LOG_LEVEL"},{"description":"Cron expression for the KEV catalog conditional-refresh poll. HTTP transport only; an empty value disables the in-process schedule.","format":"string","default":"*/30 * * * *","name":"CISA_KEV_REFRESH_CRON"},{"description":"Filesystem path to the local SQLite index of ICS advisories.","format":"string","default":".mirror/csaf.sqlite3","name":"CISA_CSAF_MIRROR_PATH"},{"description":"Seed the ICS advisory index in the background at startup when it has never completed a sync. Accepts true or false; set false where seeding runs out of band.","format":"string","default":"true","name":"CISA_CSAF_MIRROR_AUTO_INIT"},{"description":"Cron expression for the incremental ICS advisory refresh. HTTP transport only; an empty value disables it.","format":"string","default":"17 */6 * * *","name":"CISA_CSAF_REFRESH_CRON"},{"description":"Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.","format":"string","default":"21600","name":"CISA_VULNRICHMENT_CACHE_TTL_SECONDS"},{"description":"Seconds a parsed RSS feed window stays cached.","format":"string","default":"900","name":"CISA_FEED_CACHE_TTL_SECONDS"},{"description":"Per-request timeout in milliseconds for every upstream fetch.","format":"string","default":"30000","name":"CISA_HTTP_TIMEOUT_MS"}]},{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@cyanheads/cisa-cybersecurity-mcp-server","version":"0.1.1","runtimeHint":"node","transport":{"type":"streamable-http","url":"http://localhost:3010/mcp"},"packageArguments":[{"value":"run","type":"positional"},{"value":"start:http","type":"positional"}],"environmentVariables":[{"description":"The hostname for the HTTP server.","format":"string","default":"127.0.0.1","name":"MCP_HTTP_HOST"},{"description":"The port to run the HTTP server on.","format":"string","default":"3010","name":"MCP_HTTP_PORT"},{"description":"The endpoint path for the MCP server.","format":"string","default":"/mcp","name":"MCP_HTTP_ENDPOINT_PATH"},{"description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","default":"none","name":"MCP_AUTH_MODE"},{"description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","default":"info","name":"MCP_LOG_LEVEL"},{"description":"Cron expression for the KEV catalog conditional-refresh poll. HTTP transport only; an empty value disables the in-process schedule.","format":"string","default":"*/30 * * * *","name":"CISA_KEV_REFRESH_CRON"},{"description":"Filesystem path to the local SQLite index of ICS advisories.","format":"string","default":".mirror/csaf.sqlite3","name":"CISA_CSAF_MIRROR_PATH"},{"description":"Seed the ICS advisory index in the background at startup when it has never completed a sync. Accepts true or false; set false where seeding runs out of band.","format":"string","default":"true","name":"CISA_CSAF_MIRROR_AUTO_INIT"},{"description":"Cron expression for the incremental ICS advisory refresh. HTTP transport only; an empty value disables it.","format":"string","default":"17 */6 * * *","name":"CISA_CSAF_REFRESH_CRON"},{"description":"Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.","format":"string","default":"21600","name":"CISA_VULNRICHMENT_CACHE_TTL_SECONDS"},{"description":"Seconds a parsed RSS feed window stays cached.","format":"string","default":"900","name":"CISA_FEED_CACHE_TTL_SECONDS"},{"description":"Per-request timeout in milliseconds for every upstream fetch.","format":"string","default":"30000","name":"CISA_HTTP_TIMEOUT_MS"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-20T03:39:41.550837Z","publishedAt":"2026-09-20T03:39:41.550837Z","updatedAt":"2026-09-20T03:39:41.550837Z","isLatest":false}}},{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"io.github.cyanheads/cisa-cybersecurity-mcp-server","description":"CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.","repository":{"url":"https://github.com/cyanheads/cisa-cybersecurity-mcp-server","source":"github"},"version":"0.1.2","packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@cyanheads/cisa-cybersecurity-mcp-server","version":"0.1.2","runtimeHint":"node","transport":{"type":"stdio"},"packageArguments":[{"value":"run","type":"positional"},{"value":"start:stdio","type":"positional"}],"environmentVariables":[{"description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","default":"info","name":"MCP_LOG_LEVEL"},{"description":"Cron expression for the KEV catalog conditional-refresh poll. HTTP transport only; an empty value disables the in-process schedule.","format":"string","default":"*/30 * * * *","name":"CISA_KEV_REFRESH_CRON"},{"description":"Filesystem path to the local SQLite index of ICS advisories.","format":"string","default":".mirror/csaf.sqlite3","name":"CISA_CSAF_MIRROR_PATH"},{"description":"Seed the ICS advisory index in the background at startup when it has never completed a sync. Accepts true or false; set false where seeding runs out of band.","format":"string","default":"true","name":"CISA_CSAF_MIRROR_AUTO_INIT"},{"description":"Cron expression for the incremental ICS advisory refresh. HTTP transport only; an empty value disables it.","format":"string","default":"17 */6 * * *","name":"CISA_CSAF_REFRESH_CRON"},{"description":"Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.","format":"string","default":"21600","name":"CISA_VULNRICHMENT_CACHE_TTL_SECONDS"},{"description":"Seconds a parsed RSS feed window stays cached.","format":"string","default":"900","name":"CISA_FEED_CACHE_TTL_SECONDS"},{"description":"Per-request timeout in milliseconds for every upstream fetch.","format":"string","default":"30000","name":"CISA_HTTP_TIMEOUT_MS"}]},{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@cyanheads/cisa-cybersecurity-mcp-server","version":"0.1.2","runtimeHint":"node","transport":{"type":"streamable-http","url":"http://localhost:3010/mcp"},"packageArguments":[{"value":"run","type":"positional"},{"value":"start:http","type":"positional"}],"environmentVariables":[{"description":"The hostname for the HTTP server.","format":"string","default":"127.0.0.1","name":"MCP_HTTP_HOST"},{"description":"The port to run the HTTP server on.","format":"string","default":"3010","name":"MCP_HTTP_PORT"},{"description":"The endpoint path for the MCP server.","format":"string","default":"/mcp","name":"MCP_HTTP_ENDPOINT_PATH"},{"description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","default":"none","name":"MCP_AUTH_MODE"},{"description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","default":"info","name":"MCP_LOG_LEVEL"},{"description":"Cron expression for the KEV catalog conditional-refresh poll. HTTP transport only; an empty value disables the in-process schedule.","format":"string","default":"*/30 * * * *","name":"CISA_KEV_REFRESH_CRON"},{"description":"Filesystem path to the local SQLite index of ICS advisories.","format":"string","default":".mirror/csaf.sqlite3","name":"CISA_CSAF_MIRROR_PATH"},{"description":"Seed the ICS advisory index in the background at startup when it has never completed a sync. Accepts true or false; set false where seeding runs out of band.","format":"string","default":"true","name":"CISA_CSAF_MIRROR_AUTO_INIT"},{"description":"Cron expression for the incremental ICS advisory refresh. HTTP transport only; an empty value disables it.","format":"string","default":"17 */6 * * *","name":"CISA_CSAF_REFRESH_CRON"},{"description":"Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.","format":"string","default":"21600","name":"CISA_VULNRICHMENT_CACHE_TTL_SECONDS"},{"description":"Seconds a parsed RSS feed window stays cached.","format":"string","default":"900","name":"CISA_FEED_CACHE_TTL_SECONDS"},{"description":"Per-request timeout in milliseconds for every upstream fetch.","format":"string","default":"30000","name":"CISA_HTTP_TIMEOUT_MS"}]}],"remotes":[{"type":"streamable-http","url":"https://cisa-cybersecurity.caseyjhand.com/mcp"}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-20T14:21:22.719915Z","publishedAt":"2026-09-20T14:21:22.719915Z","updatedAt":"2026-09-20T14:21:22.719915Z","isLatest":true}}}],"metadata":{"count":2}}
