Get Vulnerability
get_vulnerabilityGet a cached CVE or CNNVD record and distribution-aware affected-package evidence.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | ||
| database | No | cve |
get_vulnerabilityGet a cached CVE or CNNVD record and distribution-aware affected-package evidence.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | ||
| database | No | cve |
Changes observed during successful MCP inspections. Dates show when Glama detected each change.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations (readOnlyHint, idempotentHint) already declare it non-destructive, and the description adds useful context: 'cached' indicates data may be stale, and 'distribution-aware affected-package evidence' hints at distribution-specific behavior. This goes beyond the annotations without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence that efficiently conveys the core purpose without filler words. Every word contributes to understanding the tool's function.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description should clarify what the return value contains. It mentions 'record and evidence' but is vague about the exact structure or how distribution-awareness manifests. The tool is simple (2 params, read-only) so this is adequate but not fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0% description coverage, so the description must explain the parameters. However, it only mentions 'CVE or CNNVD' which loosely maps to the id/database params but does not explain their specific purpose or relationship. The description adds minimal value over the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific action ('Get') on a specific resource ('cached CVE or CNNVD record') and adds a distinctive qualifier ('distribution-aware affected-package evidence'). This distinguishes it from sibling tools like search_vulnerabilities, which likely searches rather than fetches by ID.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'Get a cached CVE or CNNVD record' implies this tool is for retrieving a known vulnerability identifier, but it does not explicitly say when to use it over alternatives like search_vulnerabilities. There is no mention of exclusions or prerequisites, only an implied use case.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.
The tool set covers many closely related operations: three 'compare_*' tools, four command-diagnostic tools, and several lookup tools that can overlap. Descriptions help but boundaries are not always obvious (e.g., identify_binary vs query_file_provides, lint_command vs suggest_fix), so an agent may select the wrong tool for a task.
All tool names follow a consistent verb_noun (or verb_noun_noun) pattern with snake_case. Verbs such as get, search, compare, and diagnose are used predictably, making the set's structure easy to learn.
22 tools is more than the typical well-scoped set (3-15), and the server covers a broad but unified domain. While each tool serves a distinct purpose, the granularity is slightly heavy—some comparison and diagnostic tools could potentially be merged.
The tool surface covers core intelligence workflows: searching, fetching details, comparing, resolving installs, migration planning, lifecycle checks, and vulnerability lookup. Minor gaps exist such as a direct 'list_distributions' tool, but agents can work around these using existing tools.