Cisa Cybersecurity MCP Server is answering right now. Last checked 4 min ago. 313 installs a week from npm. It exposes 7 tools. Last commit 20 Sep 2026.
CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.
Over the last week it answered 99.1% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 4 min ago.
claude mcp add cisa-cybersecurity-mcp-server --transport http https://cisa-cybersecurity.caseyjhand.com/mcp
{
"mcpServers": {
"cisa-cybersecurity-mcp-server": {
"url": "https://cisa-cybersecurity.caseyjhand.com/mcp"
}
}
}
[mcp_servers.cisa-cybersecurity-mcp-server]
url = "https://cisa-cybersecurity.caseyjhand.com/mcp"
{
"mcpServers": {
"cisa-cybersecurity-mcp-server": {
"url": "https://cisa-cybersecurity.caseyjhand.com/mcp"
}
}
}
{
"mcpServers": {
"cisa-cybersecurity-mcp-server": {
"url": "https://cisa-cybersecurity.caseyjhand.com/mcp"
}
}
}
This one needs environment variables set before it will start:
MCP_HTTP_HOST (The hostname for the HTTP server.), MCP_HTTP_PORT (The port to run the HTTP server on.), MCP_HTTP_ENDPOINT_PATH (The endpoint path for the MCP server.), MCP_AUTH_MODE (Authentication mode to use: 'none', 'jwt', or 'oauth'.), MCP_LOG_LEVEL (Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').), CISA_KEV_REFRESH_CRON (Cron expression for the KEV catalog conditional-refresh poll. HTTP transport only; an empty value disables the in-process schedule.), CISA_CSAF_MIRROR_PATH (Filesystem path to the local SQLite index of ICS advisories.), CISA_CSAF_MIRROR_AUTO_INIT (Seed the ICS advisory index in the background at startup when it has never completed a sync. Accepts true or false; set false where seeding runs out of band.), CISA_CSAF_REFRESH_CRON (Cron expression for the incremental ICS advisory refresh. HTTP transport only; an empty value disables it.), CISA_VULNRICHMENT_CACHE_TTL_SECONDS (Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.), CISA_FEED_CACHE_TTL_SECONDS (Seconds a parsed RSS feed window stays cached.), CISA_HTTP_TIMEOUT_MS (Per-request timeout in milliseconds for every upstream fetch.).
The author declared them in the registry entry; get the values from the project itself.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
cisa_check_cve_status
cisa_get_advisory
cisa_get_alerts
cisa_get_ssvc
cisa_list_reference
cisa_search_ics_advisories
cisa_search_kev
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://cisa-cybersecurity.caseyjhand.com/mcp | streamable-http | answering | 392 ms | 4 min ago |
CISA advisories & ICS alerts: new CVEs, remediation. Register in-session — free testnet funds.
Gibraltar company tools: corporate tax, compliance deadlines, and PDF form generation.
Gibraltar company tools: corporate tax, compliance deadlines, and PDF form generation.
Query Microsoft Patch Tuesday security updates (MSRC) with EPSS and CISA KEV enrichment
Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th
California, US, and global climate compliance scans with source-linked deadlines.
CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...
Query CISA KEV / EPSS vulnerability feeds with full per-record provenance and auditable versions
Answers built from our own checks of this server.