PluginBench
MCP Server

io.github.cyanheads/cisa-cybersecurity-mcp-server MCP Server

io.github.cyanheads/cisa-cybersecurity-mcp-server

What is the io.github.cyanheads/cisa-cybersecurity-mcp-server MCP server?

CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.

How to install io.github.cyanheads/cisa-cybersecurity-mcp-server

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • MCP_LOG_LEVEL

    Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').

  • CISA_KEV_REFRESH_CRON

    Cron expression for the KEV catalog conditional-refresh poll, on every transport. Set off to disable it; an invalid expression fails startup.

  • CISA_CSAF_MIRROR_PATH

    Filesystem path to the local SQLite index of ICS advisories. Unset, it is csaf.sqlite3 under cisa-cybersecurity-mcp-server in the per-user cache directory: ~/Library/Caches on macOS, $XDG_CACHE_HOME or ~/.cache on Linux, %LOCALAPPDATA% on Windows.

  • CISA_CSAF_MIRROR_AUTO_INIT

    Seed the ICS advisory index in the background at startup when it has never completed a sync, and re-ingest it in place when an older server version built it. Accepts true or false; set false where seeding runs out of band.

  • CISA_CSAF_REFRESH_CRON

    Cron expression for the incremental ICS advisory refresh, on every transport; the refresh also runs once at startup. Set off to disable both; an invalid expression fails startup.

  • CISA_VULNRICHMENT_CACHE_TTL_SECONDS

    Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.

  • CISA_FEED_CACHE_TTL_SECONDS

    Seconds a parsed RSS feed window stays cached.

  • CISA_HTTP_TIMEOUT_MS

    Per-request timeout in milliseconds for every upstream fetch.

  • MCP_HTTP_HOST

    The hostname for the HTTP server.

  • MCP_HTTP_PORT

    The port to run the HTTP server on.

  • MCP_HTTP_ENDPOINT_PATH

    The endpoint path for the MCP server.

  • MCP_AUTH_MODE

    Authentication mode to use: 'none', 'jwt', or 'oauth'.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "cisa-cybersecurity-mcp-server": {
      "command": "node",
      "args": [
        "-y",
        "@cyanheads/cisa-cybersecurity-mcp-server",
        "run",
        "start:stdio"
      ],
      "env": {
        "MCP_LOG_LEVEL": "<YOUR_MCP_LOG_LEVEL>",
        "CISA_KEV_REFRESH_CRON": "<YOUR_CISA_KEV_REFRESH_CRON>",
        "CISA_CSAF_MIRROR_PATH": "<YOUR_CISA_CSAF_MIRROR_PATH>",
        "CISA_CSAF_MIRROR_AUTO_INIT": "<YOUR_CISA_CSAF_MIRROR_AUTO_INIT>",
        "CISA_CSAF_REFRESH_CRON": "<YOUR_CISA_CSAF_REFRESH_CRON>",
        "CISA_VULNRICHMENT_CACHE_TTL_SECONDS": "<YOUR_CISA_VULNRICHMENT_CACHE_TTL_SECONDS>",
        "CISA_FEED_CACHE_TTL_SECONDS": "<YOUR_CISA_FEED_CACHE_TTL_SECONDS>",
        "CISA_HTTP_TIMEOUT_MS": "<YOUR_CISA_HTTP_TIMEOUT_MS>",
        "MCP_HTTP_HOST": "<YOUR_MCP_HTTP_HOST>",
        "MCP_HTTP_PORT": "<YOUR_MCP_HTTP_PORT>",
        "MCP_HTTP_ENDPOINT_PATH": "<YOUR_MCP_HTTP_ENDPOINT_PATH>",
        "MCP_AUTH_MODE": "<YOUR_MCP_AUTH_MODE>"
      }
    }
  }
}

Related MCP servers

Search ClinicalTrials.gov, retrieve study details and results, and match patients to eligible trials.

81
TypeScript
Apache-2.0
View repository →

Read, write, and inspect the system clipboard on macOS, Linux (X11/Wayland), and Windows via MCP.

1
TypeScript
Apache-2.0
View repository →

Crypto market data via CoinGecko — prices, markets, history, trending, and deep coin metadata.

1
TypeScript
Apache-2.0
View repository →

Search, compare, and analyze U.S. college data — costs, earnings, programs, and outcomes.

1
TypeScript
View repository →

Access U.S. congressional data - bills, votes, members, committees - via MCP.

1
TypeScript
Apache-2.0
View repository →

Search US court opinions, federal dockets, judges, citations, and oral arguments via CourtListener.

2
TypeScript
View repository →