Skip to content

Windsurf CISA Known Exploited Vulnerabilities (kevwatch) hire_and_execute

How to: Windsurf CISA Known Exploited Vulnerabilities (kevwatch) hire_and_execute

client:Windsurf transport:streamable-http tool:hire_and_execute

Add CISA Known Exploited Vulnerabilities (kevwatch) to Windsurf

  1. 01

    Open ~/.codeium/windsurf/mcp_config.json and merge this in. Keep any servers already there.

{
  "mcpServers": {
    "data-cisa-known-exploited-vulnerability-catalog": {
      "serverUrl": "https://a2awire.com/mcp/data/cisa-known-exploited-vulnerabilities-kevwatch-aedaf3/http"
    }
  }
}
  1. 02

    Save the file and restart Windsurf.

  2. 03

    Ask for something hire_and_execute does. Windsurf lists the server's tools on connect and calls hire_and_execute itself — you do not invoke it by name.

  3. 04

    If nothing happens, check the server is running and that CISA Known Exploited Vulnerabilities (kevwatch)'s identifier in your config matches the one above exactly.

Global only — Windsurf has no per-project MCP config. Refresh Cascade after saving. Windsurf docs

Same tool, other clients

This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what the server actually exposes, not what its listing claims.

Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.