Skip to content

VS Code cisa cybersecurity mcp server cisa_check_cve_status

How to: VS Code cisa cybersecurity mcp server cisa_check_cve_status

client:VS Code transport:streamable-http tool:cisa_check_cve_status

Add cisa cybersecurity mcp server to VS Code

  1. 01

    Open .vscode/mcp.json and merge this in. Keep any servers already there.

{
  "servers": {
    "cisa-cybersecurity-mcp-server": {
      "type": "http",
      "url": "https://cisa-cybersecurity.caseyjhand.com/mcp"
    }
  }
}
  1. 02

    Save the file and restart VS Code.

  2. 03

    Ask for something cisa_check_cve_status does. VS Code lists the server's tools on connect and calls cisa_check_cve_status itself — you do not invoke it by name.

  3. 04

    If nothing happens, check the server is running and that cisa cybersecurity mcp server's identifier in your config matches the one above exactly.

Requires agent mode. MCP: Open User Configuration puts the same block in every workspace. VS Code docs

Set these first

cisa cybersecurity mcp server will not start until these are set, so cisa_check_cve_status never becomes available.

  • MCP_LOG_LEVEL
  • CISA_KEV_REFRESH_CRON
  • CISA_CSAF_MIRROR_PATH
  • CISA_CSAF_MIRROR_AUTO_INIT
  • CISA_CSAF_REFRESH_CRON
  • CISA_VULNRICHMENT_CACHE_TTL_SECONDS
  • CISA_FEED_CACHE_TTL_SECONDS
  • CISA_HTTP_TIMEOUT_MS

Same tool, other clients

This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what the server actually exposes, not what its listing claims.

Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.