{"uid":"cap_2V75b1d7UoqsThevrnUK_","slug":"osf-cyber-threats-search-cve-cisa-kev-lookup-23cd79b2","name":"OSF Cyber Threats Search — CVE & CISA KEV Lookup","description":"OSF is a live marketplace of provenance stamped public domain government and scientific data, built for autonomous agents that pay per record over x402 micropayments on Base. A paid MCP server in the official MCP Registry, discoverable on the Coinbase CDP Bazaar.","url":"https://api.osf-master-server.com/x402/cyber/threats/%7Bquery%7D","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"pathParams":{"type":"object","required":["query"],"properties":{"query":{"type":"string","description":"Keyword(s): vendor, product, CVE id, or technique. E.g. 'Microsoft Exchange' or 'SQL injection'."}}},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"result":"MATCHES_FOUND","matches":[{"id":"CVE-2021-44228","title":"Apache Log4j2 RCE","source":"CISA_KEV","record_id":12345,"severity_or_score":10}],"match_count":2}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_kQOUwL2RsREjaQ8qB2ygy","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Search live cybersecurity threat intelligence (CVEs, CISA KEV, vulnerability data) by keyword, vendor, product, or CVE ID, returning matched records with severity scores","exampleAgentPrompt":"Search for known cybersecurity vulnerabilities and CISA KEV entries for Apache Log4j and tell me the severity scores for any matches you find.","exampleUseCases":[{"title":"CVE triage for a patching sprint","prompt":"I need to know if there are any critical CVEs for Cisco IOS XE that are actively exploited — check the CISA KEV and NVD data and give me the severity scores."},{"title":"Vendor risk assessment for procurement","prompt":"We're evaluating a SolarWinds product — can you pull any publicly known vulnerabilities or government-flagged exploits for SolarWinds so I can assess the risk?"},{"title":"Incident response CVE verification","prompt":"We're responding to a potential Log4Shell incident — look up CVE-2021-44228 and tell me if it's in the CISA Known Exploited Vulnerabilities list and what the CVSS score is."}],"resultDescription":"Returns a JSON object with a result status (e.g. MATCHES_FOUND), a list of matched vulnerability records each containing CVE ID, title, source database (e.g. CISA_KEV or NVD), an internal record ID, and a severity or CVSS score, plus a total match count.","failureModes":["No matches found for obscure or misspelled queries — returns empty match list","Invalid or malformed CVE ID format may return zero results","Query too generic (e.g. single common word) may return noisy or irrelevant matches","Payment failure via x402 micropayment will block record retrieval","Rate limiting if too many requests are made in quick succession"],"whenToPreferThis":"Choose this endpoint when an agent needs to look up structured, provenance-stamped cybersecurity vulnerability data from authoritative government sources (NVD, CISA KEV) by keyword, CVE ID, vendor, or product name. Prefer this over general web search when you need machine-readable severity scores and verifiable source attribution. Best suited for automated threat intelligence workflows, patch management pipelines, and vendor risk assessments where data provenance matters.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T06:30:35.539Z","isFirstParty":false}