Skip to content
mcp/skillhub

Cisa Cybersecurity MCP Server

by cyanheadsio.github.cyanheads/cisa-cybersecurity-mcp-serverv0.3.0

CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.

1Node.jsstdioremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active14d ago

Install Cisa Cybersecurity MCP server

Install in Claude Code

claude mcp add cisa-cybersecurity -- npx -y @cyanheads/cisa-cybersecurity-mcp-server run start:stdio

Configuration

VariableRequiredSecretDescription
MCP_LOG_LEVEL——Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').
CISA_KEV_REFRESH_CRON——Cron expression for the KEV catalog conditional-refresh poll, on every transport. Set off to disable it; an invalid expression fails startup.
CISA_CSAF_MIRROR_PATH——Filesystem path to the local SQLite index of ICS advisories. Unset, it is csaf.sqlite3 under cisa-cybersecurity-mcp-server in the per-user cache directory: ~/Library/Caches on macOS, $XDG_CACHE_HOME or ~/.cache on Linux, %LOCALAPPDATA% on Windows.
CISA_CSAF_MIRROR_AUTO_INIT——Seed the ICS advisory index in the background at startup when it has never completed a sync, and re-ingest it in place when an older server version built it. Accepts true or false; set false where seeding runs out of band.
CISA_CSAF_REFRESH_CRON——Cron expression for the incremental ICS advisory refresh, on every transport; the refresh also runs once at startup. Set off to disable both; an invalid expression fails startup.
CISA_VULNRICHMENT_CACHE_TTL_SECONDS——Seconds a fetched SSVC record stays cached. Negative results use one sixth of this value.
CISA_FEED_CACHE_TTL_SECONDS——Seconds a parsed RSS feed window stays cached.
CISA_HTTP_TIMEOUT_MS——Per-request timeout in milliseconds for every upstream fetch.
MCP_HTTP_HOST——The hostname for the HTTP server.
MCP_HTTP_PORT——The port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATH——The endpoint path for the MCP server.
MCP_AUTH_MODE——Authentication mode to use: 'none', 'jwt', or 'oauth'.

Remote endpoints

  • streamable-httphttps://cisa-cybersecurity.caseyjhand.com/mcp

Freshness

Active — last maintenance signal 14d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-25 · 14d ago · GitHub

  2. Latest release

    2026-09-25 · 14d ago · GitHub · v0.3.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-25 · 14d ago · official registry · v0.3.0

FAQ

›How do I install the Cisa Cybersecurity MCP server in Claude Code?

Run: claude mcp add cisa-cybersecurity -- npx -y @cyanheads/cisa-cybersecurity-mcp-server run start:stdio. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Cisa Cybersecurity require an API key?

No required environment variables are declared in its published metadata.

›Can I use Cisa Cybersecurity as a remote (hosted) MCP server?

Yes — it offers both a hosted endpoint and a local stdio package.

›Is Cisa Cybersecurity in the official MCP registry?

Yes, as io.github.cyanheads/cisa-cybersecurity-mcp-server.