the recordCopied from the official MCP registry, exactly as it holds it.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.cyanheads/nist-nvd-mcp-server",
"description": "Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.",
"repository": {
"url": "https://github.com/cyanheads/nist-nvd-mcp-server",
"source": "github"
},
"version": "0.2.0",
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/nist-nvd-mcp-server",
"version": "0.2.0",
"runtimeHint": "bun",
"transport": {
"type": "stdio"
},
"packageArguments": [
{
"value": "run",
"type": "positional"
},
{
"value": "start:stdio",
"type": "positional"
}
],
"environmentVariables": [
{
"description": "NVD API key. Without it, rate limit is 5 req/30s; with it, 50 req/30s. Get one free at nvd.nist.gov/developers/request-an-api-key.",
"format": "string",
"name": "NVD_API_KEY"
},
{
"description": "Per-request timeout in milliseconds. Raise to 60000 when using nvd_get_cve_history without an API key.",
"format": "string",
"default": "10000",
"name": "NVD_REQUEST_TIMEOUT_MS"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
},
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/nist-nvd-mcp-server",
"version": "0.2.0",
"runtimeHint": "bun",
"transport": {
"type": "streamable-http",
"url": "http://localhost:3010/mcp"
},
"packageArguments": [
{
"value": "run",
"type": "positional"
},
{
"value": "start:http",
"type": "positional"
}
],
"environmentVariables": [
{
"description": "NVD API key. Without it, rate limit is 5 req/30s; with it, 50 req/30s. Get one free at nvd.nist.gov/developers/request-an-api-key.",
"format": "string",
"name": "NVD_API_KEY"
},
{
"description": "Per-request timeout in milliseconds. Raise to 60000 when using nvd_get_cve_history without an API key.",
"format": "string",
"default": "10000",
"name": "NVD_REQUEST_TIMEOUT_MS"
},
{
"description": "The hostname for the HTTP server.",
"format": "string",
"default": "127.0.0.1",
"name": "MCP_HTTP_HOST"
},
{
"description": "The port to run the HTTP server on.",
"format": "string",
"default": "3010",
"name": "MCP_HTTP_PORT"
},
{
"description": "The endpoint path for the MCP server.",
"format": "string",
"default": "/mcp",
"name": "MCP_HTTP_ENDPOINT_PATH"
},
{
"description": "Authentication mode to use: 'none', 'jwt', or 'oauth'.",
"format": "string",
"default": "none",
"name": "MCP_AUTH_MODE"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
}
]
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-07-31T10:34:36.316716Z",
"publishedAt": "2026-07-31T10:34:36.316716Z",
"updatedAt": "2026-07-31T10:34:36.316716Z",
"isLatest": true
}
}
}
Make it installable
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
What this is
MCP server
application/mcp-server-record+jsonlocal · you run it yourselfversion 0.2.0last seen 2026-08-23
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.