MCP Tools Reference
Fleet’s MCP server exposes 58 tools that let AI assistants and agents drive Fleet directly — query CRA compliance, run assessments, manage distribution, prepare ENISA notifications, check threat intelligence, and talk to the AI advisor. They group into nine areas:
| Area | Tools | Examples |
|---|---|---|
| Assessment | 11 | fleet_list_assessed_products, fleet_get_gap_analysis, fleet_list_scans, fleet_list_findings, fleet_list_rulesets, fleet_ingest_sbom, fleet_ingest_source |
| AI Advisor | 6 | fleet_advisor_chat, fleet_advisor_chat_sessions_list, fleet_advisor_artefacts_list, fleet_advisor_save_artefact |
| Distribution | 7 | fleet_create_app, fleet_create_release, fleet_publish_release, fleet_upload_asset, fleet_check_update |
| Licensing | 3 | fleet_create_license, fleet_activate_license, fleet_revoke_license |
| Administration | 6 | fleet_create_org, fleet_create_api_key, fleet_list_scopes, fleet_get_instance_config, fleet_set_instance_config |
| Documentation | 3 | fleet_docs_search, fleet_docs_list_topics, fleet_docs_get_topic |
| Cybersec threat-intel | 7 | cybersec_check_cve, cybersec_audit_dependency, cybersec_search_threats, cybersec_lookup_actor, cybersec_lookup_technique |
| ENISA Reporting | 9 | fleet_enisa_create_notification, fleet_enisa_submit_revision, fleet_enisa_edit_draft, fleet_enisa_promote_draft, fleet_enisa_export |
| Vulnerability Monitoring | 6 | fleet_list_vuln_findings, fleet_ingest_vex, fleet_emit_vex, fleet_set_finding_vex, fleet_edit_vex_draft, fleet_apply_vex_draft |
The core assessment tools are documented in detail below. The ENISA Reporting
tools drive the ENISA Single Reporting Platform — create a
case, submit staged 24h/72h/final revisions against the
obligation matrix, and export the form-ready
report. Over HTTP they require the enisa:read / enisa:write scopes (mint a
key with the right scope; discover the catalogue with fleet_list_scopes).
Delivery of the exported report is covered in
Notifications & Report Delivery.
fleet_list_assessed_products
Section titled “fleet_list_assessed_products”List all products under CRA assessment.
Input: None
Output: JSON array of assessed products with id, name, version, ruleset_id.
fleet_get_gap_analysis
Section titled “fleet_get_gap_analysis”Get compliance gap analysis for a product.
Input:
{ "product_id": "uuid" }Output: Compliance percentage, status breakdown (not_started/in_progress/needs_evidence/compliant/non_compliant/not_applicable), and list of gaps.
fleet_list_scans
Section titled “fleet_list_scans”List scan history for a product.
Input:
{ "product_id": "uuid" }Output: Array of scans with id, commit_sha, status, summary, timestamps.
fleet_list_findings
Section titled “fleet_list_findings”List findings from a specific scan.
Input:
{ "scan_id": "uuid" }Output: Array of findings with requirement_id, risk_id, status, confidence, detector, message, source_locations.
fleet_list_rulesets
Section titled “fleet_list_rulesets”List available CRA compliance rulesets.
Input: None
Output: Array of rulesets with id, name, version, status, catalog stats.
fleet_enisa_get_draft / fleet_enisa_edit_draft / fleet_enisa_promote_draft
Section titled “fleet_enisa_get_draft / fleet_enisa_edit_draft / fleet_enisa_promote_draft”Read, edit, and promote a mutable report draft (see ENISA Reporting).
edit_draft creates the draft if absent (seed: true pre-fills from the latest
revision) and shallow-merges a patch; promote_draft validates and writes an
immutable revision.
Input (edit):
{ "notification_id": "uuid", "seed": false, "patch": { "title": "RCE", "stage": "update_72h" } }Vulnerability Monitoring tools
Section titled “Vulnerability Monitoring tools”Drive continuous vulnerability awareness for a product. See
Vulnerability Monitoring for the full feature; running a
pass is done via POST /api/v1/monitor/products/{id}/run or the scheduler.
fleet_list_vuln_findings
Section titled “fleet_list_vuln_findings”List stored findings for a product (vuln id, severity, CVSS, exploited flag, EUVD id, VEX status, open/resolved state).
Input:
{ "product_id": "uuid" }fleet_ingest_vex
Section titled “fleet_ingest_vex”Ingest a VEX document (OpenVEX or CycloneDX-VEX) to triage findings.
Input:
{ "product_id": "uuid", "document": { "@context": "https://openvex.dev/ns/v0.2.0", "statements": [] } }document may be a JSON object or a string.
Output: { "format": "openvex", "statements": N, "applied": M }.
fleet_emit_vex
Section titled “fleet_emit_vex”Emit the product’s findings as a VEX document.
Input:
{ "product_id": "uuid", "format": "openvex" }format is openvex (default) or cyclonedx.
fleet_set_finding_vex
Section titled “fleet_set_finding_vex”Set the VEX triage on a single finding.
Input:
{ "finding_id": "uuid", "status": "not_affected", "justification": "not reachable" }status: unknown / not_affected / affected / fixed / under_investigation.
fleet_edit_vex_draft
Section titled “fleet_edit_vex_draft”Create or replace a product’s editable VEX draft (provide document, or seed: true
to start from current findings).
Input:
{ "product_id": "uuid", "document": { "@context": "https://openvex.dev/ns/v0.2.0", "statements": [] } }fleet_apply_vex_draft
Section titled “fleet_apply_vex_draft”Apply the product’s VEX draft — ingest its statements onto findings.
Input:
{ "product_id": "uuid" }