Skip to content

MCP Tools Reference

Fleet’s MCP server exposes 58 tools that let AI assistants and agents drive Fleet directly — query CRA compliance, run assessments, manage distribution, prepare ENISA notifications, check threat intelligence, and talk to the AI advisor. They group into nine areas:

Area Tools Examples
Assessment 11 fleet_list_assessed_products, fleet_get_gap_analysis, fleet_list_scans, fleet_list_findings, fleet_list_rulesets, fleet_ingest_sbom, fleet_ingest_source
AI Advisor 6 fleet_advisor_chat, fleet_advisor_chat_sessions_list, fleet_advisor_artefacts_list, fleet_advisor_save_artefact
Distribution 7 fleet_create_app, fleet_create_release, fleet_publish_release, fleet_upload_asset, fleet_check_update
Licensing 3 fleet_create_license, fleet_activate_license, fleet_revoke_license
Administration 6 fleet_create_org, fleet_create_api_key, fleet_list_scopes, fleet_get_instance_config, fleet_set_instance_config
Documentation 3 fleet_docs_search, fleet_docs_list_topics, fleet_docs_get_topic
Cybersec threat-intel 7 cybersec_check_cve, cybersec_audit_dependency, cybersec_search_threats, cybersec_lookup_actor, cybersec_lookup_technique
ENISA Reporting 9 fleet_enisa_create_notification, fleet_enisa_submit_revision, fleet_enisa_edit_draft, fleet_enisa_promote_draft, fleet_enisa_export
Vulnerability Monitoring 6 fleet_list_vuln_findings, fleet_ingest_vex, fleet_emit_vex, fleet_set_finding_vex, fleet_edit_vex_draft, fleet_apply_vex_draft

The core assessment tools are documented in detail below. The ENISA Reporting tools drive the ENISA Single Reporting Platform — create a case, submit staged 24h/72h/final revisions against the obligation matrix, and export the form-ready report. Over HTTP they require the enisa:read / enisa:write scopes (mint a key with the right scope; discover the catalogue with fleet_list_scopes). Delivery of the exported report is covered in Notifications & Report Delivery.

List all products under CRA assessment.

Input: None

Output: JSON array of assessed products with id, name, version, ruleset_id.

Get compliance gap analysis for a product.

Input:

{ "product_id": "uuid" }

Output: Compliance percentage, status breakdown (not_started/in_progress/needs_evidence/compliant/non_compliant/not_applicable), and list of gaps.

List scan history for a product.

Input:

{ "product_id": "uuid" }

Output: Array of scans with id, commit_sha, status, summary, timestamps.

List findings from a specific scan.

Input:

{ "scan_id": "uuid" }

Output: Array of findings with requirement_id, risk_id, status, confidence, detector, message, source_locations.

List available CRA compliance rulesets.

Input: None

Output: Array of rulesets with id, name, version, status, catalog stats.

fleet_enisa_get_draft / fleet_enisa_edit_draft / fleet_enisa_promote_draft

Section titled “fleet_enisa_get_draft / fleet_enisa_edit_draft / fleet_enisa_promote_draft”

Read, edit, and promote a mutable report draft (see ENISA Reporting). edit_draft creates the draft if absent (seed: true pre-fills from the latest revision) and shallow-merges a patch; promote_draft validates and writes an immutable revision.

Input (edit):

{ "notification_id": "uuid", "seed": false, "patch": { "title": "RCE", "stage": "update_72h" } }

Drive continuous vulnerability awareness for a product. See Vulnerability Monitoring for the full feature; running a pass is done via POST /api/v1/monitor/products/{id}/run or the scheduler.

List stored findings for a product (vuln id, severity, CVSS, exploited flag, EUVD id, VEX status, open/resolved state).

Input:

{ "product_id": "uuid" }

Ingest a VEX document (OpenVEX or CycloneDX-VEX) to triage findings.

Input:

{ "product_id": "uuid", "document": { "@context": "https://openvex.dev/ns/v0.2.0", "statements": [] } }

document may be a JSON object or a string.

Output: { "format": "openvex", "statements": N, "applied": M }.

Emit the product’s findings as a VEX document.

Input:

{ "product_id": "uuid", "format": "openvex" }

format is openvex (default) or cyclonedx.

Set the VEX triage on a single finding.

Input:

{ "finding_id": "uuid", "status": "not_affected", "justification": "not reachable" }

status: unknown / not_affected / affected / fixed / under_investigation.

Create or replace a product’s editable VEX draft (provide document, or seed: true to start from current findings).

Input:

{ "product_id": "uuid", "document": { "@context": "https://openvex.dev/ns/v0.2.0", "statements": [] } }

Apply the product’s VEX draft — ingest its statements onto findings.

Input:

{ "product_id": "uuid" }