Atlas / MCP servers / sieteunoseis / Cisco Support

Cisco SupportCAUTION

mcp/sieteunoseis/cisco-support

Comprehensive TypeScript MCP server for Cisco Support APIs with dual transport support

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
97 95r · 2w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-cisco-support) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](https://glama.ai/mcp/servers/@sieteunoseis/mcp-cisco-support) [](https://developer.cisco.com/codeexchange/github/repo/sieteunoseis/mcp-cisco-support) [](https://ghcr.io/sieteunoseis/mcp-cisco-support) [](https://github.com/sieteunoseis/mcp-cisco-support/actions)

A production-ready TypeScript MCP (Model Context Protocol) server for Cisco Support APIs with comprehensive security and dual transport support. This extensible server provides access to multiple Cisco Support APIs including Bug Search, Case Management, and End-of-Life information.

🚀 Current Features

  • Multi-API Support: 8 Cisco Support APIs fully implemented (46 total tools)
  • OAuth 2.1 Server: ✨ Production-grade authentication with fine-grained scope-based access control
  • ElicitationRequest Support: Dynamic user interaction for gathering missing parameters
  • Triple Auth Modes: stdio (no auth), Bearer token (simple), OAuth 2.1 (production)
  • Configurable API Access: Enable only the Cisco Support APIs you have access to
  • Specialized Prompts: 9 workflow prompts for guided Cisco support scenarios
  • Dual Transport: stdio (local MCP clients) and HTTP (remote server with auth
Read from source at commit ee9e9b1714beOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-cisco-support --env AUTH_TYPE=${AUTH_TYPE} --env CISCO_CLIENT_SECRET=${CISCO_CLIENT_SECRET} --env DANGEROUSLY_OMIT_AUTH=${DANGEROUSLY_OMIT_AUTH} --env MCP_BEARER_TOKEN=${MCP_BEARER_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-cisco-support": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AUTH_TYPE": "${AUTH_TYPE}",
        "CISCO_CLIENT_SECRET": "${CISCO_CLIENT_SECRET}",
        "DANGEROUSLY_OMIT_AUTH": "${DANGEROUSLY_OMIT_AUTH}",
        "MCP_BEARER_TOKEN": "${MCP_BEARER_TOKEN}"
      }
    }
  }
}
03

Exposed tools (97)

95 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_upgrade_risk_with_airead🤖 AI-POWERED: Comprehensive AI analysis of software upgrade risks. Analyzes bug data between versions and provides detailed risk assessment with specific recommendations. Requires client with sampling support.
case_idreadSpecific case ID to investigate (optional)
categorize_bugread🤖 AI-POWERED: Analyze and categorize a bug using AI. Provides severity assessment, impact analysis, and functional category classification. Requires client with sampling support.
cisco-case-investigationreadInvestigate support cases and related information using Case API tools
cisco-eox-researchreadResearch end-of-life and end-of-sale information for specific Cisco products
cisco-high-severity-searchreadSearch for high-severity bugs (severity 3 or higher) for specific products - handles API limitation requiring separate searches. Provide either product_keyword OR serial_number (not both).
cisco-incident-investigationreadInvestigate Cisco bugs related to specific incident symptoms and errors. Provide either product OR serial_number.
cisco-interactive-searchread⚠️ EXPERIMENTAL: Interactive search with elicitation requests for missing parameters. Note: ElicitationRequest support is limited in current MCP clients (Claude Desktop uses conversational follow-ups instead). Kept for future client support.
cisco-known-issuesreadCheck for known issues in specific Cisco software releases or products. Provide either product OR serial_number.
cisco-lifecycle-planningreadResearch end-of-life information for Cisco products to plan replacements and maintenance
cisco-maintenance-prepreadPrepare for maintenance windows by identifying potential issues and bugs. Provide either product OR serial_number.
cisco-security-advisoryreadResearch security-related bugs and vulnerabilities for Cisco products. Provide either product OR serial_number.
cisco-smart-searchreadIntelligent search strategy with automatic refinement and comprehensive analysis. Uses multiple search techniques and provides web search guidance.
cisco-upgrade-planningreadResearch known issues and bugs before upgrading Cisco software or hardware. Provide either product OR serial_number.
close_smart_bonding_ticketread⚠️ EXPERIMENTAL/UNTESTED: Close a completed support ticket with diagnosis and solution. This is the final state for a ticket after resolution and customer confirmation.
compare_software_versionsreadCompare bugs, CVEs, and recommendations between two software versions on the same product. Analyzes differences in known issues, security vulnerabilities, and provides upgrade recommendations.
comprehensive_analysisreadBEST FOR DETAILED ANALYSIS: Combines bug database search with web search guidance for EoL information. Provides complete product analysis including known issues, lifecycle status, and actionable recommendations. Ideal for failover issues, configuration problems, and product reliability concerns.
contract_idreadContract ID to search cases for (optional)
current_versionreadCurrent software version (e.g.,
date_range_endreadEnd date for lifecycle search (YYYY-MM-DD)
date_range_startwriteStart date for lifecycle search (YYYY-MM-DD)
environmentreadEnvironment type (production, staging, lab)
escalate_smart_bonding_ticketread⚠️ EXPERIMENTAL/UNTESTED: Escalate a support ticket to Cisco by changing priority to
extract_product_queryread🤖 AI-POWERED: Parse natural language queries into structured bug search parameters. Extracts product IDs, versions, severity, status, and keywords from conversational queries. Requires client with sampling support.
get_all_security_advisoriesreadGet all published security advisories with optional pagination and filtering. NOTE: PSIRT API does not support searching by product series or product name directly - use severity, year, or date range filters instead.
get_bug_detailsreadGet details for up to 5 specific bug IDs
get_case_detailsreadGet detailed information for a single case ID. Returns comprehensive case information including status, severity, description, and all case attributes.
get_case_summaryreadGet case summary information for up to 30 specific case IDs. Returns brief information for multiple cases.
get_compatible_software_by_mdf_idreadGet compatible and suggested software releases for a specific MDF ID. Useful for finding upgrade paths from current software versions.
get_compatible_software_by_product_idreadGet compatible and suggested software releases for a specific product ID. Useful for finding upgrade paths from current software versions.
get_coverage_status_by_serialreadGet detailed coverage status, warranty, and product information for up to 75 serial numbers. Returns comprehensive coverage details including warranty dates, contract information, and product identifiers.
get_coverage_summary_by_instancereadGet coverage summary by instance numbers. Instance numbers are unique identifiers for devices in Cisco systems. Returns coverage information for specified instances.
get_coverage_summary_by_serialreadGet summary coverage information for up to 75 serial numbers. Returns brief coverage status and key dates. Use this for quick coverage lookups without full details.
get_eox_by_datereadGet end-of-life information for products within a specific date range based on EoX attributes (sales date, support date, etc.)
get_eox_by_product_idreadGet end-of-life information for specific product IDs (up to 20 product IDs per call)
get_eox_by_serial_numberreadGet end-of-life information for specific serial numbers (up to 20 serial numbers per call)
get_eox_by_software_releasereadGet end-of-life information for software releases (up to 20 software version/OS combinations)
get_latest_security_advisoriesreadGet the latest N security advisories
get_product_info_by_product_idsreadGet detailed product information for up to 5 product identifiers (PIDs). Returns specifications, descriptions, and technical details.
get_product_info_by_serial_numbersreadGet detailed product information for up to 5 device serial numbers. Returns specifications, orderable PIDs, and product details.
get_product_mdf_info_by_product_idsreadGet Manufacturing Data Format (MDF) information for up to 5 product identifiers. Returns detailed manufacturing specifications and data format information. Note: Only hardware products are supported.
get_rma_detailsreadGet detailed information for a specific RMA (Return Material Authorization) number. Returns comprehensive RMA details including status, return reason, product information, tracking, and associated case number.
get_rmas_by_userreadGet list of RMAs associated with a specific user ID. Returns RMAs for the specified user, by default from the last 30 days. Maximum date range is 90 days.
get_security_advisories_by_first_publishedreadGet security advisories by first published date range
get_security_advisories_by_severityreadGet all security advisories for a specific severity level. Severity levels: critical, high, medium, low, informational (NOT numeric like Bug API)
get_security_advisories_by_yearreadGet all security advisories published in a specific year
get_security_advisory_by_bug_idreadGet security advisory by Cisco bug ID
get_security_advisory_by_cvereadGet security advisory by CVE identifier (e.g., CVE-2018-0101)
get_security_advisory_by_idreadGet a specific security advisory by its advisory ID (e.g., cisco-sa-20180221-ucdm)
get_software_releases_by_mdf_idsreadGet suggested software releases (without images) for specified MDF IDs. Focuses on release versions and recommendations without image details.
get_software_releases_by_product_idsreadGet suggested software releases (without images) for specified product IDs. Focuses on release versions and recommendations without image details.
get_software_suggestions_by_mdf_idsreadGet software suggestions including recommended releases and images for specified MDF IDs. MDF IDs are Manufacturing Data Format identifiers.
get_software_suggestions_by_product_idsreadGet software suggestions including recommended releases and images for specified product IDs. Returns detailed software recommendations for planning upgrades and deployments.
include_web_guidancereadInclude web search recommendations for additional research (true/false)
initial_queryreadInitial search query (optional - if not provided, will use elicitation to gather)
issue_typereadType of issues to focus on (performance, stability, features)
maintenance_typereadType of maintenance (software upgrade, hardware replacement, configuration change)
max_severityreadHighest severity to include (1=highest, 6=lowest). Will search from 1 down to this number.
multi_severity_searchreadRECOMMENDED for multi-severity searches: Automatically searches multiple severity levels and combines results with severity breakdown counts. Use this when you need
productreadCisco product experiencing the issue (e.g.,
product_focusreadFocus area: product_ids, serial_numbers, software_releases, or date_range
product_idsreadProduct IDs to check (comma-separated, e.g.,
product_keywordreadProduct name or keyword to search for (e.g.,
product_name_resolverreadResolves product IDs to full product names and provides web search strategies. Helps convert technical product codes to searchable terms.
progressive_bug_searchreadAutomatically tries multiple search strategies, starting specific and broadening scope if needed. Handles version normalization and product ID variations.
pull_smart_bonding_ticketsread⚠️ EXPERIMENTAL/UNTESTED: Retrieve ticket updates from Cisco Smart Bonding that have not yet been pulled. Returns all new ticket updates since last pull. Requires SMART_BONDING_CLIENT_ID and SMART_BONDING_CLIENT_SECRET environment variables (contact Cisco Account Manager to obtain).
resolve_product_nameread🤖 AI-POWERED: Resolve natural language product descriptions to Cisco product IDs. Converts friendly names like
resolve_smart_bonding_ticketread⚠️ EXPERIMENTAL/UNTESTED: Mark a support ticket as
search_bugs_by_keywordreadSearch for bugs using keywords in descriptions and headlines. Use this when searching by general terms, symptoms, or when product-specific tools are not applicable. IMPORTANT: severity parameter returns ONLY that specific level. For
search_bugs_by_product_and_releasereadSearch bugs by specific product ID and software releases. CRITICAL: Use
search_bugs_by_product_idreadSearch bugs by specific base product ID (e.g., C9200-24P). Use when you have an exact Cisco product ID. For general product searches by name, consider using keyword search instead.
search_bugs_by_product_name_affectedreadSearch bugs by full product name and affected releases. NOTE: Requires FULL descriptive product names (like
search_bugs_by_product_name_fixedreadSearch bugs by full product name and fixed releases. NOTE: Requires FULL descriptive product names (like
search_bugs_by_product_series_affectedreadSearch bugs by product series and affected releases. This endpoint accepts full product series names like
search_bugs_by_product_series_fixedreadSearch bugs by product series and fixed releases. This endpoint accepts full product series names like
search_cases_by_contractreadSearch for cases associated with specific contract IDs (max 10). Returns cases linked to the specified contracts.
search_cases_by_userreadSearch for cases associated with specific user IDs (max 10). Returns cases owned by or involving the specified users.
search_contextreadContext for the search to optimize strategy
search_queryreadWhat you want to search for (e.g.,
search_rmas_by_serialreadSearch for RMAs associated with specific serial numbers. Returns RMA history for devices identified by their serial numbers.
search_valuesreadValues to search for (product IDs, serial numbers, or software releases)
security_focusreadSpecific security concern (CVE, vulnerability type, etc.)
serial_numberreadSerial number to look up product information (e.g.,
serial_numbersreadSerial numbers to check (comma-separated)
severityreadIncident severity level (1=Critical, 2=High, 3=Medium)
smart_search_strategyreadAnalyzes search queries and suggests optimal search approaches based on input patterns. Provides strategic guidance for finding bugs effectively.
software_versionreadCurrent software version if known (e.g.,
statusreadCase status to filter by (Open, Closed, etc.)
summarize_bugs_with_airead🤖 AI-POWERED: Generate natural language summaries of bug search results. Highlights critical issues, severity distribution, and actionable recommendations. Requires client with sampling support.
symptomreadThe error message, symptom, or behavior observed during the incident
target_versionreadTarget upgrade version (e.g.,
test_toolreadTest tool
timelinereadMaintenance window timeline (e.g.,
update_smart_bonding_ticketwrite⚠️ EXPERIMENTAL/UNTESTED: Update an existing support ticket with work notes and status changes. Use this to add updates, notes, or modify ticket information.
use_elicitationreadWhether to use elicitation to gather additional search parameters (true/false)
user_idreadUser ID to search cases for (optional)
versionreadProduct version if applicable (e.g.,
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/sse-server.ts:117
console.log(`🔑 Bearer token: ${authToken}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/sse-server.ts:129
console.log(`   (Query parameter also supported: ?token=${authToken})`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/sse-server.ts:134
console.log(`   Token Endpoint: ${oauth2Config.issuerUrl}/token`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/sse-server.ts:155
console.log(`🌐 MCP Server is up and running at http://127.0.0.1:${port} 🚀`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/index.ts:15
join(__dirname, '../../package.json'), // When compiled to dist/src/
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server.ts:67
join(__dirname, "../../package.json"), // When compiled to dist/src/
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @blackwell-systems/gcf, cors, dotenv, express, helmet, morgan, uuid
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:694
curl -X POST http://localhost:3000/token \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:712
curl -X POST http://localhost:3000/token \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CLAUDE.md:722
- `POST /token` - Token endpoint
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:709
- `POST /token` - Token endpoint (PKCE required)
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:803
| `/sse/session/{sessionId}` | POST | Session-specific MCP message endpoint |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
CLAUDE.md:1105
# Administrator - Full access
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:676
| `mcp` | All APIs | Full access to all MCP tools |
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH_CLIENTS_CONFIG.md:89
| `mcp` | **All APIs** | Full access to all MCP tools and APIs (default) |
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/OAUTH_CLIENTS_CONFIG.md:102
**Full access (default)**:
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/archive/OAUTH_2.1_IMPLEMENTATION_SUMMARY.md:21
- `mcp` - Full access to all APIs (default)
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/OAUTH_CLIENTS_CONFIG.md:144
- API access is controlled by the `SUPPORT_API` environment variable
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/archive/OAUTH2_AUTHENTICATION.md:1214
# Get access token using client credentials
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/CISCO_COOKIE_ANALYSIS.md:257
# Add to crontab
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ee9e9b1714befull audit observations/trust-audit/mcp-server/sieteunoseis__cisco-support.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ee9e9b1714beCAUTIONB87first audit
06

Questions

What is the Cisco Support MCP server?

Comprehensive TypeScript MCP server for Cisco Support APIs with dual transport support

What tools does Cisco Support expose?

97 in total: 95 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Cisco Support safe to connect to an agent?

With care. The audit graded it B (87/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Cisco Support need?

It reads AUTH_TYPE, CISCO_CLIENT_SECRET, DANGEROUSLY_OMIT_AUTH, MCP_BEARER_TOKEN, OAUTH2_ALLOW_DYNAMIC_REGISTRATION, OAUTH2_ISSUER_URL, OAUTH_CLIENTS_CONFIG and OAUTH_SECRETS_CONFIG from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Cisco Support run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-cisco-support at 1.18.0.

How current is this page?

The grade is for one exact copy of the source (ee9e9b1714be), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement