Cisco SupportCAUTION
Comprehensive TypeScript MCP server for Cisco Support APIs with dual transport support
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mcp-cisco-support) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](https://glama.ai/mcp/servers/@sieteunoseis/mcp-cisco-support) [](https://developer.cisco.com/codeexchange/github/repo/sieteunoseis/mcp-cisco-support) [](https://ghcr.io/sieteunoseis/mcp-cisco-support) [](https://github.com/sieteunoseis/mcp-cisco-support/actions)
A production-ready TypeScript MCP (Model Context Protocol) server for Cisco Support APIs with comprehensive security and dual transport support. This extensible server provides access to multiple Cisco Support APIs including Bug Search, Case Management, and End-of-Life information.
🚀 Current Features
- Multi-API Support: 8 Cisco Support APIs fully implemented (46 total tools)
- OAuth 2.1 Server: ✨ Production-grade authentication with fine-grained scope-based access control
- ElicitationRequest Support: Dynamic user interaction for gathering missing parameters
- Triple Auth Modes: stdio (no auth), Bearer token (simple), OAuth 2.1 (production)
- Configurable API Access: Enable only the Cisco Support APIs you have access to
- Specialized Prompts: 9 workflow prompts for guided Cisco support scenarios
- Dual Transport: stdio (local MCP clients) and HTTP (remote server with auth
ee9e9b1714beOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-cisco-support --env AUTH_TYPE=${AUTH_TYPE} --env CISCO_CLIENT_SECRET=${CISCO_CLIENT_SECRET} --env DANGEROUSLY_OMIT_AUTH=${DANGEROUSLY_OMIT_AUTH} --env MCP_BEARER_TOKEN=${MCP_BEARER_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-cisco-support": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AUTH_TYPE": "${AUTH_TYPE}",
"CISCO_CLIENT_SECRET": "${CISCO_CLIENT_SECRET}",
"DANGEROUSLY_OMIT_AUTH": "${DANGEROUSLY_OMIT_AUTH}",
"MCP_BEARER_TOKEN": "${MCP_BEARER_TOKEN}"
}
}
}
}Exposed tools (97)
95 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_upgrade_risk_with_ai | read | 🤖 AI-POWERED: Comprehensive AI analysis of software upgrade risks. Analyzes bug data between versions and provides detailed risk assessment with specific recommendations. Requires client with sampling support. |
case_id | read | Specific case ID to investigate (optional) |
categorize_bug | read | 🤖 AI-POWERED: Analyze and categorize a bug using AI. Provides severity assessment, impact analysis, and functional category classification. Requires client with sampling support. |
cisco-case-investigation | read | Investigate support cases and related information using Case API tools |
cisco-eox-research | read | Research end-of-life and end-of-sale information for specific Cisco products |
cisco-high-severity-search | read | Search for high-severity bugs (severity 3 or higher) for specific products - handles API limitation requiring separate searches. Provide either product_keyword OR serial_number (not both). |
cisco-incident-investigation | read | Investigate Cisco bugs related to specific incident symptoms and errors. Provide either product OR serial_number. |
cisco-interactive-search | read | ⚠️ EXPERIMENTAL: Interactive search with elicitation requests for missing parameters. Note: ElicitationRequest support is limited in current MCP clients (Claude Desktop uses conversational follow-ups instead). Kept for future client support. |
cisco-known-issues | read | Check for known issues in specific Cisco software releases or products. Provide either product OR serial_number. |
cisco-lifecycle-planning | read | Research end-of-life information for Cisco products to plan replacements and maintenance |
cisco-maintenance-prep | read | Prepare for maintenance windows by identifying potential issues and bugs. Provide either product OR serial_number. |
cisco-security-advisory | read | Research security-related bugs and vulnerabilities for Cisco products. Provide either product OR serial_number. |
cisco-smart-search | read | Intelligent search strategy with automatic refinement and comprehensive analysis. Uses multiple search techniques and provides web search guidance. |
cisco-upgrade-planning | read | Research known issues and bugs before upgrading Cisco software or hardware. Provide either product OR serial_number. |
close_smart_bonding_ticket | read | ⚠️ EXPERIMENTAL/UNTESTED: Close a completed support ticket with diagnosis and solution. This is the final state for a ticket after resolution and customer confirmation. |
compare_software_versions | read | Compare bugs, CVEs, and recommendations between two software versions on the same product. Analyzes differences in known issues, security vulnerabilities, and provides upgrade recommendations. |
comprehensive_analysis | read | BEST FOR DETAILED ANALYSIS: Combines bug database search with web search guidance for EoL information. Provides complete product analysis including known issues, lifecycle status, and actionable recommendations. Ideal for failover issues, configuration problems, and product reliability concerns. |
contract_id | read | Contract ID to search cases for (optional) |
current_version | read | Current software version (e.g., |
date_range_end | read | End date for lifecycle search (YYYY-MM-DD) |
date_range_start | write | Start date for lifecycle search (YYYY-MM-DD) |
environment | read | Environment type (production, staging, lab) |
escalate_smart_bonding_ticket | read | ⚠️ EXPERIMENTAL/UNTESTED: Escalate a support ticket to Cisco by changing priority to |
extract_product_query | read | 🤖 AI-POWERED: Parse natural language queries into structured bug search parameters. Extracts product IDs, versions, severity, status, and keywords from conversational queries. Requires client with sampling support. |
get_all_security_advisories | read | Get all published security advisories with optional pagination and filtering. NOTE: PSIRT API does not support searching by product series or product name directly - use severity, year, or date range filters instead. |
get_bug_details | read | Get details for up to 5 specific bug IDs |
get_case_details | read | Get detailed information for a single case ID. Returns comprehensive case information including status, severity, description, and all case attributes. |
get_case_summary | read | Get case summary information for up to 30 specific case IDs. Returns brief information for multiple cases. |
get_compatible_software_by_mdf_id | read | Get compatible and suggested software releases for a specific MDF ID. Useful for finding upgrade paths from current software versions. |
get_compatible_software_by_product_id | read | Get compatible and suggested software releases for a specific product ID. Useful for finding upgrade paths from current software versions. |
get_coverage_status_by_serial | read | Get detailed coverage status, warranty, and product information for up to 75 serial numbers. Returns comprehensive coverage details including warranty dates, contract information, and product identifiers. |
get_coverage_summary_by_instance | read | Get coverage summary by instance numbers. Instance numbers are unique identifiers for devices in Cisco systems. Returns coverage information for specified instances. |
get_coverage_summary_by_serial | read | Get summary coverage information for up to 75 serial numbers. Returns brief coverage status and key dates. Use this for quick coverage lookups without full details. |
get_eox_by_date | read | Get end-of-life information for products within a specific date range based on EoX attributes (sales date, support date, etc.) |
get_eox_by_product_id | read | Get end-of-life information for specific product IDs (up to 20 product IDs per call) |
get_eox_by_serial_number | read | Get end-of-life information for specific serial numbers (up to 20 serial numbers per call) |
get_eox_by_software_release | read | Get end-of-life information for software releases (up to 20 software version/OS combinations) |
get_latest_security_advisories | read | Get the latest N security advisories |
get_product_info_by_product_ids | read | Get detailed product information for up to 5 product identifiers (PIDs). Returns specifications, descriptions, and technical details. |
get_product_info_by_serial_numbers | read | Get detailed product information for up to 5 device serial numbers. Returns specifications, orderable PIDs, and product details. |
get_product_mdf_info_by_product_ids | read | Get Manufacturing Data Format (MDF) information for up to 5 product identifiers. Returns detailed manufacturing specifications and data format information. Note: Only hardware products are supported. |
get_rma_details | read | Get detailed information for a specific RMA (Return Material Authorization) number. Returns comprehensive RMA details including status, return reason, product information, tracking, and associated case number. |
get_rmas_by_user | read | Get list of RMAs associated with a specific user ID. Returns RMAs for the specified user, by default from the last 30 days. Maximum date range is 90 days. |
get_security_advisories_by_first_published | read | Get security advisories by first published date range |
get_security_advisories_by_severity | read | Get all security advisories for a specific severity level. Severity levels: critical, high, medium, low, informational (NOT numeric like Bug API) |
get_security_advisories_by_year | read | Get all security advisories published in a specific year |
get_security_advisory_by_bug_id | read | Get security advisory by Cisco bug ID |
get_security_advisory_by_cve | read | Get security advisory by CVE identifier (e.g., CVE-2018-0101) |
get_security_advisory_by_id | read | Get a specific security advisory by its advisory ID (e.g., cisco-sa-20180221-ucdm) |
get_software_releases_by_mdf_ids | read | Get suggested software releases (without images) for specified MDF IDs. Focuses on release versions and recommendations without image details. |
get_software_releases_by_product_ids | read | Get suggested software releases (without images) for specified product IDs. Focuses on release versions and recommendations without image details. |
get_software_suggestions_by_mdf_ids | read | Get software suggestions including recommended releases and images for specified MDF IDs. MDF IDs are Manufacturing Data Format identifiers. |
get_software_suggestions_by_product_ids | read | Get software suggestions including recommended releases and images for specified product IDs. Returns detailed software recommendations for planning upgrades and deployments. |
include_web_guidance | read | Include web search recommendations for additional research (true/false) |
initial_query | read | Initial search query (optional - if not provided, will use elicitation to gather) |
issue_type | read | Type of issues to focus on (performance, stability, features) |
maintenance_type | read | Type of maintenance (software upgrade, hardware replacement, configuration change) |
max_severity | read | Highest severity to include (1=highest, 6=lowest). Will search from 1 down to this number. |
multi_severity_search | read | RECOMMENDED for multi-severity searches: Automatically searches multiple severity levels and combines results with severity breakdown counts. Use this when you need |
product | read | Cisco product experiencing the issue (e.g., |
product_focus | read | Focus area: product_ids, serial_numbers, software_releases, or date_range |
product_ids | read | Product IDs to check (comma-separated, e.g., |
product_keyword | read | Product name or keyword to search for (e.g., |
product_name_resolver | read | Resolves product IDs to full product names and provides web search strategies. Helps convert technical product codes to searchable terms. |
progressive_bug_search | read | Automatically tries multiple search strategies, starting specific and broadening scope if needed. Handles version normalization and product ID variations. |
pull_smart_bonding_tickets | read | ⚠️ EXPERIMENTAL/UNTESTED: Retrieve ticket updates from Cisco Smart Bonding that have not yet been pulled. Returns all new ticket updates since last pull. Requires SMART_BONDING_CLIENT_ID and SMART_BONDING_CLIENT_SECRET environment variables (contact Cisco Account Manager to obtain). |
resolve_product_name | read | 🤖 AI-POWERED: Resolve natural language product descriptions to Cisco product IDs. Converts friendly names like |
resolve_smart_bonding_ticket | read | ⚠️ EXPERIMENTAL/UNTESTED: Mark a support ticket as |
search_bugs_by_keyword | read | Search for bugs using keywords in descriptions and headlines. Use this when searching by general terms, symptoms, or when product-specific tools are not applicable. IMPORTANT: severity parameter returns ONLY that specific level. For |
search_bugs_by_product_and_release | read | Search bugs by specific product ID and software releases. CRITICAL: Use |
search_bugs_by_product_id | read | Search bugs by specific base product ID (e.g., C9200-24P). Use when you have an exact Cisco product ID. For general product searches by name, consider using keyword search instead. |
search_bugs_by_product_name_affected | read | Search bugs by full product name and affected releases. NOTE: Requires FULL descriptive product names (like |
search_bugs_by_product_name_fixed | read | Search bugs by full product name and fixed releases. NOTE: Requires FULL descriptive product names (like |
search_bugs_by_product_series_affected | read | Search bugs by product series and affected releases. This endpoint accepts full product series names like |
search_bugs_by_product_series_fixed | read | Search bugs by product series and fixed releases. This endpoint accepts full product series names like |
search_cases_by_contract | read | Search for cases associated with specific contract IDs (max 10). Returns cases linked to the specified contracts. |
search_cases_by_user | read | Search for cases associated with specific user IDs (max 10). Returns cases owned by or involving the specified users. |
search_context | read | Context for the search to optimize strategy |
search_query | read | What you want to search for (e.g., |
search_rmas_by_serial | read | Search for RMAs associated with specific serial numbers. Returns RMA history for devices identified by their serial numbers. |
search_values | read | Values to search for (product IDs, serial numbers, or software releases) |
security_focus | read | Specific security concern (CVE, vulnerability type, etc.) |
serial_number | read | Serial number to look up product information (e.g., |
serial_numbers | read | Serial numbers to check (comma-separated) |
severity | read | Incident severity level (1=Critical, 2=High, 3=Medium) |
smart_search_strategy | read | Analyzes search queries and suggests optimal search approaches based on input patterns. Provides strategic guidance for finding bugs effectively. |
software_version | read | Current software version if known (e.g., |
status | read | Case status to filter by (Open, Closed, etc.) |
summarize_bugs_with_ai | read | 🤖 AI-POWERED: Generate natural language summaries of bug search results. Highlights critical issues, severity distribution, and actionable recommendations. Requires client with sampling support. |
symptom | read | The error message, symptom, or behavior observed during the incident |
target_version | read | Target upgrade version (e.g., |
test_tool | read | Test tool |
timeline | read | Maintenance window timeline (e.g., |
update_smart_bonding_ticket | write | ⚠️ EXPERIMENTAL/UNTESTED: Update an existing support ticket with work notes and status changes. Use this to add updates, notes, or modify ticket information. |
use_elicitation | read | Whether to use elicitation to gather additional search parameters (true/false) |
user_id | read | User ID to search cases for (optional) |
version | read | Product version if applicable (e.g., |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
console.log(`🔑 Bearer token: ${authToken}`);console.log(` (Query parameter also supported: ?token=${authToken})`);console.log(` Token Endpoint: ${oauth2Config.issuerUrl}/token`);console.log(`🌐 MCP Server is up and running at http://127.0.0.1:${port} 🚀`);join(__dirname, '../../package.json'), // When compiled to dist/src/
join(__dirname, "../../package.json"), // When compiled to dist/src/
@modelcontextprotocol/sdk, @blackwell-systems/gcf, cors, dotenv, express, helmet, morgan, uuid
curl -X POST http://localhost:3000/token \
curl -X POST http://localhost:3000/token \
- `POST /token` - Token endpoint
- `POST /token` - Token endpoint (PKCE required)
| `/sse/session/{sessionId}` | POST | Session-specific MCP message endpoint |# Administrator - Full access
| `mcp` | All APIs | Full access to all MCP tools |
| `mcp` | **All APIs** | Full access to all MCP tools and APIs (default) |
**Full access (default)**:
- `mcp` - Full access to all APIs (default)
- API access is controlled by the `SUPPORT_API` environment variable
# Get access token using client credentials
# Add to crontab
Gates applied: no_behavioural_pass.
ee9e9b1714befull audit observations/trust-audit/mcp-server/sieteunoseis__cisco-support.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ee9e9b1714be | CAUTION | B | 87 | first audit |
Questions
What is the Cisco Support MCP server?
Comprehensive TypeScript MCP server for Cisco Support APIs with dual transport support
What tools does Cisco Support expose?
97 in total: 95 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cisco Support safe to connect to an agent?
With care. The audit graded it B (87/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Cisco Support need?
It reads AUTH_TYPE, CISCO_CLIENT_SECRET, DANGEROUSLY_OMIT_AUTH, MCP_BEARER_TOKEN, OAUTH2_ALLOW_DYNAMIC_REGISTRATION, OAUTH2_ISSUER_URL, OAUTH_CLIENTS_CONFIG and OAUTH_SECRETS_CONFIG from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Cisco Support run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-cisco-support at 1.18.0.
How current is this page?
The grade is for one exact copy of the source (ee9e9b1714be), read on 2026-10-08. The repository is watched and re-audited when it changes.