Skip to main content
MCP Servers / Tenable VPR MCP

Tenable VPR MCP

Read-only Tenable.io / Tenable One MCP server with a VPR re-prioritization comparison tool, CISA KEV / EPSS exploitation cross-check, and pentest re-test scan-delta reporting.

AuthorSabastiaz
Transportstdio
Runtimepython
LicenseMIT
AddedAug 3, 2026
ReviewedAug 4, 2026

Baseline review at submission: an accuracy and overt-behavior check, not a full security audit, and it does not cover later changes to the repository. Learn more about our security review process.

Compatible Clients

Claude CodeClaude Desktop

Integrations

Tenable

Tools (11)

  1. list_scans

    List scans visible to the authenticated API key, optionally filtered by folder ID.

  2. get_scan_details

    Latest results for a single scan: hosts scanned, per-plugin findings, severity counts.

  3. list_assets

    List assets known to the tenant (hostname, IPs, UUID, last seen, sources).

  4. get_asset_details

    Full detail for a single asset by UUID, including tags and exposure scores if licensed.

  5. search_vulnerabilities

    Search current findings via the vulnerability workbench, filterable by severity and plugin family.

  6. get_plugin_details

    Full plugin detail: description, solution, CVSS vectors, CVEs, and VPR drivers.

  7. list_tags

    List asset tag categories and values configured in the tenant.

  8. list_agents

    List Nessus Agents with status, platform, and last connect / last scanned timestamps.

  9. compare_vpr_reprioritization

    Before/after comparison of CVSS-based severity vs. VPR-based severity per finding, flagged as escalated / downgraded / unchanged / unrated.

  10. check_kev_epss_exposure

    Cross-references findings' CVEs against the CISA KEV catalog and FIRST.org EPSS scores, independent of Tenable's proprietary VPR.

  11. scan_delta

    Compares a baseline scan against a re-test scan by plugin ID: fixed, still_open, and new_since_baseline, with a remediation-rate percentage.

Tags

vulnerability-managementvprpentestexposure-managementkevepss

What it does

See which findings VPR actually escalates — and back it with CISA KEV, not vendor trust.

Tenable VPR MCP exposes read-only Tenable.io / Tenable One vulnerability management data (scans, assets, findings, plugins, tags, agents) as MCP tools, plus three tools built specifically for exposure-management and pentest reporting workflows rather than raw API access:

  • compare_vpr_reprioritization builds a before/after table showing how VPR re-ranks findings against their static CVSS severity, flagging escalations and downgrades. This is the exact comparison used in Tenable One CTEM proof-of-concept deliverables, where a client needs to see concretely what VPR changes about their existing scan data.
  • check_kev_epss_exposure backs that re-prioritization with two independent, publicly sourced signals instead of relying on a single vendor score: CISA’s Known Exploited Vulnerabilities catalog and FIRST.org’s Exploit Prediction Scoring System.
  • scan_delta compares a baseline scan to a re-test scan and buckets findings into fixed / still-open / new, with a remediation-rate percentage, for the re-test report every pentest engagement produces.

How it works

Built on pyTenable for the Tenable.io API and FastMCP for the MCP server layer. CVE cross-referencing pulls live data from CISA’s public KEV JSON feed and the FIRST.org EPSS API; both calls are isolated from the comparison logic so the re-prioritization and delta-building functions are independently unit tested without live network access. The server is read-only: no scan launch, edit, or delete operations are exposed, so it’s safe to point at a production Tenable.io / Tenable One tenant.

Authentication is via TIO_ACCESS_KEY / TIO_SECRET_KEY environment variables only (never CLI arguments), generated in Tenable.io / Tenable One under Settings > My Account > API Keys.

Known limitations

  • check_kev_epss_exposure issues one additional Tenable API call per distinct plugin to resolve CVEs, so limit should stay modest for interactive use.
  • search_vulnerabilities and compare_vpr_reprioritization read from the vulnerability workbench (tenant-wide, not scan-scoped); use get_scan_details / scan_delta for scan-specific views.
  • No write operations (scan launch/configure, tag assignment, asset deletion) are implemented by design.