CSAF Advisory Check
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Use in your browser
Check a public CSAF 2.0 advisory against the official schema and the mandatory, optional, and informative conformance tests, compare two advisories, or scan a vendor's recent feed.
Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.
Open the apps workspace
Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.
Copy one ready-to-send prompt for any agent that supports remote MCP connections.
For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.
ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide
https://powmcp.com/csaf-advisory-check/mcp {
"mcpServers": {
"powmcp-csaf-advisory-check": {
"type": "http",
"url": "https://powmcp.com/csaf-advisory-check/mcp"
}
}
}Terminal agents add this app with one command:
claude mcp add --transport http powmcp-csaf-advisory-check https://powmcp.com/csaf-advisory-check/mcpcodex mcp add powmcp-csaf-advisory-check --url https://powmcp.com/csaf-advisory-check/mcpgemini mcp add --transport http powmcp-csaf-advisory-check https://powmcp.com/csaf-advisory-check/mcpManage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.
Proof
Check a CSAF 2.0 security advisory before you publish it
Validate one public CSAF 2.0 advisory against the bundled OASIS schema and the mandatory, optional, and informative conformance tests with document-located findings, compare an advisory against its prior revision under identical limits, or scan a provider's published feed, validating document conformance only.
Request cost1 completed result
Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.
csaf_check
Validate one public CSAF 2.0 security advisory before your PSIRT publishes it. Give a publicly fetchable HTTP(S) URL of a direct CSAF advisory JSON document and it downloads the live file under an SSRF-guarded, 5 MB-capped fetch, detects the CSAF version and document category from content, and validates it with the pinned OASIS csaf-validator-lib: the CSAF 2.0 JSON schema plus the mandatory (6.1.x), optional (6.2.x), and informative (6.3.x) numbered conformance tests, returning pass/fail, the detected version and category, and every failed test with its numbered id, tier, and JSON-pointer location. Choose the profile to run the schema plus mandatory tests only (basic), plus optional (extended), or plus informative (full, default). It validates document conformance only: it does not judge whether the vulnerability, affected products, or remediation are factually true or complete, and it never scans the user's own systems for a CVE. Fetching and validating a live document can take up to 60 seconds.
csaf_compare
Compare exactly two public CSAF 2.0 advisories under identical limits (an advisory versus its prior revision, or two vendors' advisories for the same CVE) to see which conformance problems changed and which has fewer failures. Give two distinct publicly fetchable HTTP(S) CSAF advisory URLs and it runs the same bounded validation as csaf_check on each, then reports per-advisory pass and mandatory/optional/informative failure counts, which numbered tests were introduced or resolved between them, a comparability note (only advisories sharing CSAF version and document category are comparable), and a ranking by pass state then fewer mandatory failures, asserted only when the measured findings support one. Use csaf_check for a single advisory. It ranks automated conformance only and never infers that one advisory is more factually correct, more severe, or a better disclosure. Fetching and validating two live documents can take up to 60 seconds.
csaf_provider_scan
Scan a CSAF provider's published feed and report how many of their most recent advisories are conformant. Give a provider domain (e.g. example.com) or its full provider-metadata.json URL (including a /.well-known/csaf/provider-metadata.json URL) and it resolves the provider metadata, walks the directory-based changes.csv (or ROLIE feeds) to the most recent advisories, fetches and validates a bounded roster of them with the same pinned csaf-validator-lib as csaf_check, and returns per-advisory tracking id, pass state, and mandatory-failure count plus an aggregate conformant count. Use maxAdvisories (default 10, max 20) to bound how many are checked. Use csaf_check for a single advisory. It validates document conformance only and never judges whether the advisories are factually accurate, severe, or complete. Resolving and validating a roster of live documents can take up to 60 seconds.
Other apps for the jobs next to CSAF Advisory Check.
Scope and boundaries for CSAF Advisory Check.
Validate Red Hat's public RHSA-2024:0001 CSAF JSON with the full profile and up to 300 findings, compare it with another CSAF 2.0 advisory, or scan a provider metadata feed for its three most recent advisories.
Start with pass and failureCounts, reading schema and mandatory failedTests first. Pass means the schema and mandatory 6.1.x tests are clean; optional 6.2.x warnings and informative 6.3.x notes do not fail it. Truncation makes the finding list incomplete; read comparability before using comparison drift, and read advisoriesValidated and truncation before interpreting a provider scan's conformantCount.
The pinned OASIS validator establishes document conformance only. It does not confirm that vulnerability statements, affected products, severity, or remediation are true or complete, and it does not scan systems for exposure; provider results cover only the bounded advisory roster fetched.