Azure / Azure/aks-mcp

AKS CVE MCP Tools Integration

Open
#218 4 comments 0 reactions 1 assignee Claimed by @bcho View on GitHub
Dominant language
Go
Stars
140
Forks
45
Avg merge
4d 3h
Merged PRs (30d)
2

Description

Hi,

We would like to integrate AKS CVE related data into AKS MCP to provide up-to-date CVE information to the AKS user. We propose to add the following MCP tools:

- `az_aks_cve_get_security_bulletins`: Get comprehensive AKS security bulletins and CVE advisories
- `az_aks_cve_get_active_versions`: Get currently supported AKS, VHD, and K8S release versions
- `az_aks_get_cve_status_by_component`: Get CVE status and impact analysis for specific components across release categories

The data will be retrieved from public data endpoint: `https://cve-api.prod-aks.azure.com/` (AKS CVE API, [sample data](https://cve-api.prod-aks.azure.com/api/v1/aks-releases/v20250829/scan-reports)) and `https://releases.aks.azure.com/` (release tracker).

We aim to use the above tools allow user to query about live CVEs and mitigation status from their AKS clusters, example scenarios:

- list AKS managed addons impacted by CVE X
- tell me how to mitigate CVE Y in my cluster (using `az_aks_get_cve_status_by_component`)
- tell me about the impact of nginx ingress CVE `CVE-2025-1098` (using `az_aks_cve_get_security_bulletins`)
- ...

We will also provide sample prompts to help the user troubleshoot / investigate usages around the vulneriabilities in their AKS clusters. @feiskyer / @julia-yin do you have any objections / concerns for us to implement above tools?

cc @riyac12

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.