{"name":"CVD Portal Agent","description":"Files and triages EU vulnerability reports, checks Article 14 obligations, and generates CSAF 2.0 advisories on a CRA compliance platform. Covers classification, Annex I, technical documentation, and authority reporting under Regulation (EU) 2024/2847.","version":"1.0.0","supportedInterfaces":[{"url":"https://cvdportal.com/api/mcp/public","protocolBinding":"MCP","protocolVersion":"1.0"},{"url":"https://cvdportal.com/api/mcp","protocolBinding":"MCP","protocolVersion":"1.0"}],"provider":{"organization":"Porta Regulus B.V.","url":"https://cvdportal.com"},"iconUrl":"https://cvdportal.com/logo.svg","documentationUrl":"https://docs.cvdportal.com","capabilities":{"streaming":true,"pushNotifications":true,"extendedAgentCard":false},"defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"skills":[{"id":"find_vendor_portal","name":"Find a vendor's disclosure portal","description":"Look up a manufacturer's coordinated vulnerability disclosure portal on CVD Portal by slug or custom domain. Returns the portal URL, the RFC 9116 security.txt URL and the disclosure contact. Call this before submitting, so the report reaches the right vendor.","tags":["vulnerability-disclosure","cvd","manufacturer-portal","lookup"],"examples":["Find the disclosure portal for the manufacturer with slug 'acme'","Find the portal at disclose.acme.com"]},{"id":"submit_vulnerability_to_vendor","name":"Submit a vulnerability report to a manufacturer","description":"File a coordinated vulnerability disclosure report to a manufacturer's public CVD Portal. No API key needed. Returns a reference number and a tracking token. Confirm the vendor and the finding with the person you are acting for before calling this: a disclosure is a permanent record on the vendor's side and cannot be retracted through the API.","tags":["vulnerability-disclosure","submission","cvd","eu-cra"]},{"id":"track_vulnerability_report","name":"Track a filed vulnerability report","description":"Read the current status of a report already filed through a CVD Portal disclosure portal, using the tracking token issued at submission. Status only; the description and contact are not returned through this skill.","tags":["vulnerability-disclosure","status","tracking"]},{"id":"subscribe_to_report","name":"Subscribe to report status push updates","description":"Register a public HTTPS callback URL to receive real-time status push notifications when a report's status changes. Authenticates via the tracking token. The callback receives signed POST requests with status-only payloads.","tags":["vulnerability-disclosure","push-notifications","webhooks"]},{"id":"get_compliance_status","name":"Get CRA compliance status","description":"Return the authenticated company's CRA compliance summary and recommendations. Mirrors GET /api/v1/compliance/status. Requires an Enterprise API key with the read scope.","tags":["cra-compliance","eu-cra","reporting"]}]}