openapi: 3.2.0 info: title: ToolOracle MCP Platform Security API version: 4.2.0 description: ToolOracle MCP Platform — 89 servers, 1096 tools, OracleNet self-learning agent mesh. Neural routing, W3C DIDs, Verifiable Credentials, escrow-free x402 USDC settlement on Base + XRPL native escrow. x-hedera-mainnet: contract: 0.0.10420310 beacon_topic: 0.0.10420280 join_topic: 0.0.10420282 x-changelog: - version: 4.2.0 date: '2026-04-28' changes: - Canonicalized counts from /assets/catalog.json - Aligned root /openapi.json with /.well-known/openapi.json - Added x-counts and x-canonical-source extensions - version: 4.1.0 date: '2026-04-19' changes: - Added Mesh Economics v1 API paths (/economics/api/*) - Added Mesh Nervous System discovery paths (/.well-known/agent-pulse, /.well-known/meta-tools) - Added /.well-known/mesh-economics discovery endpoint x-counts: servers_online: 89 tools_available: 1096 categories: 7 chains_supported: 13 paid_products: 18 x-canonical-source: https://tooloracle.io/assets/catalog.json x-generated-at: '2026-09-20T02:13:01+00:00' servers: - url: https://tooloracle.io tags: - name: Security paths: /v2/cve_lookup: post: operationId: v2_cve_lookup tags: - Security summary: NIST NVD CVE search by keyword, vendor, or product — CVSS score, CWE, references description: 'AgentNOMOS CVE Vulnerability Intelligence Lookup: Keyword, vendor or product search against the NIST NVD database. Returns per CVE: cve_id, published date, CVSS base score and vector string, attack vector, CWE class, description excerpt, references and the NVD detail URL. Source is NIST NVD only — no CISA KEV and no MITRE ATT&CK integration. For automated security checks and agent workflows.' requestBody: required: true content: application/json: schema: type: object properties: keyword: type: string description: Search keyword, vendor, or product name limit: type: integer description: Max results (default 10, max 50) required: - keyword example: keyword: openssl limit: 5 responses: '200': description: Success (synthetic example) content: application/json: example: total_results: 10 returned: 1 vulnerabilities: - cve_id: CVE-2026-45363 published: '2026-07-14' cvss_score: 9.1 attack_vector: NETWORK cwe: CWE-287 nvd_url: https://nvd.nist.gov/vuln/detail/CVE-2026-45363 source: NIST NVD '402': description: 'Payment Required (x402 v2): payment requirements are in the PAYMENT-REQUIRED response header (accepts[]); retry with the PAYMENT-SIGNATURE header (USDC on Base, eip155:8453). Success carries the PAYMENT-RESPONSE settlement header. The legacy X-PAYMENT header is not accepted on /v2 routes.' '400': description: Bad Request — invalid or missing parameters. x-x402: price: $0.005 currency: USDC network: eip155:8453 method: POST example_type: synthetic externalDocs: description: x402 v2 buyer quickstart (pay one /v2 route and verify the signed NOMOS execution receipt) url: https://tooloracle.io/docs/x402-buyer-quickstart/