MCP and agent glossary
Short definitions of the words used on the install guides, written for this catalog. They are not a spec, and they are not legal terms.
If you want the steps rather than the definition, open CVE Risk Check in Cursor or the full install index. The same facts in plain text are on llms.txt.
MCP
Model Context Protocol is the open protocol an agent client uses to list tools and call them. On this site every plugin is an MCP server. The HTTP path is /mcp on that plugin's host, for example https://cve.openkrill.app/mcp. A client that speaks MCP can use the same server ChatGPT, Claude, Cursor and Pi use. MCP does not, by itself, grant a login or a right to private data.
MCP server
The program that publishes tools. Each Agent Tools plugin is one server on its own hostname, because a ChatGPT directory submission proves control of a host one plugin at a time. The server answers tools/list and tools/call. It does not keep your conversation. The only lasting record of a normal call is a daily count, described on the privacy page.
MCP client
The application that connects to a server and decides when to call a tool. ChatGPT, Claude, Cursor and Pi are clients. They differ in where you paste the server URL and in whether the connection starts from your machine or from the vendor's cloud. The server URL does not change. A client can also refuse to connect if the server asks for OAuth and you have not signed in. These servers do not ask.
Tool
A named function the model can call, with an input schema and an output schema. check_cve is a tool. find_company_jobs is a tool. The name is what you see in tools/list. The description starts with when to use it, so the model can choose. A plugin has several tools. Calling one does not call the others.
tools/list and tools/call
tools/list returns the tools a server offers, including names, descriptions and schemas. tools/call runs one tool with the arguments the client sends. Both are JSON-RPC methods posted to the server's /mcp URL. A successful call returns structuredContent that matches the tool's output schema. A rejected argument comes back as a tool error, not as a made-up answer.
Streamable HTTP
The remote transport these servers use. The client POSTs a JSON-RPC message to https://host/mcp and reads a JSON reply. There is no local process to install and no stdio command. Cursor calls this a url entry. Claude Code calls it transport http. Pi's adapter treats a url without a command as a remote server. SSE is an older transport. These servers speak streamable HTTP.
JSON-RPC
The message format MCP uses. A call has jsonrpc set to 2.0, an id, a method and params. The reply has the same id and either a result or an error. You do not need to write JSON-RPC by hand in ChatGPT or Claude. Cursor and Pi hide it too. The integration pages show a tools/call body so you can repeat the checked example with curl if you want to see the raw reply.
Connector
Claude's name for a remote MCP server you add yourself. A custom connector is not the same as a listing in the Anthropic Directory. ChatGPT uses the word connector for some built-in services and the word plugin for a directory submission. On this site, connector means the URL you paste so a client can call one of our servers. It is not an account link and not a write access grant.
Plugin
One product in this catalog: a display name, a hostname, a set of tools, and the listing text those tools are described with. Company Jobs Finder is a plugin. Its slug is company-jobs and its host is jobs.openkrill.app. The pages under /integrations are generated from that listing so the tool names on the page match tools/list. A plugin is not a ChatGPT directory listing until the owner submits it. The developer-mode steps still work.
Tool annotation
A hint on a tool: readOnlyHint, destructiveHint, idempotentHint and openWorldHint. Clients use them to decide whether to ask before running a tool. Every tool in this catalog sets all four. The data tools are read-only. openWorldHint is true when the tool reads a public service outside our servers, such as the National Vulnerability Database or a job board. An annotation is not a permission you grant. It is a description of the tool.
OAuth for MCP
A way for a client to get an access token without you pasting a key. connect.openkrill.app supports it for the shared API tools: dynamic client registration, authorization code with PKCE, and refresh tokens. The plugin hosts on this site do not require OAuth. Leave the OAuth client id fields empty when you add one. If a client insists on a sign-in for a plugin host, the server is the wrong kind of protected resource for that flow. Use the URL as a public server instead.
API key
An optional key for the shared API at api.openkrill.app. Without a key, anonymous calls are limited to 20 a minute and 200 tool calls a day per network. A key lifts those limits. Plugin hosts do not take a key and do not have a key field in their install steps. Do not invent one. Keys come from support@openkrill.app if you need the shared API above the anonymous limits.
llms.txt
A plain-text page at /llms.txt written for agents. It lists every HTTP tool and every plugin MCP URL, the cache time, and how OAuth on connect.openkrill.app works. The HTML integration pages are the version with install steps for a specific client. An agent that only fetches text can start at /llms.txt and follow the URLs. The HTML pages link back to it.
Rate limit
A cap on how many calls one network can make. Plugin calls are limited per network and per day. The shared API states the numbers in /llms.txt. Past a limit the HTTP API answers 429 with Retry-After. An MCP call answers with a tool error whose text starts with rate_limited or anonymous_daily_limit. A rate limit is not a finding about your question. Wait and retry. The servers do not store the network address with the answer.
Cache
A stored copy of a public answer so the next identical question is faster. Responses say HIT, MISS or STALE on the shared API. Plugin cache times differ: a CVE record is kept for about an hour, a holiday calendar for about a day, a DNS mail check for about two minutes. The cache key is a hash of the tool arguments. It does not contain who asked. Error results are not cached, so the next call retries.
Agent
A model that can choose a tool, call it, and use the result in the next step. The clients on the integration pages are agents in that sense. They are not a person, and they do not get extra access because they are automated. An agent should be given the same public inputs you would type: a CVE id, a company name, a DOI. It should not be given secrets, a resume, or a description of your legal situation. The role pages list questions that stay inside what the tools actually do.