Production-ready MCP server for OpenCTI 6.x threat intelligence integration with Claude Desktop. Provides professional analysis templates and enterprise features for AI-enhanced threat intelligence workflows.
This server has solid tool definitions with comprehensive schemas and descriptions. All 9 tools have explicit JSON Schema definitions with proper type constraints, enums, and parameter ranges. Descriptions are detailed and domain-specific (threat intelligence context). Tool naming follows verb_noun pattern consistently. However, there are gaps in output schema documentation, no error handling guidance visible in tool definitions, no tool annotations (readonly/destructive hints), and no evidence of idempotency or recovery patterns. The server is well-structured for its narrow domain (OpenCTI threat intel) but lacks production-grade error handling and some composition patterns that would push it to 80+.
Query MITRE ATT&CK techniques and tactics from OpenCTI. Retrieves attack patterns with descriptions, kill chain phases, and associated threat intelligence. Access the 452K+ MITRE ATT&CK techniques in your OpenCTI instance.
Retrieve malware information from OpenCTI including family details, capabilities, variants, and associated indicators.
Get recent indicators from OpenCTI 6.x with professional analysis template guidance. Retrieves indicators and applies executive, technical, incident response, or trend analysis templates for structured output.
Retrieve tactics, techniques, and procedures (TTPs) for specific threat actors from OpenCTI.
Generate comprehensive threat landscape summary with professional analysis. Aggregates indicators, identifies trends, and produces executive or technical summaries of the current threat environment based on OpenCTI data.
No output schemas documented. Tools define inputSchema comprehensively but do not document what fields/structure they return. LLMs cannot plan downstream tool chains or extract relevant data without knowing response structure.
No tool annotations present. Tools lack readOnlyHint, destructiveHint, or idempotentHint metadata. The agent cannot infer which tools are safe to retry, which have side effects, or which are read-only operations. All tools are read-only (threat intel queries) but this is not formally declared.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 70 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Search and retrieve vulnerability information from OpenCTI. Includes CVE details, CVSS scores, affected software, and threat context.
Search for threat intelligence entities (campaigns, threat actors, threat groups) in OpenCTI with filtering and analysis.
Search for threat intelligence indicators by observable value with automatic type detection and contextual analysis. Supports IPv4/IPv6 addresses, domain names, URLs, email addresses, and file hashes (MD5, SHA1, SHA256). Returns matching indicators with threat context including labels, confidence scores, and related campaigns.
Check OpenCTI connection, version compatibility, and data availability with diagnostic information. Validates OpenCTI 6.x setup and reports on database status, active connectors, and overall system readiness.
No error handling or recovery guidance. Tool definitions do not indicate what errors are possible, when they are retryable, or how to recover. A malformed OpenCTI query could fail with no guidance for the agent on next steps.
Some parameter descriptions are vague. 'get_vulnerabilities' and 'get_malware' only document search_term and limit with minimal context. 'get_vulnerabilities' says 'Optional search term (CVE ID, product name, etc.)', does it support partial matches? Regex? Case-sensitive? This forces LLM guessing.
No pagination guidance. Tools like 'get_recent_indicators_with_analysis' accept a 'limit' parameter (max 100) but don't document: what happens if there are more results? Is there a next_cursor or offset? How does the agent fetch subsequent pages? This omission forces either arbitrary result cutoffs or incomplete threat intel.
Incomplete field naming consistency. 'search_observable' returns threat context including 'labels, confidence scores, and related campaigns' but the exact JSON field names are not specified. Downstream tools that might consume these (e.g. a hypothetical 'create_incident_from_observable') cannot reliably extract the campaign ID if the field name is unclear.
No confirmation or dry-run patterns for risky operations. While all current tools are read-only, the server architecture (mcp>=1.0.0) supports Multi-Round-Trip Requests but does not use them. If destructive operations are added later (e.g. 'delete_campaign'), they should request confirmation before executing.