Query MITRE ATT&CK and MITRE ATLAS (AI/ML) frameworks via Model Context Protocol.
Strong naming consistency and complete input schemas across all 19 tools. All tools follow verb_noun pattern (get_*) and accept pagination parameters where appropriate. Descriptions are clear and functional (avg 80-120 chars), meeting the 10-1024 char baseline. However, descriptions lack LLM-optimization guidance (WHEN to call, prerequisites, distinctions from similar tools). Output schemas are not explicitly documented in code, inferred from wrapper implementations but not declared to clients. Error handling is minimal; no recovery guidance or invalid-value clarification. Tool composition is excellent (read-only patterns, proper chaining via IDs), but descriptions could better explain domain distinctions (ATT&CK vs ATLAS) and use cases.
Return detailed ATLAS mitigation for a given mitigation ID (e.g., 'AML.M0001').
Return a paginated summary list of ATLAS mitigations.
Return detailed ATLAS tactic for a given tactic ID or ATT&CK reference ID (e.g., 'AML.TA0001' or 'TA0001').
Return a paginated summary list of ATLAS tactics.
Return detailed ATLAS technique for a given technique ID (e.g., 'AML.T0001').
Return a paginated summary list of ATLAS techniques.
Return ATLAS techniques used in a specific tactic (e.g., 'AML.TA0001' or 'TA0001').
Output schemas not explicitly documented in MCP tool registration. Descriptions state WHAT data is returned (e.g., 'Return full ATT&CK technique object'), but the exact field structure is not declared in the tool definition. LLMs cannot reliably plan downstream data extraction without this.
Descriptions lack domain-specific guidance. ATT&CK and ATLAS tools are named similarly but serve different security frameworks. Descriptions should clarify: 'Returns MITRE ATT&CK techniques (cyber adversary tactics and techniques)' vs 'Returns ATLAS techniques (adversarial ML attack patterns).' This prevents LLM confusion when both tools are available.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 70 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Return detailed ATT&CK group object for group alias (e.g., 'APT1').
Return a paginated summary list of ATT&CK groups.
Return a paginated summary list of ATT&CK mitigations.
Return mitigations for a specific technique ID.
Return a paginated summary list of ATT&CK software.
Return ATT&CK software used by a specific group (filtered by group alias).
Return full ATT&CK tactic object for MITRE tactic ID (e.g., 'TA0001').
Return a paginated summary list of ATT&CK tactics.
Return full ATT&CK technique object for MITRE technique ID (e.g., 'T1055').
Return a paginated summary list of ATT&CK techniques.
Return techniques used in a specific ATT&CK tactic (e.g., 'initial-access').
Return ATT&CK techniques used by a specific group (filtered by group alias).
No error handling or recovery guidance. Descriptions do not indicate what happens if an ID is not found, if parameters are invalid, or what the agent should try next (e.g., 'If technique_id is invalid, call get_techniques() to discover valid IDs'). This forces agents to guess on failures.
Parameter descriptions for string inputs lack format/constraint guidance. E.g., 'technique_id' is marked 'case-insensitive' but no format pattern is provided (T#### vs AML.T#### for ATLAS). No min/max length constraints. This invites invalid input from LLMs.
Descriptions for paginated tools (limit/offset) do not state a result cap or explain the impact of large limits on context size. Baseline rubric advises capping results at 20-50 items and stating this limit in the description. Current descriptions omit this guidance.
No per-tool use case or selection guidance. Descriptions are functional but lack WHEN/WHY language. E.g., 'Use get_techniques_by_tactic if you want to see all techniques in a single phase; use get_techniques_used_by_group if you want to know what a specific threat actor does.' This helps LLMs disambiguate when similar tools exist.