Map Tenable Security Center findings to MITRE ATT&CK techniques and export a VPR-scored ATT&CK Navigator layer.
This server has good fundamentals: all 4 tools are explicitly registered with FastMCP, named with clear action verbs (map_, export_, techniques_for_, my_findings_for_), have descriptions, and include typed input schemas. However, there are gaps in parameter documentation, missing output schema specifications, and no error handling guidance. Descriptions are solid (100-180 chars) but could be more prescriptive about when to call each tool. The caching behavior is clever but undocumented in the API surface, forcing users to infer it from tool descriptions.
Map the environment and write a MITRE ATT&CK Navigator layer (v4.5) to disk.
Pull open findings from Security Center and map them to ATT&CK. Returns the coverage summary and per-technique scores (ranked by aggregated VPR). Scope to a single repository or saved query, or leave both unset to map everything. Set ``no_semantic`` to use the deterministic chain only.
Which of my findings map to the given ATT&CK technique IDs? Reuses the last cached run for the same scope when available; otherwise pulls and maps the environment first. Base-technique IDs (``T1190``) also match their sub-techniques.
List the ATT&CK techniques (from the local catalog) under a given tactic. Useful as an entry-point question: "for initial-access, which techniques should I look at?" Tactic names use ATT&CK slug form, e.g. ``initial-access``, ``execution``, ``privilege-escalation``.
Output schemas not formally documented. Tools return dict[str, Any] but the structure of 'summary', 'scores', 'matches' fields is not specified in JSON Schema or description. LLMs cannot infer downstream field names (e.g., what fields exist in result.scores[i]).
Parameter descriptions are sparse or missing constraint details. Example: 'repository_id' and 'query_id' say '(optional)' but do not explain what happens if both are None, or whether they are mutually exclusive. 'severities' lists items but does not specify enum values (e.g., what severity levels are valid?).
No error handling or recovery guidance. If Security Center is unreachable, or if a technique_id is invalid, the tool returns no guidance on what the LLM should do next. Descriptions do not explain failure modes.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 68 | 2026-07-28+ | v2 |
Caching behavior (_last_runs dict) is implicit and not exposed in the tool API. The description of 'my_findings_for_techniques' says it 'reuses the last cached run for the same scope when available' but does not explain how to invalidate the cache or force a fresh run. An LLM could be fooled into thinking it is querying fresh data when it is actually re-using stale results.
No pagination or result limiting documented. 'map_environment' returns 'scores' as a list but does not specify a maximum length or whether results are paginated. Large deployments could return hundreds of techniques, exhausting context. The tool description should state if results are capped and offer pagination if needed.
'tactic' parameter in 'techniques_for_tactic' accepts free-form strings, though it says 'ATT&CK slug form' (e.g., 'initial-access'). No enum constraint prevents the LLM from passing 'Initial Access' or 'initial_access' (wrong format). The description normalizes via .lower().replace(' ', '-'), masking the validation but not preventing mistakes.