
Official MCP RegistryListed
Lattice: CVE, MITRE ATT&CK and detection graph for security agents
CVE, KEV, MITRE ATT&CK, CWE and detection graph for AI agents; every link names its source.
First seen 4 Oct 2026. Evidence as of 5 Oct 2026.
7
Tools
From an anonymous probe
1
Source listings
Each with its own history
27
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| graph_lookup | Find nodes by exact external id, e.g. CVE-2021-44228, T1059.001, CWE-79. Returns each match with its source (a CVE has a kev node if CISA lists it as exploited, and an nvd node) and a uid for graph_node and graph_neighbors. An empty items list means the graph has no such id. | Read-only |
| graph_meta | Describe the graph this server reads, without looking up any fact in it. Returns the snapshot id and creation time, the schema version with notable schema changes, the node labels (types), the relationship verbs, the contributing sources, and the path templates that graph_path accepts. When to call it: once at the start of a session, to learn the valid values for the label argument of graph_lookup, graph_search and graph_neighbors, the verb values for graph_neighbors and the template names for graph_path; and when you report a finding, to cite the snapshot id it came from. What it is not for: it returns no CVEs, techniques, groups or detections. Use graph_lookup to find those. It takes no arguments, only reads, and gives the same answer to every caller of a snapshot. | Read-only |
| graph_neighbors | Directly connected nodes with each link's verb, source, confidence and whether it is declared or inferred. Declared and cross-source links come first. If the answer has truncated: true, pass its next_cursor as cursor to continue. | Read-only |
| graph_node | One node's properties (long text is clipped). uid comes from graph_lookup or graph_search. On a kev node: date_added, due_date, known_ransomware_use (Known or Unknown; Unknown means not recorded), required_action, vendor_project, product. On an nvd node: description and metadata (cvss_score, affected_products). A cvss_score of 0 means not scored yet. | Read-only |
| graph_notices | Return the licence and attribution notices for the data sources behind an answer. Other tools list notice ids with their answers. Pass those ids here to get, for each notice, its title, what it applies to, the obligation it places on you (for example attribution wording or a share-alike condition) and the notice text. Long texts are cut and flagged text_truncated, with text_url pointing to the full text. When to call it: before you quote, republish or build on anything the graph returned, and then quote what the obligation requires. Unknown ids are reported in unknown rather than failing. What it is not for: it returns no security facts, and it is source licence information, not legal advice. It only reads and gives the same answer each time for a snapshot. | Read-only |
| graph_path | Answer a fixed multi-hop question from an external id. Templates: cve-context (start: CVE), cve-to-defense (start: CVE), technique-coverage (start: Technique), weakness-chain (start: Weakness), actor-ttps (start: ThreatActor/Malware/Campaign). cve-to-defense gives the techniques a CVE enables and the detections and procedures for them. | Read-only |
| graph_search | List nodes whose external id starts with a prefix (e.g. CVE-2024-1, T105). Ids only, not free text. If the answer has truncated: true, pass its next_cursor as cursor to continue; a list without truncated is complete. | Read-only |
Change history
- graph_search: title changed
- graph_search: input schema changed
- graph_search: annotations changed
- graph_path: title changed
- graph_path: input schema changed
- graph_path: annotations changed
- graph_notices: title changed
- graph_notices: input schema changed
- graph_notices: description changed (+"Return the licence" +"for the data sources behind an answer. Other tools list notice ids with their answers. Pass those ids here to get, for each notice, its title, what it applies to, the obligation it places on you (for example attribution wording or a share-alike condition)" +"the")
- graph_notices: annotations changed
- graph_node: title changed
- graph_node: input schema changed
- graph_node: annotations changed
- graph_neighbors: title changed
- graph_neighbors: input schema changed
- graph_neighbors: annotations changed
- graph_meta: title changed
- graph_meta: description changed (+"Describe the graph this server reads, without looking up any fact in it. Returns the snapshot id and creation time, the schema version with notable schema changes," +"node" +"(types), the")
- graph_meta: annotations changed
- graph_lookup: title changed
- graph_lookup: input schema changed
- graph_lookup: annotations changed
- server instructions changed (+"If an answer carries an `access` object you called without a key: read access.limits and access.get_a_key. An agent may obtain a key itself with the call described there, but only when it acts for a real person or organisation that has asked it to.")
- Website changed from "https://namiq.io/lattice" to "https://lattice.namiq.io" (registry)
- Name changed (registry)
- Description changed (registry)
- Listed (registry)
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | io.namiq/lattice | 4 Oct 2026 | 5 Oct 2026 | 2 |