Skip to main content
Glama

Bulk ATLAS Technique Lookup

bulk_atlas_technique_lookup
Read-onlyIdempotent

Bulk ATLAS technique lookup — retrieve full records for up to 50 techniques in a single request instead of N separate atlas_technique_lookup calls. Designed as the natural follow-up to atlas_case_study_lookup, whose techniques_used array can be passed directly. Each item is the same shape as atlas_technique_lookup, including parent-tactics inheritance for sub-techniques (inherited_tactics=true flag) and per-item next_calls (D3FEND bridge when attack_reference_id present, sibling-technique search by tactic, parent lookup for sub-techniques). Free: 30/hr (1 per item), Pro: 500/hr. Returns {results [{technique_id, status (ok|not_found|invalid_format), technique, error}], total, successful, failed, partial, summary}.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
technique_idsYesList of MITRE ATLAS technique ids in format 'AML.T####' or 'AML.T####.###' (e.g. ['AML.T0051', 'AML.T0043', 'AML.T0000.000']). Up to 50 per call. Case-insensitive; normalized + de-duplicated server-side. Each id counts as 1 request toward the rate limit.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • changedOutput schema / properties / result / properties / next_calls / type
      Previous value: -"array"New value: +[
      +  "array",
      +  "null"
      +]
    • changedOutput schema / properties / result / properties / verdict / type
      Previous value: -"object"New value: +[
      +  "object",
      +  "null"
      +]
  2. Changed1 schema field changed
    • changedOutput schema / properties / result / properties / next_calls / type
      Previous value: -"object"New value: +"array"
  3. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "properties": {
      +    "result": {
      +      "properties": {
      +        "failed": {
      +          "type": "integer"
      +        },
      +        "next_calls": {
      +          "type": "object"
      +        },
      +        "partial": {
      +          "type": "boolean"
      +        },
      +        "processed": {
      +          "type": "integer"
      +        },
      +        "results": {
      +          "type": "array"
      +        },
      +        "skipped_due_to_rate_limit": {
      +          "type": "array"
      +        },
      +        "successful": {
      +          "type": "integer"
      +        },
      +        "summary": {
      +          "type": "string"
      +        },
      +        "total": {
      +          "type": "integer"
      +        },
      +        "verdict": {
      +          "type": "object"
      +        }
      +      },
      +      "required": [],
      +      "type": "object"
      +    }
      +  },
      +  "required": [
      +    "result"
      +  ],
      +  "type": "object"
      +}
  4. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -{
      -  "$defs": {
      -    "AtlasTechniqueResponse": {
      -      "additionalProperties": true,
      -      "properties": {
      -        "attack_reference_id": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "attack_reference_url": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "created_date": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "description": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "inherited_tactics": {
      -          "anyOf": [
      -            {
      -              "type": "boolean"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "maturity": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "modified_date": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "name": {
      -          "type": "string"
      -        },
      -        "next_calls": {
      -          "anyOf": [
      -            {
      -              "items": {
      -                "$ref": "#/$defs/PivotHint"
      -              },
      -              "type": "array"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "subtechnique_of": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "tactics": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "technique_id": {
      -          "type": "string"
      -        },
      -        "verdict": {
      -          "anyOf": [
      -            {
      -              "$ref": "#/$defs/Verdict"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "technique_id",
      -        "name"
      -      ],
      -      "type": "object"
      -    },
      -    "BulkAtlasTechniqueItem": {
      -      "additionalProperties": true,
      -      "properties": {
      -        "error": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "status": {
      -          "enum": [
      -            "ok",
      -            "error",
      -            "not_found",
      -            "invalid_format"
      -          ],
      -          "type": "string"
      -        },
      -        "technique": {
      -          "anyOf": [
      -            {
      -              "$ref": "#/$defs/AtlasTechniqueResponse"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "technique_id": {
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "technique_id"
      -      ],
      -      "type": "object"
      -    },
      -    "BulkAtlasTechniqueResponse": {
      -      "additionalProperties": true,
      -      "properties": {
      -        "failed": {
      -          "type": "integer"
      -        },
      -        "next_calls": {
      -          "anyOf": [
      -            {
      -              "items": {
      -                "$ref": "#/$defs/PivotHint"
      -              },
      -              "type": "array"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "partial": {
      -          "type": "boolean"
      -        },
      -        "processed": {
      -          "type": "integer"
      -        },
      -        "results": {
      -          "items": {
      -            "$ref": "#/$defs/BulkAtlasTechniqueItem"
      -          },
      -          "type": "array"
      -        },
      -        "skipped_due_to_rate_limit": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "successful": {
      -          "type": "integer"
      -        },
      -        "summary": {
      -          "type": "string"
      -        },
      -        "total": {
      -          "type": "integer"
      -        },
      -        "verdict": {
      -          "anyOf": [
      -            {
      -              "$ref": "#/$defs/Verdict"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "type": "object"
      -    },
      -    "ErrorDetail": {
      -      "properties": {
      -        "code": {
      -          "enum": [
      -            "invalid_argument",
      -            "not_found",
      -            "rate_limit_exceeded",
      -            "auth_required",
      -            "tier_limit",
      -            "upstream_timeout",
      -            "upstream_error",
      -            "internal_error"
      -          ],
      -          "type": "string"
      -        },
      -        "docs_url": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "message": {
      -          "maxLength": 500,
      -          "type": "string"
      -        },
      -        "retry_after_seconds": {
      -          "anyOf": [
      -            {
      -              "type": "integer"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "upgrade_url": {
      -          "anyOf": [
      -            {
      -              "type": "string"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        }
      -      },
      -      "required": [
      -        "code",
      -        "message"
      -      ],
      -      "type": "object"
      -    },
      -    "ErrorResponse": {
      -      "properties": {
      -        "error": {
      -          "$ref": "#/$defs/ErrorDetail"
      -        }
      -      },
      -      "required": [
      -        "error"
      -      ],
      -      "type": "object"
      -    },
      -    "PivotHint": {
      -      "additionalProperties": true,
      -      "properties": {
      -        "input": {
      -          "type": "string"
      -        },
      -        "params": {
      -          "anyOf": [
      -            {
      -              "additionalProperties": {
      -                "type": "string"
      -              },
      -              "type": "object"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "reason": {
      -          "type": "string"
      -        },
      -        "tool": {
      -          "enum": [
      -            "cve_lookup",
      -            "cve_search",
      -            "cve_leading",
      -            "bulk_cve_lookup",
      -            "calculate_risk_score",
      -            "get_cvss_details",
      -            "exploit_lookup",
      -            "kev_detail",
      -            "cwe_lookup",
      -            "subdomain_enum",
      -            "ssl_check",
      -            "tech_fingerprint",
      -            "asn_lookup",
      -            "ip_lookup",
      -            "ioc_lookup",
      -            "bulk_ioc_lookup",
      -            "hash_lookup",
      -            "threat_intel",
      -            "threat_report",
      -            "audit_domain",
      -            "domain_report",
      -            "dns_lookup",
      -            "whois_lookup",
      -            "wayback_lookup",
      -            "scan_headers",
      -            "check_headers",
      -            "check_secrets",
      -            "check_injection",
      -            "check_dependencies",
      -            "email_mx",
      -            "email_security_posture",
      -            "email_disposable",
      -            "email_verify",
      -            "robots_txt",
      -            "redirect_chain",
      -            "brand_assets",
      -            "seo_audit",
      -            "phone_lookup",
      -            "username_lookup",
      -            "password_check",
      -            "phishing_check",
      -            "atlas_technique_lookup",
      -            "atlas_technique_search",
      -            "bulk_atlas_technique_lookup",
      -            "atlas_case_study_lookup",
      -            "atlas_case_study_search",
      -            "d3fend_defense_lookup",
      -            "d3fend_defense_search",
      -            "d3fend_defense_for_attack",
      -            "d3fend_attack_coverage",
      -            "sigma_rule_lookup",
      -            "bulk_sigma_rule_lookup",
      -            "tech_stack_cve_audit"
      -          ],
      -          "type": "string"
      -        }
      -      },
      -      "required": [
      -        "tool",
      -        "input",
      -        "reason"
      -      ],
      -      "type": "object"
      -    },
      -    "Verdict": {
      -      "properties": {
      -        "completeness": {
      -          "enum": [
      -            "complete",
      -            "partial",
      -            "minimal"
      -          ],
      -          "type": "string"
      -        },
      -        "data_age_seconds": {
      -          "anyOf": [
      -            {
      -              "type": "integer"
      -            },
      -            {
      -              "type": "null"
      -            }
      -          ]
      -        },
      -        "deterministic": {
      -          "type": "boolean"
      -        },
      -        "falsifiable_fields": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "sources_queried": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        },
      -        "sources_unavailable": {
      -          "items": {
      -            "type": "string"
      -          },
      -          "type": "array"
      -        }
      -      },
      -      "required": [
      -        "deterministic"
      -      ],
      -      "type": "object"
      -    }
      -  },
      -  "properties": {
      -    "result": {
      -      "anyOf": [
      -        {
      -          "$ref": "#/$defs/BulkAtlasTechniqueResponse"
      -        },
      -        {
      -          "$ref": "#/$defs/ErrorResponse"
      -        }
      -      ]
      -    }
      -  },
      -  "required": [
      -    "result"
      -  ],
      -  "type": "object"
      -}New value: +null
  5. Changed122 schema fields changed
    • removedOutput schema / $defs / AtlasTechniqueResponse / description
      Removed value: -"MITRE ATLAS technique record (AI/ML attack catalog).\n\nATLAS catalogues adversarial techniques targeting AI/ML systems (LLM prompt\ninjection, model poisoning, evasion). About 80% of techniques have no ATT&CK\nbridge — ATLAS is the canonical reference for AI/ML-specific TTPs."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_id / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_id / description
      Removed value: -"Bridged ATT&CK technique id when ATLAS cites a parallel enterprise TTP, e.g. 'T1596'. About 20% of ATLAS techniques carry an ATT&CK reference; use this to pivot to D3FEND defenses."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_id / title
      Removed value: -"Attack Reference Id"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_url / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_url / description
      Removed value: -"Canonical ATT&CK URL for the bridged technique, e.g. 'https://attack.mitre.org/techniques/T1596/'."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / attack_reference_url / title
      Removed value: -"Attack Reference Url"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / created_date / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / created_date / description
      Removed value: -"ISO-8601 date the technique was first published in ATLAS."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / created_date / title
      Removed value: -"Created Date"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / description / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / description / description
      Removed value: -"Full technique description as published by MITRE ATLAS. May be multi-paragraph."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / description / title
      Removed value: -"Description"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / inherited_tactics / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / inherited_tactics / description
      Removed value: -"True when `tactics` was inherited from the parent technique (this is a sub-technique). Omitted when tactics are native to the record."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / inherited_tactics / title
      Removed value: -"Inherited Tactics"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / maturity / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / maturity / description
      Removed value: -"MITRE ATLAS maturity classification: 'demonstrated' (observed in real attacks) or 'feasible' (theoretical)."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / maturity / title
      Removed value: -"Maturity"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / modified_date / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / modified_date / description
      Removed value: -"ISO-8601 date of the most recent ATLAS update for this technique."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / modified_date / title
      Removed value: -"Modified Date"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / name / description
      Removed value: -"Human-readable technique name, e.g. 'Search Open Technical Databases'."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / name / title
      Removed value: -"Name"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / next_calls / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / next_calls / description
      Removed value: -"Suggested follow-up MCP tool calls. Ordered by relevance; agents should chain these without re-prompting the user."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / next_calls / title
      Removed value: -"Next Calls"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / subtechnique_of / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / subtechnique_of / description
      Removed value: -"Parent technique id when this is a sub-technique, e.g. 'AML.T0000' for 'AML.T0000.000'."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / subtechnique_of / title
      Removed value: -"Subtechnique Of"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / tactics / description
      Removed value: -"ATLAS tactic ids that this technique belongs to, e.g. ['AML.TA0002'] (Reconnaissance). Sub-techniques have empty tactics in upstream ATLAS; we backfill from the parent and set inherited_tactics=true when this happens."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / tactics / title
      Removed value: -"Tactics"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / technique_id / description
      Removed value: -"Canonical ATLAS technique id, e.g. 'AML.T0000', 'AML.T0000.000'."
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / technique_id / title
      Removed value: -"Technique Id"
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / verdict / default
      Removed value: -null
    • removedOutput schema / $defs / AtlasTechniqueResponse / properties / verdict / description
      Removed value: -"Falsifiability metadata: sources_queried, sources_unavailable, completeness, deterministic flag. Lets agents distinguish 'no data' from 'source failed' without re-running the call."
    • removedOutput schema / $defs / AtlasTechniqueResponse / title
      Removed value: -"AtlasTechniqueResponse"
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / description
      Removed value: -"One ATLAS technique outcome inside a bulk_atlas_technique_lookup response."
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / error / default
      Removed value: -null
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / error / description
      Removed value: -"Human-readable error message when status is 'not_found' or 'invalid_format'."
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / error / title
      Removed value: -"Error"
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / status / default
      Removed value: -"ok"
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / status / description
      Removed value: -"Per-item outcome (v1.21.0+ unified across bulk_cve/bulk_ioc/bulk_atlas): 'ok' = technique populated; 'not_found' = id not in synced ATLAS catalog; 'invalid_format' = id failed AML.T#### / AML.T####.### regex; 'error' = transient lookup failure (DB I/O exception) — rare, server-side fallback only."
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / status / title
      Removed value: -"Status"
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / technique / default
      Removed value: -null
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / technique / description
      Removed value: -"Full ATLAS technique record when status='ok'. Same shape as /v1/atlas/{technique_id}."
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / technique_id / description
      Removed value: -"Echoed input ATLAS technique id (upper-cased + de-duplicated)."
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / properties / technique_id / title
      Removed value: -"Technique Id"
    • removedOutput schema / $defs / BulkAtlasTechniqueItem / title
      Removed value: -"BulkAtlasTechniqueItem"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / failed / default
      Removed value: -0
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / failed / description
      Removed value: -"Count of items with status='not_found' or 'invalid_format'."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / failed / title
      Removed value: -"Failed"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / next_calls / default
      Removed value: -null
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / next_calls / description
      Removed value: -"Suggested follow-up MCP tool calls. Ordered by relevance; agents should chain these without re-prompting the user."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / next_calls / title
      Removed value: -"Next Calls"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / partial / default
      Removed value: -false
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / partial / description
      Removed value: -"True when at least one item was not_found, invalid_format, or skipped due to rate limit."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / partial / title
      Removed value: -"Partial"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / processed / default
      Removed value: -0
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / processed / description
      Removed value: -"Count of items actually looked up (== len(results)). Equal to total unless dynamic-budget partial-fill kicked in."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / processed / title
      Removed value: -"Processed"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / results / description
      Removed value: -"Per-technique outcome list, preserving input order after upper-case de-duplication."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / results / title
      Removed value: -"Results"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / skipped_due_to_rate_limit / description
      Removed value: -"Technique IDs that were not processed because the caller's remaining hourly quota was smaller than the input list. Empty when full budget was available."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / skipped_due_to_rate_limit / title
      Removed value: -"Skipped Due To Rate Limit"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / successful / default
      Removed value: -0
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / successful / description
      Removed value: -"Count of items with status='ok'."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / successful / title
      Removed value: -"Successful"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / summary / default
      Removed value: -""
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / summary / description
      Removed value: -"One-line aggregate summary (e.g. '4/5 techniques found')."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / summary / title
      Removed value: -"Summary"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / total / default
      Removed value: -0
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / total / description
      Removed value: -"Total number of unique technique IDs submitted (== processed + len(skipped_due_to_rate_limit))."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / total / title
      Removed value: -"Total"
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / verdict / default
      Removed value: -null
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / verdict / description
      Removed value: -"Falsifiability metadata: sources_queried, sources_unavailable, completeness, deterministic flag. Lets agents distinguish 'no data' from 'source failed' without re-running the call."
    • removedOutput schema / $defs / BulkAtlasTechniqueResponse / title
      Removed value: -"BulkAtlasTechniqueResponse"
    • removedOutput schema / $defs / ErrorDetail / description
      Removed value: -"Structured failure body. Codes mirror app/exceptions.AppException\nsubclasses; agent retry / upgrade decisions key off `code`, not `message`."
    • removedOutput schema / $defs / ErrorDetail / properties / code / description
      Removed value: -"Stable machine-readable failure category. Agents key retry/upgrade decisions off this."
    • removedOutput schema / $defs / ErrorDetail / properties / code / title
      Removed value: -"Code"
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / description
      Removed value: -"Documentation pointer (e.g. tool input contract) when code='invalid_argument'."
    • removedOutput schema / $defs / ErrorDetail / properties / docs_url / title
      Removed value: -"Docs Url"
    • removedOutput schema / $defs / ErrorDetail / properties / message / description
      Removed value: -"Human-readable detail. Free text — never parse. Capped at 500 chars to prevent oversized upstream errors from bloating responses."
    • removedOutput schema / $defs / ErrorDetail / properties / message / title
      Removed value: -"Message"
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / description
      Removed value: -"When code='rate_limit_exceeded', the minimum seconds to wait before retrying."
    • removedOutput schema / $defs / ErrorDetail / properties / retry_after_seconds / title
      Removed value: -"Retry After Seconds"
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / default
      Removed value: -null
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / description
      Removed value: -"Pricing/upgrade URL when code='tier_limit' or 'rate_limit_exceeded' on the Free tier."
    • removedOutput schema / $defs / ErrorDetail / properties / upgrade_url / title
      Removed value: -"Upgrade Url"
    • removedOutput schema / $defs / ErrorDetail / title
      Removed value: -"ErrorDetail"
    • removedOutput schema / $defs / ErrorResponse / description
      Removed value: -"MCP error envelope. Tool return type is always\n`SpecificResponse | ErrorResponse` — Union flag tells the agent which arm\narrived without parsing the inner body."
    • removedOutput schema / $defs / ErrorResponse / title
      Removed value: -"ErrorResponse"
    • removedOutput schema / $defs / PivotHint / description
      Removed value: -"A suggested follow-up MCP tool call. Surfaced inside response.next_calls so\nLLM agents can chain related lookups without manual prompting. Each hint names\nthe tool, the input value to pass, and a short reason explaining why this\npivot adds value in the current context."
    • removedOutput schema / $defs / PivotHint / properties / input / description
      Removed value: -"Suggested input value to pass to the tool — typically a CVE ID, CWE ID, domain, or IP. Pre-populated from the current response so the agent can call the next tool without re-deriving the argument."
    • removedOutput schema / $defs / PivotHint / properties / input / title
      Removed value: -"Input"
    • removedOutput schema / $defs / PivotHint / properties / params / default
      Removed value: -null
    • removedOutput schema / $defs / PivotHint / properties / params / description
      Removed value: -"Optional extra kwargs to pass alongside `input`. Used by pivot generators when the next call benefits from a secondary parameter, e.g. {'exclude_id': 'AML.T0051'} to skip the originating technique from a sibling-tactic search. Omitted when no extra args are needed."
    • removedOutput schema / $defs / PivotHint / properties / params / title
      Removed value: -"Params"
    • removedOutput schema / $defs / PivotHint / properties / reason / description
      Removed value: -"Short rationale (one sentence) for why this follow-up call adds value, e.g. 'Federal patch deadline + ransomware association', 'Public exploits / PoC availability'."
    • removedOutput schema / $defs / PivotHint / properties / reason / title
      Removed value: -"Reason"
    • removedOutput schema / $defs / PivotHint / properties / tool / description
      Removed value: -"Canonical MCP tool name to call next. Constrained to known operation_ids in tools/list — adding a new tool here requires expanding the Literal."
    • removedOutput schema / $defs / PivotHint / properties / tool / title
      Removed value: -"Tool"
    • removedOutput schema / $defs / PivotHint / title
      Removed value: -"PivotHint"
    • removedOutput schema / $defs / Verdict / properties / completeness / default
      Removed value: -"complete"
    • removedOutput schema / $defs / Verdict / properties / completeness / description
      Removed value: -"'complete' = every planned source returned data; 'partial' = at least one source in sources_unavailable failed or was skipped; 'minimal' = only the primary/required source returned, optional enrichment missing."
    • removedOutput schema / $defs / Verdict / properties / completeness / title
      Removed value: -"Completeness"
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / default
      Removed value: -null
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / description
      Removed value: -"Seconds elapsed since the oldest cached source was fetched, or null when every source was queried live for this request. Use to judge freshness."
    • removedOutput schema / $defs / Verdict / properties / data_age_seconds / title
      Removed value: -"Data Age Seconds"
    • removedOutput schema / $defs / Verdict / properties / deterministic / description
      Removed value: -"True when the response is fully reproducible from the listed sources for the same input at the same moment (no randomness, no model inference). False for endpoints that include probabilistic scoring or LLM output."
    • removedOutput schema / $defs / Verdict / properties / deterministic / title
      Removed value: -"Deterministic"
    • removedOutput schema / $defs / Verdict / properties / falsifiable_fields / description
      Removed value: -"Top-level response fields whose values a caller can independently re-derive from the named upstream sources (e.g. 'dns', 'ssl', 'whois'). Fields not in this list are derived/computed and cannot be directly re-verified."
    • removedOutput schema / $defs / Verdict / properties / falsifiable_fields / title
      Removed value: -"Falsifiable Fields"
    • removedOutput schema / $defs / Verdict / properties / sources_queried / description
      Removed value: -"Canonical source identifiers successfully consulted for this response (e.g. 'ripe_stat', 'shodan_internetdb', 'firehol'). Agent-readable list, order not significant."
    • removedOutput schema / $defs / Verdict / properties / sources_queried / title
      Removed value: -"Sources Queried"
    • removedOutput schema / $defs / Verdict / properties / sources_unavailable / description
      Removed value: -"Sources that were expected but not returned — either intentionally skipped (lite mode, tier gating) or failed (quota, timeout, upstream down). Empty list means every planned source produced data."
    • removedOutput schema / $defs / Verdict / properties / sources_unavailable / title
      Removed value: -"Sources Unavailable"
    • removedOutput schema / $defs / Verdict / title
      Removed value: -"Verdict"
    • removedOutput schema / properties / result / title
      Removed value: -"Result"
    • removedOutput schema / title
      Removed value: -"bulk_atlas_technique_lookupOutput"
  6. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "calculate_risk_score",
      -  "get_cvss_details",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_security_posture",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage",
      -  "sigma_rule_lookup",
      -  "bulk_sigma_rule_lookup"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_security_posture",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage",
      +  "sigma_rule_lookup",
      +  "bulk_sigma_rule_lookup",
      +  "tech_stack_cve_audit"
      +]
  7. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "calculate_risk_score",
      -  "get_cvss_details",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_security_posture",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_security_posture",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage",
      +  "sigma_rule_lookup",
      +  "bulk_sigma_rule_lookup"
      +]
  8. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "calculate_risk_score",
      -  "get_cvss_details",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_security_posture",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage"
      +]
  9. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_disposable",
      -  "email_verify",
      -  "robots_txt",
      -  "redirect_chain",
      -  "brand_assets",
      -  "seo_audit",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "calculate_risk_score",
      +  "get_cvss_details",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage"
      +]
  10. Changed4 schema fields changed
    • changedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / partial / description
      Previous value: -"True when at least one item was not_found or invalid_format."New value: +"True when at least one item was not_found, invalid_format, or skipped due to rate limit."
    • addedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / processed
      Added value: +{
      +  "default": 0,
      +  "description": "Count of items actually looked up (== len(results)). Equal to total unless dynamic-budget partial-fill kicked in.",
      +  "title": "Processed",
      +  "type": "integer"
      +}
    • addedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / skipped_due_to_rate_limit
      Added value: +{
      +  "description": "Technique IDs that were not processed because the caller's remaining hourly quota was smaller than the input list. Empty when full budget was available.",
      +  "items": {
      +    "type": "string"
      +  },
      +  "title": "Skipped Due To Rate Limit",
      +  "type": "array"
      +}
    • changedOutput schema / $defs / BulkAtlasTechniqueResponse / properties / total / description
      Previous value: -"Total number of unique technique IDs processed (== len(results))."New value: +"Total number of unique technique IDs submitted (== processed + len(skipped_due_to_rate_limit))."
  11. Changed1 schema field changed
    • changedOutput schema / $defs / PivotHint / properties / tool / enum
      Previous value: -[
      -  "cve_lookup",
      -  "cve_search",
      -  "cve_leading",
      -  "bulk_cve_lookup",
      -  "exploit_lookup",
      -  "kev_detail",
      -  "cwe_lookup",
      -  "subdomain_enum",
      -  "ssl_check",
      -  "tech_fingerprint",
      -  "asn_lookup",
      -  "ip_lookup",
      -  "ioc_lookup",
      -  "bulk_ioc_lookup",
      -  "hash_lookup",
      -  "threat_intel",
      -  "threat_report",
      -  "audit_domain",
      -  "domain_report",
      -  "dns_lookup",
      -  "whois_lookup",
      -  "wayback_lookup",
      -  "scan_headers",
      -  "check_headers",
      -  "check_secrets",
      -  "check_injection",
      -  "check_dependencies",
      -  "email_mx",
      -  "email_disposable",
      -  "phone_lookup",
      -  "username_lookup",
      -  "password_check",
      -  "phishing_check",
      -  "atlas_technique_lookup",
      -  "atlas_technique_search",
      -  "bulk_atlas_technique_lookup",
      -  "atlas_case_study_lookup",
      -  "atlas_case_study_search",
      -  "d3fend_defense_lookup",
      -  "d3fend_defense_search",
      -  "d3fend_defense_for_attack",
      -  "d3fend_attack_coverage"
      -]New value: +[
      +  "cve_lookup",
      +  "cve_search",
      +  "cve_leading",
      +  "bulk_cve_lookup",
      +  "exploit_lookup",
      +  "kev_detail",
      +  "cwe_lookup",
      +  "subdomain_enum",
      +  "ssl_check",
      +  "tech_fingerprint",
      +  "asn_lookup",
      +  "ip_lookup",
      +  "ioc_lookup",
      +  "bulk_ioc_lookup",
      +  "hash_lookup",
      +  "threat_intel",
      +  "threat_report",
      +  "audit_domain",
      +  "domain_report",
      +  "dns_lookup",
      +  "whois_lookup",
      +  "wayback_lookup",
      +  "scan_headers",
      +  "check_headers",
      +  "check_secrets",
      +  "check_injection",
      +  "check_dependencies",
      +  "email_mx",
      +  "email_disposable",
      +  "email_verify",
      +  "robots_txt",
      +  "redirect_chain",
      +  "brand_assets",
      +  "seo_audit",
      +  "phone_lookup",
      +  "username_lookup",
      +  "password_check",
      +  "phishing_check",
      +  "atlas_technique_lookup",
      +  "atlas_technique_search",
      +  "bulk_atlas_technique_lookup",
      +  "atlas_case_study_lookup",
      +  "atlas_case_study_search",
      +  "d3fend_defense_lookup",
      +  "d3fend_defense_search",
      +  "d3fend_defense_for_attack",
      +  "d3fend_attack_coverage"
      +]
  12. Changed3 schema fields changed
    • addedOutput schema / $defs
      Added value: +{
      +  "AtlasTechniqueResponse": {
      +    "additionalProperties": true,
      +    "description": "MITRE ATLAS technique record (AI/ML attack catalog).\n\nATLAS catalogues adversarial techniques targeting AI/ML systems (LLM prompt\ninjection, model poisoning, evasion). About 80% of techniques have no ATT&CK\nbridge — ATLAS is the canonical reference for AI/ML-specific TTPs.",
      +    "properties": {
      +      "attack_reference_id": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Bridged ATT&CK technique id when ATLAS cites a parallel enterprise TTP, e.g. 'T1596'. About 20% of ATLAS techniques carry an ATT&CK reference; use this to pivot to D3FEND defenses.",
      +        "title": "Attack Reference Id"
      +      },
      +      "attack_reference_url": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Canonical ATT&CK URL for the bridged technique, e.g. 'https://attack.mitre.org/techniques/T1596/'.",
      +        "title": "Attack Reference Url"
      +      },
      +      "created_date": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "ISO-8601 date the technique was first published in ATLAS.",
      +        "title": "Created Date"
      +      },
      +      "description": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Full technique description as published by MITRE ATLAS. May be multi-paragraph.",
      +        "title": "Description"
      +      },
      +      "inherited_tactics": {
      +        "anyOf": [
      +          {
      +            "type": "boolean"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "True when `tactics` was inherited from the parent technique (this is a sub-technique). Omitted when tactics are native to the record.",
      +        "title": "Inherited Tactics"
      +      },
      +      "maturity": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "MITRE ATLAS maturity classification: 'demonstrated' (observed in real attacks) or 'feasible' (theoretical).",
      +        "title": "Maturity"
      +      },
      +      "modified_date": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "ISO-8601 date of the most recent ATLAS update for this technique.",
      +        "title": "Modified Date"
      +      },
      +      "name": {
      +        "description": "Human-readable technique name, e.g. 'Search Open Technical Databases'.",
      +        "title": "Name",
      +        "type": "string"
      +      },
      +      "next_calls": {
      +        "anyOf": [
      +          {
      +            "items": {
      +              "$ref": "#/$defs/PivotHint"
      +            },
      +            "type": "array"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Suggested follow-up MCP tool calls. Ordered by relevance; agents should chain these without re-prompting the user.",
      +        "title": "Next Calls"
      +      },
      +      "subtechnique_of": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Parent technique id when this is a sub-technique, e.g. 'AML.T0000' for 'AML.T0000.000'.",
      +        "title": "Subtechnique Of"
      +      },
      +      "tactics": {
      +        "description": "ATLAS tactic ids that this technique belongs to, e.g. ['AML.TA0002'] (Reconnaissance). Sub-techniques have empty tactics in upstream ATLAS; we backfill from the parent and set inherited_tactics=true when this happens.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "title": "Tactics",
      +        "type": "array"
      +      },
      +      "technique_id": {
      +        "description": "Canonical ATLAS technique id, e.g. 'AML.T0000', 'AML.T0000.000'.",
      +        "title": "Technique Id",
      +        "type": "string"
      +      },
      +      "verdict": {
      +        "anyOf": [
      +          {
      +            "$ref": "#/$defs/Verdict"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Falsifiability metadata: sources_queried, sources_unavailable, completeness, deterministic flag. Lets agents distinguish 'no data' from 'source failed' without re-running the call."
      +      }
      +    },
      +    "required": [
      +      "technique_id",
      +      "name"
      +    ],
      +    "title": "AtlasTechniqueResponse",
      +    "type": "object"
      +  },
      +  "BulkAtlasTechniqueItem": {
      +    "additionalProperties": true,
      +    "description": "One ATLAS technique outcome inside a bulk_atlas_technique_lookup response.",
      +    "properties": {
      +      "error": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Human-readable error message when status is 'not_found' or 'invalid_format'.",
      +        "title": "Error"
      +      },
      +      "status": {
      +        "default": "ok",
      +        "description": "Per-item outcome (v1.21.0+ unified across bulk_cve/bulk_ioc/bulk_atlas): 'ok' = technique populated; 'not_found' = id not in synced ATLAS catalog; 'invalid_format' = id failed AML.T#### / AML.T####.### regex; 'error' = transient lookup failure (DB I/O exception) — rare, server-side fallback only.",
      +        "enum": [
      +          "ok",
      +          "error",
      +          "not_found",
      +          "invalid_format"
      +        ],
      +        "title": "Status",
      +        "type": "string"
      +      },
      +      "technique": {
      +        "anyOf": [
      +          {
      +            "$ref": "#/$defs/AtlasTechniqueResponse"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Full ATLAS technique record when status='ok'. Same shape as /v1/atlas/{technique_id}."
      +      },
      +      "technique_id": {
      +        "description": "Echoed input ATLAS technique id (upper-cased + de-duplicated).",
      +        "title": "Technique Id",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "technique_id"
      +    ],
      +    "title": "BulkAtlasTechniqueItem",
      +    "type": "object"
      +  },
      +  "BulkAtlasTechniqueResponse": {
      +    "additionalProperties": true,
      +    "properties": {
      +      "failed": {
      +        "default": 0,
      +        "description": "Count of items with status='not_found' or 'invalid_format'.",
      +        "title": "Failed",
      +        "type": "integer"
      +      },
      +      "next_calls": {
      +        "anyOf": [
      +          {
      +            "items": {
      +              "$ref": "#/$defs/PivotHint"
      +            },
      +            "type": "array"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Suggested follow-up MCP tool calls. Ordered by relevance; agents should chain these without re-prompting the user.",
      +        "title": "Next Calls"
      +      },
      +      "partial": {
      +        "default": false,
      +        "description": "True when at least one item was not_found or invalid_format.",
      +        "title": "Partial",
      +        "type": "boolean"
      +      },
      +      "results": {
      +        "description": "Per-technique outcome list, preserving input order after upper-case de-duplication.",
      +        "items": {
      +          "$ref": "#/$defs/BulkAtlasTechniqueItem"
      +        },
      +        "title": "Results",
      +        "type": "array"
      +      },
      +      "successful": {
      +        "default": 0,
      +        "description": "Count of items with status='ok'.",
      +        "title": "Successful",
      +        "type": "integer"
      +      },
      +      "summary": {
      +        "default": "",
      +        "description": "One-line aggregate summary (e.g. '4/5 techniques found').",
      +        "title": "Summary",
      +        "type": "string"
      +      },
      +      "total": {
      +        "default": 0,
      +        "description": "Total number of unique technique IDs processed (== len(results)).",
      +        "title": "Total",
      +        "type": "integer"
      +      },
      +      "verdict": {
      +        "anyOf": [
      +          {
      +            "$ref": "#/$defs/Verdict"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Falsifiability metadata: sources_queried, sources_unavailable, completeness, deterministic flag. Lets agents distinguish 'no data' from 'source failed' without re-running the call."
      +      }
      +    },
      +    "title": "BulkAtlasTechniqueResponse",
      +    "type": "object"
      +  },
      +  "ErrorDetail": {
      +    "description": "Structured failure body. Codes mirror app/exceptions.AppException\nsubclasses; agent retry / upgrade decisions key off `code`, not `message`.",
      +    "properties": {
      +      "code": {
      +        "description": "Stable machine-readable failure category. Agents key retry/upgrade decisions off this.",
      +        "enum": [
      +          "invalid_argument",
      +          "not_found",
      +          "rate_limit_exceeded",
      +          "auth_required",
      +          "tier_limit",
      +          "upstream_timeout",
      +          "upstream_error",
      +          "internal_error"
      +        ],
      +        "title": "Code",
      +        "type": "string"
      +      },
      +      "docs_url": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Documentation pointer (e.g. tool input contract) when code='invalid_argument'.",
      +        "title": "Docs Url"
      +      },
      +      "message": {
      +        "description": "Human-readable detail. Free text — never parse. Capped at 500 chars to prevent oversized upstream errors from bloating responses.",
      +        "maxLength": 500,
      +        "title": "Message",
      +        "type": "string"
      +      },
      +      "retry_after_seconds": {
      +        "anyOf": [
      +          {
      +            "type": "integer"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "When code='rate_limit_exceeded', the minimum seconds to wait before retrying.",
      +        "title": "Retry After Seconds"
      +      },
      +      "upgrade_url": {
      +        "anyOf": [
      +          {
      +            "type": "string"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Pricing/upgrade URL when code='tier_limit' or 'rate_limit_exceeded' on the Free tier.",
      +        "title": "Upgrade Url"
      +      }
      +    },
      +    "required": [
      +      "code",
      +      "message"
      +    ],
      +    "title": "ErrorDetail",
      +    "type": "object"
      +  },
      +  "ErrorResponse": {
      +    "description": "MCP error envelope. Tool return type is always\n`SpecificResponse | ErrorResponse` — Union flag tells the agent which arm\narrived without parsing the inner body.",
      +    "properties": {
      +      "error": {
      +        "$ref": "#/$defs/ErrorDetail"
      +      }
      +    },
      +    "required": [
      +      "error"
      +    ],
      +    "title": "ErrorResponse",
      +    "type": "object"
      +  },
      +  "PivotHint": {
      +    "additionalProperties": true,
      +    "description": "A suggested follow-up MCP tool call. Surfaced inside response.next_calls so\nLLM agents can chain related lookups without manual prompting. Each hint names\nthe tool, the input value to pass, and a short reason explaining why this\npivot adds value in the current context.",
      +    "properties": {
      +      "input": {
      +        "description": "Suggested input value to pass to the tool — typically a CVE ID, CWE ID, domain, or IP. Pre-populated from the current response so the agent can call the next tool without re-deriving the argument.",
      +        "title": "Input",
      +        "type": "string"
      +      },
      +      "params": {
      +        "anyOf": [
      +          {
      +            "additionalProperties": {
      +              "type": "string"
      +            },
      +            "type": "object"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Optional extra kwargs to pass alongside `input`. Used by pivot generators when the next call benefits from a secondary parameter, e.g. {'exclude_id': 'AML.T0051'} to skip the originating technique from a sibling-tactic search. Omitted when no extra args are needed.",
      +        "title": "Params"
      +      },
      +      "reason": {
      +        "description": "Short rationale (one sentence) for why this follow-up call adds value, e.g. 'Federal patch deadline + ransomware association', 'Public exploits / PoC availability'.",
      +        "title": "Reason",
      +        "type": "string"
      +      },
      +      "tool": {
      +        "description": "Canonical MCP tool name to call next. Constrained to known operation_ids in tools/list — adding a new tool here requires expanding the Literal.",
      +        "enum": [
      +          "cve_lookup",
      +          "cve_search",
      +          "cve_leading",
      +          "bulk_cve_lookup",
      +          "exploit_lookup",
      +          "kev_detail",
      +          "cwe_lookup",
      +          "subdomain_enum",
      +          "ssl_check",
      +          "tech_fingerprint",
      +          "asn_lookup",
      +          "ip_lookup",
      +          "ioc_lookup",
      +          "bulk_ioc_lookup",
      +          "hash_lookup",
      +          "threat_intel",
      +          "threat_report",
      +          "audit_domain",
      +          "domain_report",
      +          "dns_lookup",
      +          "whois_lookup",
      +          "wayback_lookup",
      +          "scan_headers",
      +          "check_headers",
      +          "check_secrets",
      +          "check_injection",
      +          "check_dependencies",
      +          "email_mx",
      +          "email_disposable",
      +          "phone_lookup",
      +          "username_lookup",
      +          "password_check",
      +          "phishing_check",
      +          "atlas_technique_lookup",
      +          "atlas_technique_search",
      +          "bulk_atlas_technique_lookup",
      +          "atlas_case_study_lookup",
      +          "atlas_case_study_search",
      +          "d3fend_defense_lookup",
      +          "d3fend_defense_search",
      +          "d3fend_defense_for_attack",
      +          "d3fend_attack_coverage"
      +        ],
      +        "title": "Tool",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "tool",
      +      "input",
      +      "reason"
      +    ],
      +    "title": "PivotHint",
      +    "type": "object"
      +  },
      +  "Verdict": {
      +    "properties": {
      +      "completeness": {
      +        "default": "complete",
      +        "description": "'complete' = every planned source returned data; 'partial' = at least one source in sources_unavailable failed or was skipped; 'minimal' = only the primary/required source returned, optional enrichment missing.",
      +        "enum": [
      +          "complete",
      +          "partial",
      +          "minimal"
      +        ],
      +        "title": "Completeness",
      +        "type": "string"
      +      },
      +      "data_age_seconds": {
      +        "anyOf": [
      +          {
      +            "type": "integer"
      +          },
      +          {
      +            "type": "null"
      +          }
      +        ],
      +        "default": null,
      +        "description": "Seconds elapsed since the oldest cached source was fetched, or null when every source was queried live for this request. Use to judge freshness.",
      +        "title": "Data Age Seconds"
      +      },
      +      "deterministic": {
      +        "description": "True when the response is fully reproducible from the listed sources for the same input at the same moment (no randomness, no model inference). False for endpoints that include probabilistic scoring or LLM output.",
      +        "title": "Deterministic",
      +        "type": "boolean"
      +      },
      +      "falsifiable_fields": {
      +        "description": "Top-level response fields whose values a caller can independently re-derive from the named upstream sources (e.g. 'dns', 'ssl', 'whois'). Fields not in this list are derived/computed and cannot be directly re-verified.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "title": "Falsifiable Fields",
      +        "type": "array"
      +      },
      +      "sources_queried": {
      +        "description": "Canonical source identifiers successfully consulted for this response (e.g. 'ripe_stat', 'shodan_internetdb', 'firehol'). Agent-readable list, order not significant.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "title": "Sources Queried",
      +        "type": "array"
      +      },
      +      "sources_unavailable": {
      +        "description": "Sources that were expected but not returned — either intentionally skipped (lite mode, tier gating) or failed (quota, timeout, upstream down). Empty list means every planned source produced data.",
      +        "items": {
      +          "type": "string"
      +        },
      +        "title": "Sources Unavailable",
      +        "type": "array"
      +      }
      +    },
      +    "required": [
      +      "deterministic"
      +    ],
      +    "title": "Verdict",
      +    "type": "object"
      +  }
      +}
    • addedOutput schema / properties / result / anyOf
      Added value: +[
      +  {
      +    "$ref": "#/$defs/BulkAtlasTechniqueResponse"
      +  },
      +  {
      +    "$ref": "#/$defs/ErrorResponse"
      +  }
      +]
    • removedOutput schema / properties / result / type
      Removed value: -"string"
  13. Added

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Despite annotations already declaring readOnly/idempotent/destructive flags, the description enriches behavior with per-item details: 'parent-tactics inheritance... inherited_tactics=true flag,' 'per-item next_calls' with D3FEND/sibling/parent options, and the response envelope including partial-failure statuses. This goes well beyond structured metadata.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Though long, the description front-loads the core purpose in the first clause and then packs each subsequent sentence with necessary detail (per-item shape, next_calls, rate limits, return structure). No filler; the length is justified by the tool's complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the full usage lifecycle: when to use, input constraints, per-item result shape with error statuses, follow-up actions from next_calls, rate limits, and the top-level response fields. With output schema and annotations present, nothing critical is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema covers technique_ids with format, max, case-insensitivity, normalization/de-dup, and per-item rate count (100% coverage). The description does not add new param semantics beyond restating the 50-technique limit, so baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states 'retrieve full records for up to 50 techniques in a single request' and contrasts with 'N separate atlas_technique_lookup calls,' distinguishing it from the sibling single-lookup tool. Also names the natural predecessor (atlas_case_study_lookup), making the purpose concrete.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly frames it as 'instead of N separate atlas_technique_lookup calls' and as 'the natural follow-up to atlas_case_study_lookup,' telling the agent when to choose this bulk tool. Also notes rate-limit implications (1 per item), helping with batch planning.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.