threatmodel-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@threatmodel-mcpCreate a threat model for my web app with user, web server, and database."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ThreatModel-MCP
Model Context Protocol server for AI-powered threat modeling.
Demo

Related MCP server: MCP SSDLC Security Toolkit
Setup
Install dependenciespip install -r requirements.txtInstall Graphviz(optional, for PNG diagrams)Windows: Download from https://graphviz.org/download/
Mac: brew install graphviz
Linux: sudo apt-get install graphviz
Configure MCP client(Claude Desktop, etc.){ "mcpServers": { "threatmodel": { "command": "python", "args": ["/full/path/to/threatmodel_server.py"] } } }
Available Tools
create_threat_model
Creates comprehensive threat models with components, boundaries, and data flows.
Parameters:
system_name - Name of the system
components - Array of system components with types, boundaries, security controls
boundaries - Trust boundaries with security levels (0-10)
dataflows - Data flows between components with protocols and classifications
output_format - "diagram", "pytm_code", "threats", or "full_analysis"
auto_save - Auto-save files (default: true)
save_path - Directory to save files (default: current directory)
analyze_security_threats
Performs deep security analysis using multiple frameworks.
Parameters:
analysis_depth - "basic", "standard", "comprehensive", or "paranoid"
threat_frameworks - ["STRIDE", "MITRE_ATTACK", "OWASP", "NIST", "CIS"]
focus_areas - Authentication, data protection, network security, etc.
compliance_frameworks - ["SOC2", "ISO27001", "HIPAA", "PCI-DSS", "GDPR"]
generate_security_controls
Generates security control recommendations based on threats.
Parameters:
threats - Array of identified threats
risk_appetite - "low", "medium", or "high"
technology_stack - Current technologies (AWS, k8s, etc.)
prioritization_method - "risk_based", "quick_wins", "compliance_driven"
validate_architecture
Validates architecture against security best practices.
Parameters:
components - System components to validate
validation_rules - ["zero_trust", "encryption_in_transit", "api_gateway_pattern"]
architecture_patterns - ["microservices", "serverless", "hybrid_cloud"]
Component Types
Actors: user, admin, service_account Services: server, api_gateway, microservice, lambda, container Data: database, cache, message_queue, file_storage Infrastructure: load_balancer, firewall, external_service
Protocols & Classifications
Protocols: HTTPS, gRPC, WebSocket, SQL, Redis, S3 API Data Classifications: PUBLIC → INTERNAL → CONFIDENTIAL → RESTRICTED → TOP_SECRET
Auto-Save Features
Generated files (with timestamps):
SystemName_threatmodel_YYYYMMDD_HHMMSS.png - Diagram (when output_format="diagram")
SystemName_threatmodel_YYYYMMDD_HHMMSS.dot - DOT source (always)
SystemName_threatmodel_YYYYMMDD_HHMMSS.py - PyTM code (always)
SystemName_threatmodel_analysis_YYYYMMDD_HHMMSS.md - Analysis report (when output_format="full_analysis")
Example Usage
Example 1: Codebase Analysis
Prompt: "Create a high level threat diagram of current codebase"

Example threat model diagram generated from a cloned OpenAI Codex codebase, showing multi-layer security boundaries, component classifications, and encrypted data flows between services.
Example 2: Web Application Architecture
Prompt: "A web application where the user interacts with a web server, which in turn communicates with a database server. The web server and database server are outside the user's trust boundary. The user connects to the web application via a browser. The web server handles requests and responses, and the database server stores application data. The trust boundary is around the user only; both the web server and database server are outside this boundary"

Example threat model showing user trust boundary with web and database servers in untrusted zone.
Refer to threat analysis report in assets/Web_Application_System_Threat_Analysis_Report.md
Troubleshooting
Graphviz issues: Verify with dot -V DOT syntax errors: Component names automatically sanitized No Python: Ensure Python in PATH
This server cannot be deployed
Maintenance
Related MCP Connectors
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI-powered security scanning of codebases through conversational analysis, allowing users to assess, threat model, code review, DAST test, and generate security reports using natural language with Claude.MIT
- AlicenseBqualityDmaintenanceEnables orchestrating secure software development pipelines with domain-specific compliance (HIPAA, PCI-DSS, etc.), generating pseudocode, threat models, and CI/CD from user stories via natural language.17MIT
- AlicenseNot gradedqualityCmaintenanceAutomates 85-95% of the Secure Software Development Lifecycle (SSDLC) planning phase through multi-role AI orchestration, enabling business analysis, threat modeling, test strategy design, and security code review.MIT

Aribot MCPofficial
AlicenseNot gradedqualityBmaintenanceEnables security work such as threat modeling, scanning, compliance checks, and remediation through AI assistants using the Model Context Protocol.MIT