一个用于全面威胁建模的模型上下文协议(MCP)服务器,具备自动代码验证功能。
该服务器提供威胁建模工具,包括业务上下文分析、架构分析、威胁行为者分析、信任边界分析、资产流分析、代码安全验证以及综合报告生成。
此 MCP 服务器调用现有代理的 LLM,而非对外部 API 或其他服务进行网络调用。它依赖于现有客户端的 LLM,可能是 Amazon-Q、Kiro 或 Cline。
此威胁建模 MCP 服务器具有三项主要功能:
它还具备生成最终报告的工具,支持 Markdown 和 JSON 可导出格式。
.threatmodel 目录中,您可以根据代码、设计和架构的演变来演进威胁模型。注意: 在使用这些提示之前,您必须先完成安装过程来设置 MCP 服务器。
"Threat model this project using the threat modeling MCP Server"
在提示中明确要求使用威胁建模MCP服务器将确保客户端(Cline/Kiro等)遵循准确的阶段和方法,而不是走捷径并引入结果幻觉。
### 对子项目进行威胁建模或将范围缩小到子文件夹```
"Threat model this subfolder using the threat modeling MCP Server"
在子文件夹上运行会将威胁模型和代码的范围限制在该子文件夹内,并将结果保存为该子文件夹下的.threatmodel目录。
"Save the threat model report"
### 验证威胁建模过程的完整性```
"Please complete all the phases in the threat model plan and then generate the final report."
"Threat model this project using the threat model MCP server and consider this architecture_image.png attached for this review"
### 尝试缓解威胁```
"Can you see if you can implement mitigation controls in the code based on the threats reported in the threat model"
"Can you updated the threat model based on the code fixes which mitigated the reported threats"
### 更多示例```bash
# Set up context
"Set business context for an e-commerce payment system"
# Add architecture
"Add a web server component using AWS EC2"
"Add a database component using AWS RDS"
# Identify threats
"Add a threat where an attacker with network access performs SQL injection"
# Add mitigations
"Add a mitigation for input validation"
# Export results
"Export the threat model to my_model.json"
在安装威胁建模MCP服务器之前,请确保满足以下要求:
uvx
uvx --version安装并验证 uvx 正常工作后,将以下配置添加到您的 mcp.json 配置文件中。根据您使用的客户端类型(kiro/cline/amazon-q),mcp.json 的位置会有所不同。添加配置并重启 IDE 后,威胁建模 MCP 服务器将自动通过 uvx 直接从本 GitHub 仓库安装。
注意: 此MCP服务器用于威胁建模的工具已添加到
autoApprove中,以提升用户体验,实现无缝操作,无需对每个工具调用进行手动批准提示。所有工具均为服务器内部工具,不进行外部API调用。如果您希望每次调用时审查并批准每个工具,则需要将 autoApprove 数组替换为:"autoApprove": []
将以下内容添加到您的MCP客户端配置中: