Skip to content

For agents and the people who build them

The seven Lattice tools and their exact arguments

What each read-only tool returns, the argument names to send, the five path templates, and which tools work without a key.

4 minute read

What you are connecting to

Lattice is a read-only MCP server over a graph of public cybersecurity sources: CVE entries, CISA known-exploited status, MITRE ATT&CK techniques, CWE weaknesses, threat groups and detection rules. Every tool only reads a published snapshot. Calling a tool twice gives the same answer, and none of them changes anything.

The endpoint is https://lattice.namiq.io/mcp over streamable HTTP. Send a key in the X-API-Key header. Discovery (initialize and tools/list) needs no key, so an agent can read this list before anyone signs up.

The tools

An argument followed by a question mark is optional. id is an external id; uid is the graph's own identifier and comes from an earlier answer.

ToolArguments (exact names)What comes back
graph_metanoneThe snapshot id, the node types, the relationship verbs, the sources and the path templates. Call it once at the start of a session.
graph_lookupid, label?The nodes with that exact external id, such as CVE-2021-44228, T1059.001 or CWE-79, each with its source and a uid. A CVE can return two nodes: the CISA known-exploited entry and the NVD entry.
graph_searchid_prefix, label?, limit?, cursor?Ids that start with a prefix such as CVE-2024-1 or T105. Ids only, not free text. If the answer says truncated, pass next_cursor as cursor.
graph_nodeuidOne node's properties, by the uid a lookup or search returned.
graph_neighborsuid, direction?, verb?, label?, limit?, cursor?The directly connected nodes, each link with its verb, its source, and whether it is declared or inferred.
graph_pathtemplate, id, label?A fixed multi-step question from an external id. The templates are listed below.
graph_noticesids?The licence and attribution notices of the sources an answer used.

The five path templates

TemplateThe question it answers
cve-to-defenseWhich ATT&CK techniques does this CVE enable, and then which detections and response procedures exist for them?
cve-contextWhat surrounds this CVE: its weakness, its known-exploited entry, the products it names?
technique-coverageFor this technique, which detections exist, and which sources hold them?
weakness-chainFrom this weakness, which CVEs and techniques connect to it?
actor-ttpsWhich techniques is this threat group associated with?

Without a key

While keyless access is on, graph_lookup, graph_meta and graph_notices answer without a key, with small limits. Every keyless answer says that it is keyless and how to get a key. The other tools need a key. The connection guide covers keyless access and getting a key.

What it does not do

  • It does not look at your systems. Lattice answers questions about public knowledge. It has no view of your network, your hosts or your alerts.
  • It is not complete. A lookup that returns nothing means the graph holds nothing on that id; it does not mean the id does not exist.
  • It is not a free-text search. graph_search matches the start of an id.
  • An inferred link is a guess. Say "likely", never "is".

Where to go next