For agents and the people who build them
The seven Lattice tools and their exact arguments
What each read-only tool returns, the argument names to send, the five path templates, and which tools work without a key.
4 minute read
What you are connecting to
Lattice is a read-only MCP server over a graph of public cybersecurity sources: CVE entries, CISA known-exploited status, MITRE ATT&CK techniques, CWE weaknesses, threat groups and detection rules. Every tool only reads a published snapshot. Calling a tool twice gives the same answer, and none of them changes anything.
The endpoint is https://lattice.namiq.io/mcp over streamable HTTP. Send a key in the X-API-Key header. Discovery (initialize and tools/list) needs no key, so an agent can read this list before anyone signs up.
The tools
An argument followed by a question mark is optional. id is an external id; uid is the graph's own identifier and comes from an earlier answer.
| Tool | Arguments (exact names) | What comes back |
|---|---|---|
| graph_meta | none | The snapshot id, the node types, the relationship verbs, the sources and the path templates. Call it once at the start of a session. |
| graph_lookup | id, label? | The nodes with that exact external id, such as CVE-2021-44228, T1059.001 or CWE-79, each with its source and a uid. A CVE can return two nodes: the CISA known-exploited entry and the NVD entry. |
| graph_search | id_prefix, label?, limit?, cursor? | Ids that start with a prefix such as CVE-2024-1 or T105. Ids only, not free text. If the answer says truncated, pass next_cursor as cursor. |
| graph_node | uid | One node's properties, by the uid a lookup or search returned. |
| graph_neighbors | uid, direction?, verb?, label?, limit?, cursor? | The directly connected nodes, each link with its verb, its source, and whether it is declared or inferred. |
| graph_path | template, id, label? | A fixed multi-step question from an external id. The templates are listed below. |
| graph_notices | ids? | The licence and attribution notices of the sources an answer used. |
The five path templates
| Template | The question it answers |
|---|---|
| cve-to-defense | Which ATT&CK techniques does this CVE enable, and then which detections and response procedures exist for them? |
| cve-context | What surrounds this CVE: its weakness, its known-exploited entry, the products it names? |
| technique-coverage | For this technique, which detections exist, and which sources hold them? |
| weakness-chain | From this weakness, which CVEs and techniques connect to it? |
| actor-ttps | Which techniques is this threat group associated with? |
Without a key
While keyless access is on, graph_lookup, graph_meta and graph_notices answer without a key, with small limits. Every keyless answer says that it is keyless and how to get a key. The other tools need a key. The connection guide covers keyless access and getting a key.
What it does not do
- It does not look at your systems. Lattice answers questions about public knowledge. It has no view of your network, your hosts or your alerts.
- It is not complete. A lookup that returns nothing means the graph holds nothing on that id; it does not mean the id does not exist.
- It is not a free-text search. graph_search matches the start of an id.
- An inferred link is a guess. Say "likely", never "is".
Where to go next
- IT and security for small firms — The service behind the reference layer: someone who looks after your own estate.
- The IT check — Reference material tells you what is known. The check tells you where your own estate stands.
- OCO, the cyber graph behind this — Lattice serves public knowledge. OCO is the product that works on a real estate.
- Get a Lattice trial key — read the beta terms first.