Server definition
- Hash
- sha256:504a403954fbe76df6e21f866c653d833e4b662f6580e32d267f9a08cd352b63
- What it is
- What a remote MCP server returned when asked what it offers: 53 tools
The blob, as servednamed by its sha256
{
"instructions": "This server provides expert security content by Lenny Zeltser, covering incident response, malware analysis, cybersecurity leadership, and security product strategy.\n\n## When to Use This Server\n\n- The user needs to **write, structure, or review an incident response report**\n- The user has **raw incident notes** and needs to turn them into a professional report\n- The user needs to **write, structure, or review a malware analysis report**\n- The user needs to **turn reverse-engineering or dynamic-analysis notes into a report**\n- The user wants to **improve writing quality** in security reports, assessments, pentest reports, or audit findings\n- The user is **planning, evaluating, or reviewing a cybersecurity product strategy**\n- The user wants to **research** expert articles on malware analysis, incident response, or security leadership\n\n## Available Tools\n\n**Search & Reference**\n- `search_zeltser`: Search articles by keyword\n- `get_article`: Retrieve full article content by URL path\n- `get_capabilities`: Detailed guide to all tools and parameters\n\n**Security Writing**\n- `get_security_writing_guidelines`: Improve tone, structure, clarity in any security document\n\n**Incident Response Reports**\n- `ir_load_context`: Load guidelines for creating reports from raw notes\n- `ir_get_template`: Get the IR report template (default) or brief template (`kind: 'brief'`)\n- `ir_get_guidelines`: Quick writing tips by topic (tone, words, structure, brief, frameworks, handoffs)\n- `ir_review_report`: Get criteria for reviewing an existing IR report\n- `ir_get_brief_template`: Standalone IR brief template\n- `ir_get_cross_server_routes`: When to consult other MCP servers for IR work\n- `ir_get_frameworks`: NIST SP 800-61r3 + GDPR + CCPA/CPRA + HIPAA + NCSL state laws + sibling frames\n\n**Product Strategy**\n- `product_load_context`: Load strategic frameworks for creating or evaluating product plans\n- `product_get_template`: Get the fill-in-the-blank strategy template\n- `product_get_guidelines`: Quick guidance on a specific topic (pricing, competitive, sales, etc.)\n- `product_review_plan`: Get criteria for reviewing an existing product strategy\n- `product_compare_context`: Comparative analysis framework for multi-company evaluation\n\n**Cybersecurity Writing Rating Sheets**\n- `rating_get_sheet`: Get one or all cybersecurity-writing rating sheets (rubric only, no score)\n- `rating_score_writing`: Score a draft against a sheet — the ONLY tool that produces numeric scores\n- `rating_load_context`: Load all sheets plus the scoring playbook in one call\n\n**AI Defense Matrix**\n- `aidefense_load_context`: Load matrix, framework alignments, and evaluation + cross-mapping playbooks\n- `aidefense_get_matrix`: Structured matrix data (8 AI asset classes x 6 NIST CSF functions)\n- `aidefense_get_framework_alignment`: Cross-mappings to NIST IR 8596, ISO 42001, MITRE ATLAS, OWASP LLM Top 10, CSA AICM, Google SAIF, OWASP AI Exchange, OWASP Agentic Top 10\n- `aidefense_evaluate_program`: Per-cell prompts and gap inventory for assessing an AI security program\n- `aidefense_cross_map`: Coverage taxonomy and capability-to-cell prompts for vendor product mapping\n\n**Cyber Threat Intel (CTI) Reports**\n- `cti_load_context`: Load guidelines for drafting a CTI report or one-page brief\n- `cti_get_template`: Get the long report or one-page brief template (`template: 'report' | 'brief'`)\n- `cti_get_guidelines`: Topic-by-topic guidance including attribution, confidence, pyramid of pain, six signals, anti-patterns, brief, handoffs\n- `cti_review_report`: Get criteria for reviewing an existing CTI report or brief\n- `cti_get_brief_template`: Standalone CTI brief template\n- `cti_get_cross_server_routes`: When to consult MITRE ATT&CK, MISP, etc. for CTI work\n- `cti_get_frameworks`: 12 primary CTI frameworks (Diamond Model, MITRE ATT&CK, Q Model, ICD-203, etc.) + sibling frames\n\n**Malware Analysis Reports**\n- `malware_load_context`: Load section guidance, MBC capability model, ICD-203 family-call confidence, Pyramid-of-Pain IOC tiering, and briefPolicy\n- `malware_get_template`: Get the 15-section malware analysis report template\n- `malware_get_guidelines`: Topic-by-topic guidance including capabilities, confidence, Pyramid of Pain, anti-patterns, methodology, fields, handoffs, and frameworks\n- `malware_review_report`: Get criteria for reviewing an existing malware analysis report\n- `malware_get_cross_server_routes`: When to consult sandbox, file reputation, detection-rule, passive-DNS, symbol, or certificate tooling\n- `malware_get_frameworks`: MBC + MITRE ATT&CK + Pyramid of Pain + ICD-203 + STIX + TLP plus sibling artifacts\n\n**Vulnerability Investigation Briefs**\n- `vuln_load_context`: Load guidelines for drafting a one-page vulnerability investigation brief (always embeds 6 mcpHandoffs pointers)\n- `vuln_get_template`: Get the brief template\n- `vuln_get_guidelines`: Topic-by-topic guidance including significance discipline (renamed from severity in 1.1.0), actions, gaps, evidence sources, handoffs\n- `vuln_review_brief`: Get criteria for reviewing an existing brief; surfaces relevant handoffs based on focus\n- `vuln_get_brief_template`: Standalone Vuln brief template (functionally equivalent to vuln_get_template)\n- `vuln_get_cross_server_routes`: When to consult NVD, CISA KEV, vendor advisories\n- `vuln_get_frameworks`: 5 primary frameworks (CVSS, CVE, NVD, CISA KEV, Vendor Advisory) + sibling frames (EPSS, SSVC, VEX) + sibling artifacts\n\n**Security Assessment Reports**\n- `assessment_load_context`: Load guidance for a findings-based assessment report or brief — risk-adjusted severity, reader-first sections, frameworks\n- `assessment_get_template`: Get the report template (default) or the one-page brief (`kind: 'brief'`)\n- `assessment_get_guidelines`: Quick writing tips by topic (severity, findings, remediation, methodology, scope, strengths, brief)\n- `assessment_review_report`: Get criteria for reviewing a report, mapped to the info-assessment rating sheet (17 items)\n- `assessment_get_brief_template`: Standalone one-page assessment brief template\n- `assessment_get_cross_server_routes`: When to consult vuln/ir/cti tools or MITRE ATT&CK, CVE, or web research\n- `assessment_get_frameworks`: NIST SP 800-115/800-30, OWASP WSTG and Risk Rating, CVSS, MITRE ATT&CK, PTES, PCI DSS, CREST\n\n## Tool Selection\n\nMatch the user's intent to the right tool:\n\n- **Writing/creating** a report or plan from scratch → `*_load_context` (+ `include_template: true` for product)\n- **Improving** writing quality, tone, or clarity in any security document → `get_security_writing_guidelines`\n- **Reviewing/critiquing** an existing draft → `*_review_report` or `*_review_plan`\n- **Scoring** a draft against a structured rubric (numeric score, gap analysis, or rubric-anchored feedback) → `rating_score_writing`\n- **Quick guidance** on a specific topic (tone, structure, pricing, etc.) → `*_get_guidelines`\n- **Researching** published expert content → `search_*` + `get_article`\n- **Structuring** a new document → `*_get_template`\n\n## Privacy\n\nAll tools return guidelines and frameworks to your AI for local analysis.\nThis server never requests user documents, notes, drafts, or plans, and instructs your AI to keep them local.",
"tools": [
{
"description": "Get the AI Defense Matrix cross-mapping playbook for mapping product capabilities to matrix cells: coverage taxonomy (primary, secondary, partial, aspirational), differentiation guidance, disambiguation block, worked examples, and out-of-scope examples. The response always includes an inScopeCheck. Products that USE AI to solve a non-AI security problem (deepfake detection, AI-for-fraud, AI features added to existing SIEM, SOAR, or EDR tools) belong in the Cyber Defense Matrix at https://cyberdefensematrix.com. Pairs naturally with product_load_context(productFocus: 'ai_security') for follow-on positioning and GTM work. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"framework": {
"description": "Optional: include only one external framework's cross-mapping (e.g., 'owasp-llm-top10') alongside the playbook.",
"enum": [
"nist-ir-8596",
"csa-aicm",
"iso-42001",
"google-saif",
"sans-caisg",
"mitre-atlas",
"owasp-ai-exchange",
"owasp-llm-top10",
"owasp-asi"
],
"type": "string"
},
"include_framework_alignment": {
"description": "Optional: when false, the framework alignment block (~half the response) is omitted in favor of a short note pointing to aidefense_get_framework_alignment. Use when the caller will fetch alignment separately and wants a slim cross_map response. Default: true.",
"type": "boolean"
},
"include_process_shaped": {
"description": "Optional: when true with whitespace, lift the coverageType filter so process and cdm-rollup cells with at most one cataloged product appear too. Use when you want to see all sparse cells regardless of whether a product is the right answer there.",
"type": "boolean"
},
"whitespace": {
"description": "Optional: when true, surface a `whitespace.sparseCells` block scoped to cells with at most one product in the AI Defense Matrix Catalog where a product can plausibly succeed (vendorDensity <= 1 AND coverageType in {tooling, hybrid}). Process and cdm-rollup cells are excluded by default because their emptiness does not indicate market opportunity. The block names the count source and catalog date, and returns no cells when counts are missing.",
"type": "boolean"
}
},
"type": "object"
},
"name": "aidefense_cross_map",
"outputSchema": null
},
{
"description": "Get the AI Defense Matrix evaluation playbook for assessing an AI security program: per-cell prompts, gap-inventory template, and a workflow that walks each asset class first and rolls findings up to the Govern column. Supports mode='gate' for binary deployment-gate decisions (returns the deployment-gate workflow plus gate-tier prompts only) and consumerPattern for scoping to consumed-vs-built AI deployments. The AI applies these prompts against your program documentation locally, and no program details leave your client. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"asset": {
"description": "Optional: focus the prompts on one asset class.",
"enum": [
"ai-workload-platforms",
"ai-coding-orchestration-tools",
"ai-generated-code",
"ai-traffic",
"ai-model",
"training-data",
"runtime-ai-data",
"ai-agent-identities",
"ai-gateways-routers",
"ai-orchestration-tools"
],
"type": "string"
},
"assets": {
"description": "Optional: focus the prompts on multiple asset classes (e.g., for a deployment that touches orchestration + runtime data + agent identities). Takes precedence over `asset` if both are set.",
"items": {
"enum": [
"ai-workload-platforms",
"ai-coding-orchestration-tools",
"ai-generated-code",
"ai-traffic",
"ai-model",
"training-data",
"runtime-ai-data",
"ai-agent-identities",
"ai-gateways-routers",
"ai-orchestration-tools"
],
"type": "string"
},
"type": "array"
},
"consumer_pattern": {
"description": "consumed: organization consumes a third-party model (GPT-4 via API) — drops AI-Workload Platforms, Training Data, AI-Generated Code rows, and AI Model identify/protect/detect/respond/recover (keeps ai-model.govern). built: organization hosts/trains its own model — all rows in scope. hybrid (default behavior when omitted): all rows in scope.",
"enum": [
"consumed",
"built",
"hybrid"
],
"type": "string"
},
"framework": {
"description": "Optional: scope cellPrompts to those whose 'sources' field cites the named framework. Accepts a bare slug ('iso-42001') for any prompt citing that framework, or a 'framework:concept-id' form ('mitre-atlas:AML.T0051') to match an exact technique. Composes with mode, consumer_pattern, asset, and assets.",
"pattern": "^(nist-ir-8596|csa-aicm|iso-42001|google-saif|mitre-atlas|owasp-ai-exchange|owasp-llm-top10|owasp-asi)(:[A-Za-z0-9._-]+)?$",
"type": "string"
},
"function": {
"description": "Optional: focus the prompts on one NIST CSF function.",
"enum": [
"govern",
"identify",
"protect",
"detect",
"respond",
"recover"
],
"type": "string"
},
"mode": {
"description": "assessment (default): full program assessment — all maturity tiers. gate: binary deployment-gate decision — returns the deploymentGateWorkflow plus only gate-tier prompts (drops 90-day and mature prompts).",
"enum": [
"assessment",
"gate"
],
"type": "string"
}
},
"type": "object"
},
"name": "aidefense_evaluate_program",
"outputSchema": null
},
{
"description": "Get AI Defense Matrix cross-mappings to nine external frameworks: NIST IR 8596, CSA AI Controls Matrix, ISO 42001, Google SAIF, SANS Critical AI Security Guidelines, MITRE ATLAS, OWASP AI Exchange, OWASP LLM Top 10, OWASP Agentic Security Top 10. Each row maps an AI asset class to how that framework applies. Each returned framework also carries a 'concepts' array of the structured IDs (MITRE ATLAS techniques, OWASP risks, ISO clauses) the matrix references for it. Supports a 'buyer' archetype shortcut to scope to the frameworks a particular buyer will care about. Use to translate between framework vocabularies. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"buyer": {
"description": "Optional: scope to a buyer archetype's framework subset. federal: NIST IR 8596 + ISO 42001. ai-governance: ISO 42001 + CSA AICM. app-security: OWASP LLM Top 10 + OWASP AI Exchange. threat-modeler: MITRE ATLAS + OWASP Agentic Top 10. enterprise: all 9 (same as omitting both parameters).",
"enum": [
"federal",
"ai-governance",
"app-security",
"threat-modeler",
"enterprise"
],
"type": "string"
},
"framework": {
"description": "Optional: scope to one framework slug (e.g., 'mitre-atlas', 'owasp-llm-top10'). Omit to get all nine. Wins over 'buyer' if both are passed.",
"enum": [
"nist-ir-8596",
"csa-aicm",
"iso-42001",
"google-saif",
"sans-caisg",
"mitre-atlas",
"owasp-ai-exchange",
"owasp-llm-top10",
"owasp-asi"
],
"type": "string"
}
},
"type": "object"
},
"name": "aidefense_get_framework_alignment",
"outputSchema": null
},
{
"description": "Get the structured AI Defense Matrix: 8 AI-specific asset rows x 6 NIST CSF 2.0 function columns. Each cell describes a control category for defending that asset class. Supports optional filtering by asset or function. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"asset": {
"description": "Optional: filter to one asset class (e.g., 'ai-model', 'training-data'). Returns the 6 cells for that row.",
"enum": [
"ai-workload-platforms",
"ai-coding-orchestration-tools",
"ai-generated-code",
"ai-traffic",
"ai-model",
"training-data",
"runtime-ai-data",
"ai-agent-identities",
"ai-gateways-routers",
"ai-orchestration-tools"
],
"type": "string"
},
"format": {
"description": "structured: typed JSON of assets, functions, and cells (default). markdown: human-readable rendering grouped by asset.",
"enum": [
"structured",
"markdown"
],
"type": "string"
},
"function": {
"description": "Optional: filter to one NIST CSF function ('govern', 'identify', 'protect', 'detect', 'respond', 'recover'). Returns the 8 cells for that column.",
"enum": [
"govern",
"identify",
"protect",
"detect",
"respond",
"recover"
],
"type": "string"
}
},
"type": "object"
},
"name": "aidefense_get_matrix",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's AI Defense Matrix context: the 8-asset x 6-NIST-CSF-2.0-function matrix, nine cross-walked frameworks (NIST IR 8596, CSA AICM, ISO 42001, Google SAIF, SANS Critical AI Security Guidelines, MITRE ATLAS, OWASP AI Exchange, OWASP LLM Top 10, OWASP Agentic Top 10), and the evaluation + cross-mapping playbooks. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "minimal: matrix summary counts only, no playbooks or framework rows. standard: full matrix, framework alignments, and the selected playbook(s) (default). comprehensive: everything including related articles.",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"purpose": {
"description": "evaluate_program: practitioner playbook for assessing an AI security program. cross_map_product: vendor playbook for mapping product capabilities to matrix cells. general: both playbooks (default).",
"enum": [
"evaluate_program",
"cross_map_product",
"general"
],
"type": "string"
}
},
"type": "object"
},
"name": "aidefense_load_context",
"outputSchema": null
},
{
"description": "Reverse-lookup a single concept ID (MITRE ATLAS technique like 'AML.T0051', OWASP LLM Top 10 risk like 'LLM01', OWASP Agentic Top 10 issue like 'ASI03', or ISO 42001 Annex A clause like 'A.6') across the AI Defense Matrix. Returns which framework the concept belongs to, the asset rows whose alignment cites it, the cells whose evaluation cellPrompts cite it, and those prompts themselves. Useful when a vendor's product is defined by a specific technique ('we defend AML.T0051') and they need to find which matrix cells to claim. Recognizes only concepts with structured IDs; for prose-only frameworks (NIST IR 8596, CSA AICM, Google SAIF, OWASP AI Exchange) use aidefense_get_framework_alignment instead. This server never requests your program docs or product roadmap and instructs your AI to keep them local—the matrix, framework alignments, and playbooks flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"concept": {
"description": "A single concept ID. Recognized patterns: 'AML.T<4 digits>(.<3 digits>)?' (MITRE ATLAS), 'LLM<2 digits>' (OWASP LLM Top 10), 'ASI<2 digits>' (OWASP Agentic Top 10), 'A.<digits>' (ISO 42001 Annex A clauses). Case-insensitive.",
"maxLength": 32,
"minLength": 1,
"type": "string"
}
},
"required": [
"concept"
],
"type": "object"
},
"name": "aidefense_locate_concept",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Security Assessment one-page executive brief template. Standalone variant of `assessment_get_template` for callers that only want the brief without the long-form report. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "assessment_get_brief_template",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Security Assessment cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult. Surfaces a compact subset of `assessment_load_context`. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "assessment_get_cross_server_routes",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Security Assessment frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone). Pass `include_siblings: false` to skip sibling blocks. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"include_siblings": {
"description": "Include the siblingFrames block (adjacent frameworks with whyOmitted notes) and the siblingArtifacts block (related templates) in the response. Default: true.",
"type": "boolean"
}
},
"type": "object"
},
"name": "assessment_get_frameworks",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert security assessment report writing guidelines. Topics: severity (the risk-adjusted severity model — the spine), findings, remediation, methodology, scope, strengths, brief (one-page brief section guidance), executive_summary, analysis, anti_patterns, frameworks, handoffs, and summary. The general 'tone' topic defers to `get_security_writing_guidelines` for the canonical Five Elements rules. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"topic": {
"description": "Which topic to surface. Defaults to a 'summary' overview when omitted.",
"enum": [
"tone",
"executive_summary",
"severity",
"findings",
"remediation",
"methodology",
"scope",
"strengths",
"analysis",
"brief",
"anti_patterns",
"frameworks",
"handoffs",
"summary",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "assessment_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's security assessment template. The report is a reader-first findings report: Executive Summary, Assessment Scope, Findings Summary, Detailed Findings, Remediation Priorities, optional Attack Path Narrative and Detection and Response Observations, Methodology, Limitations and Disclaimer, Appendices, and About this Report. The one-page brief covers Bottom Line, Key Findings, Recommended Actions, and More Information. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"kind": {
"description": "Which artifact to return: 'report' (full findings report, default) or 'brief' (one-page executive brief).",
"enum": [
"report",
"brief"
],
"type": "string"
}
},
"type": "object"
},
"name": "assessment_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's security assessment report writing context for local analysis. Returns a JSON payload with the risk-adjusted severity model (the spine), reader-first section guidance, completeness criteria, frameworks (NIST SP 800-115/800-30, OWASP WSTG/Risk Rating, CVSS, MITRE ATT&CK, PTES, PCI DSS, CREST), and the mcpHandoffs array. The 'profile' parameter ANNOTATES sections (internal/external applicability) rather than filtering — every section is returned so cross-profile comparisons are possible. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "Response size: minimal, standard, or comprehensive.",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"include_examples": {
"description": "Include exampleGood/examplePoor in fieldGuidance entries.",
"type": "boolean"
},
"profile": {
"description": "Annotate sections by applicability to this profile (internal or external). Sections are NOT filtered — annotated only.",
"enum": [
"internal",
"external"
],
"type": "string"
},
"template": {
"description": "Foreground 'report' or 'brief' sections; both lists stay in the payload.",
"enum": [
"report",
"brief"
],
"type": "string"
},
"topics": {
"description": "Narrow the response to specific topics; 'all' includes everything.",
"items": {
"enum": [
"sections",
"completeness",
"severity",
"writing",
"frameworks",
"assessment_types",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "assessment_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing security assessment report or brief. Surfaces the 17 info-assessment review items across five groups (Key Takeaways, Assessment Scope, Prioritized Findings, Remediation Suggestions, Assessment Methodology), cross-cutting criteria, the risk-adjusted severity model, anti-patterns, and a pointer to rating_score_writing for a numeric score. This server never requests your assessment notes or report and instructs your AI to keep them local—the templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "Focus areas: completeness, clarity, tone, structure, severity, remediation, strengths, anti_patterns, or all.",
"items": {
"enum": [
"completeness",
"clarity",
"tone",
"structure",
"severity",
"remediation",
"strengths",
"anti_patterns",
"all"
],
"type": "string"
},
"type": "array"
},
"sections": {
"description": "Narrow to specific report sections; 'all' includes every section.",
"items": {
"enum": [
"executive_summary",
"assessment_scope",
"findings_summary",
"detailed_findings",
"remediation_priorities",
"attack_path_narrative",
"detection_and_response",
"methodology",
"limitations_and_disclaimer",
"appendices",
"about_this_report",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "assessment_review_report",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's CTI one-page executive brief template. Standalone variant of `cti_get_template` for callers that only want the brief without the long-form report. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "cti_get_brief_template",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's CTI cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult. Surfaces a compact subset of `cti_load_context`. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "cti_get_cross_server_routes",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's CTI frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone). Pass `include_siblings: false` to skip sibling blocks. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"include_siblings": {
"description": "Include the siblingFrames block (adjacent frameworks with whyOmitted notes) and the siblingArtifacts block (related templates) in the response. Default: true.",
"type": "boolean"
}
},
"type": "object"
},
"name": "cti_get_frameworks",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert CTI writing guidelines. Topics include tone, words, structure, executive_summary, voice, articles, summary, brief (one-page brief section guidance), handoffs (cross-server routing), methodology (the three subsections), fields (per-field guidance), and CTI-specific topics: attribution (full Six Signals prose), confidence (ICD-203 ladder), pyramid_of_pain, six_signals (signals table only), and anti_patterns. The general writing topics (tone/words/structure/executive_summary) now defer to `get_security_writing_guidelines` for the canonical Five Elements rules; CTI-specific content lives in the other topics. Pair the 'fields' topic with field_id for single-field guidance. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"field_id": {
"description": "Only meaningful with topic='fields'. When supplied, returns guidance for the named field id. When omitted under topic='fields', returns a directory of available field ids.",
"type": "string"
},
"topic": {
"description": "Which topic to surface. Defaults to a 'summary' overview when omitted.",
"enum": [
"tone",
"words",
"structure",
"executive_summary",
"voice",
"articles",
"summary",
"brief",
"attribution",
"confidence",
"pyramid_of_pain",
"six_signals",
"anti_patterns",
"methodology",
"fields",
"handoffs",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "cti_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's cyber threat intel template. The long report covers Executive Summary, Actor Snapshot, Methodology, Activity Overview, Representative Adversary Techniques, Indicators of Compromise, Defensive Implications, Attribution Analysis, Anticipated Activity, optional Strategic Analysis and Competing Hypotheses, plus About this Report. The one-page brief covers Bottom Line, Quick Facts, Are We in Scope?, Defensive Actions, What We Don't Know, More Information. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"template": {
"description": "Which artifact to return: 'report' (12-section long report, default) or 'brief' (one-page executive brief).",
"enum": [
"report",
"brief"
],
"type": "string"
}
},
"type": "object"
},
"name": "cti_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's CTI writing context for local analysis. Returns a JSON payload with section guidance, completeness criteria, framework grounding (12 frameworks), the six attribution signals, ICD-203 confidence levels and ladder, and the Pyramid of Pain. The 'profile' parameter ANNOTATES sections (internal/public applicability label) rather than filtering — every section is returned so cross-profile comparisons are possible. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "Response size: minimal (~2-3k tokens), standard (~5-7k), comprehensive (~12k+).",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"include_examples": {
"description": "Include exampleGood/examplePoor in fieldGuidance entries.",
"type": "boolean"
},
"profile": {
"description": "Annotate sections by their applicability to this profile (internal or public). Sections are NOT filtered — annotated only.",
"enum": [
"internal",
"public"
],
"type": "string"
},
"template": {
"description": "Foreground 'report' or 'brief' sections; both lists stay in the payload.",
"enum": [
"report",
"brief"
],
"type": "string"
},
"topics": {
"description": "Narrow the response to specific topics; 'all' includes everything.",
"items": {
"enum": [
"completeness",
"sections",
"writing",
"attribution",
"confidence",
"pyramid_of_pain",
"six_signals",
"frameworks",
"markings",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "cti_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing CTI report or brief. Surfaces per-theme review criteria (framework, confidence, attribution, defense, distribution, etc.), cross-cutting criteria, the six anti-patterns to watch for, and focus-driven writing analysis. This server never requests your campaign or threat-intel notes and instructs your AI to keep them local—templates and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "Focus areas: completeness, clarity, tone, structure, attribution, confidence, or all.",
"items": {
"enum": [
"completeness",
"clarity",
"tone",
"structure",
"attribution",
"confidence",
"anti_patterns",
"all"
],
"type": "string"
},
"type": "array"
},
"sections": {
"description": "Narrow to specific report sections; 'all' includes every section.",
"items": {
"enum": [
"executive_summary",
"actor_snapshot",
"methodology",
"activity_overview",
"adversary_techniques",
"indicators_of_compromise",
"defensive_implications",
"attribution_analysis",
"anticipated_activity",
"strategic_analysis",
"competing_hypotheses",
"about_this_report",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "cti_review_report",
"outputSchema": null
},
{
"description": "Get the full content of a specific article from Lenny Zeltser's Website by URL path. Security articles on malware analysis, incident response, and security leadership. Returns title, date, topics, summary, and full body text.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"url": {
"description": "Article URL path or full URL (e.g., '/about', '/article-slug', or the full URL printed by search results)",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "get_article",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"abstract": {
"type": "string"
},
"body": {
"type": "string"
},
"date": {
"type": "string"
},
"site": {
"additionalProperties": false,
"properties": {
"domain": {
"minLength": 1,
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
}
},
"required": [
"name",
"domain"
],
"type": "object"
},
"title": {
"minLength": 1,
"type": "string"
},
"topics": {
"items": {
"type": "string"
},
"type": "array"
},
"url": {
"minLength": 1,
"type": "string"
}
},
"required": [
"url",
"title",
"site"
],
"type": "object"
}
},
{
"description": "List all capabilities and tools available from the Lenny Zeltser's Website MCP server, including search tools and any specialized features like IR report writing assistance.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "get_capabilities",
"outputSchema": null
},
{
"description": "Get statistics about the Lenny Zeltser's Website search index including total pages indexed, last update time, and available tools.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "get_index_info",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"generated": {
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$",
"type": "string"
},
"pageCount": {
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"site": {
"additionalProperties": false,
"properties": {
"description": {
"type": "string"
},
"domain": {
"minLength": 1,
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
}
},
"required": [
"name",
"domain"
],
"type": "object"
},
"tools": {
"items": {
"additionalProperties": false,
"properties": {
"description": {
"minLength": 1,
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
}
},
"required": [
"name",
"description"
],
"type": "object"
},
"type": "array"
},
"version": {
"minLength": 1,
"type": "string"
}
},
"required": [
"site",
"version",
"generated",
"pageCount",
"tools"
],
"type": "object"
}
},
{
"description": "Get Lenny Zeltser's expert writing guidelines for security reports and assessments. Provides guidance on tone, structure, clarity, executive summaries, and avoiding common writing mistakes. Includes rating-sheet items (the four lens sheets: structure, look, words, tone) as concrete reference points for grounded feedback. Works for any security document. This server never requests your documents and instructs your AI to keep them local—guidelines flow to your AI for local analysis. Note: For incident response reports specifically, use the ir_* tools which provide deeper section-by-section review criteria.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "Which aspects of writing to focus on. 'tone': voice, do/avoid examples. 'structure': paragraphs, report qualities, formatting. 'clarity': sentences, jargon alternatives. 'executive_summary': exec summary best practices. 'critique': writing as critique not criticism. 'analytical': evidence attribution, confidence language, comparative language, gap acknowledgment. 'all' or omit for everything.",
"items": {
"enum": [
"tone",
"structure",
"clarity",
"executive_summary",
"critique",
"analytical",
"all"
],
"type": "string"
},
"type": "array"
},
"include_examples": {
"description": "Include before/after examples. Default: true. Set to false for smaller response.",
"type": "boolean"
}
},
"type": "object"
},
"name": "get_security_writing_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's IR one-page executive brief template. Standalone variant of `ir_get_template` for callers that only want the brief without the long-form report. This server never requests your incident notes and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "ir_get_brief_template",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's IR cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult. Surfaces a compact subset of `ir_load_context`. This server never requests your incident notes and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "ir_get_cross_server_routes",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's IR frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone). Pass `include_siblings: false` to skip sibling blocks. This server never requests your incident notes and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"include_siblings": {
"description": "Include the siblingFrames block (adjacent frameworks with whyOmitted notes) and the siblingArtifacts block (related templates) in the response. Default: true.",
"type": "boolean"
}
},
"type": "object"
},
"name": "ir_get_frameworks",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert writing guidelines for incident response reports. Topics: tone, words, structure, executive_summary, voice, articles, summary, brief (one-page brief section guidance, IR 1.5.0+), frameworks (regulatory + maturity frameworks), handoffs (cross-server routing). When the topic maps to a lens (tone, words, structure), the response includes a rating-sheet checklist appendix as concrete reference points for grounded feedback. This server never requests your incident notes and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"topic": {
"description": "Specific topic: tone (collaborative framing), words (clarity, jargon), structure (paragraphs, headings), executive_summary (exec summary rules), voice (style guidelines), articles (related reading), summary (quick reference), brief (one-page brief section guidance), frameworks (NIST SP 800-61r3, GDPR, CCPA/CPRA, HIPAA, NCSL state laws + sibling frames), handoffs (when to route to other MCP servers). Omit for full guidelines.",
"enum": [
"tone",
"words",
"structure",
"executive_summary",
"voice",
"articles",
"summary",
"brief",
"frameworks",
"handoffs"
],
"type": "string"
}
},
"type": "object"
},
"name": "ir_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's structured incident response template. Covers all critical IR sections with field-by-field guidance. Pass kind: \"report\" (default — full incident-response report) or \"brief\" (one-page executive brief, IR 1.5.0+). This server never requests your incident notes and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"kind": {
"description": "Which artifact to return: 'report' (full incident-response report — default for backward compatibility) or 'brief' (one-page executive brief).",
"enum": [
"report",
"brief"
],
"type": "string"
}
},
"type": "object"
},
"name": "ir_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's IR report writing context for local analysis. Returns expert guidelines for field completeness, incident identification, notification triggers, and writing quality. Includes rating-sheet items (lens taxonomy plus the IR-specific Information sheet) as concrete reference points for grounded feedback. This server never requests your incident notes and instructs your AI to keep them local. Use detail_level to control response size: \"minimal\" (~2k tokens), \"standard\" (~5k tokens), or \"comprehensive\" (~11k tokens).",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "Level of detail to return. 'minimal': core field guidance only (~2k tokens). 'standard': field guidance + writing analysis + notifications (~5k tokens, default). 'comprehensive': everything including examples and all incident types (~11k tokens).",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"incident_type": {
"description": "Load guidance for a specific incident type only (saves tokens). Omit to load all types when 'incidents' topic is included.",
"enum": [
"ransomware",
"bec",
"data_breach",
"insider_threat",
"supply_chain"
],
"type": "string"
},
"include_examples": {
"description": "Include good/poor examples in field guidance. Default: false. Set to true for learning/training.",
"type": "boolean"
},
"topics": {
"description": "Specific topics to load. Overrides detail_level for fine-grained control. Options: completeness (field guidance), incidents (type identification), notifications (regulatory triggers), writing (style analysis), actions (urgency categorization), stakeholders (party identification), sections (review criteria).",
"items": {
"enum": [
"completeness",
"incidents",
"notifications",
"writing",
"actions",
"stakeholders",
"sections",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "ir_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing IR report. Returns focused guidance for constructive critique — what to check in each section, writing quality issues to identify, and how to frame feedback collaboratively. Includes rating-sheet items (lens taxonomy plus the IR-specific Information sheet) as concrete reference points for grounded feedback. This server never requests your report and instructs your AI to keep it local.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "What aspects to focus on. 'completeness': is everything covered? 'clarity': jargon, passive voice, vague terms. 'tone': collaborative framing. 'structure': sentence/paragraph organization.",
"items": {
"enum": [
"completeness",
"clarity",
"tone",
"structure",
"all"
],
"type": "string"
},
"type": "array"
},
"sections": {
"description": "Specific sections to get review criteria for. Omit or use 'all' for complete review criteria.",
"items": {
"enum": [
"executive_summary",
"timeline",
"root_cause",
"actions_taken",
"lessons_learned",
"business_impact",
"what_went_well",
"third_party",
"data_exposure",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "ir_review_report",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Malware cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult. Surfaces a compact subset of `malware_load_context`. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "malware_get_cross_server_routes",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Malware frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone). Pass `include_siblings: false` to skip sibling blocks. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"include_siblings": {
"description": "Include the siblingFrames block (adjacent frameworks with whyOmitted notes) and the siblingArtifacts block (related templates) in the response. Default: true.",
"type": "boolean"
}
},
"type": "object"
},
"name": "malware_get_frameworks",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert malware analysis report writing guidelines. Topics include capabilities, confidence, pyramid_of_pain, anti_patterns, methodology, fields, handoffs, frameworks, plus tone, words, structure, and executive_summary topics that defer to `get_security_writing_guidelines` for canonical Five Elements guidance. Pair the 'fields' topic with field_id for single-field guidance. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"field_id": {
"description": "Only meaningful with topic='fields'. When supplied, returns guidance for the named field id. When omitted under topic='fields', returns a directory of available field ids.",
"type": "string"
},
"topic": {
"description": "Which topic to surface. Defaults to a 'summary' overview when omitted.",
"enum": [
"tone",
"words",
"structure",
"executive_summary",
"voice",
"articles",
"summary",
"capabilities",
"confidence",
"pyramid_of_pain",
"anti_patterns",
"methodology",
"fields",
"handoffs",
"frameworks",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "malware_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's malware analysis report template. The report covers Executive Summary, Sample Snapshot, Malware Family Identification, Component Inventory, Runtime Requirements, Sources, Capabilities, Indicators of Compromise, Analysis Details, What We Don't Know, optional Infection Vector, optional Detection Engineering, About this Report, Appendix: Analysis Environment, and optional Appendix: Analysis Scripts. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "malware_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's malware analysis report writing context for local analysis. Returns a JSON payload with section guidance, the MBC capability model, ICD-203 confidence scoped to the family call, Pyramid-of-Pain IOC tiering, and a briefPolicy explaining why there is no companion brief. The 'profile' parameter ANNOTATES sections (organizationalReport/researcherNarrative applicability label) rather than filtering — every section is returned so cross-profile comparisons are possible. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "Response size: minimal, standard, or comprehensive.",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"include_examples": {
"description": "Include exampleGood/examplePoor in fieldGuidance entries.",
"type": "boolean"
},
"profile": {
"description": "Annotate sections by their applicability to this profile. Sections are NOT filtered — annotated only.",
"enum": [
"organizationalReport",
"researcherNarrative"
],
"type": "string"
},
"topics": {
"description": "Narrow the response to specific topics; 'all' includes everything.",
"items": {
"enum": [
"completeness",
"sections",
"writing",
"capabilities",
"confidence",
"pyramid_of_pain",
"frameworks",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "malware_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing malware analysis report. Surfaces per-theme review criteria for identification, capabilities, indicators, evidence, ecosystem, detection, reproducibility, and distribution; cross-cutting criteria; anti-patterns; and focus-driven writing analysis. This server never requests your sample, analysis notes, or indicators and instructs your AI to keep them local—guidelines and the report template flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "Focus areas: completeness, clarity, tone, structure, capabilities, confidence, anti_patterns, or all.",
"items": {
"enum": [
"completeness",
"clarity",
"tone",
"structure",
"capabilities",
"confidence",
"anti_patterns",
"all"
],
"type": "string"
},
"type": "array"
},
"sections": {
"description": "Narrow to specific report sections; 'all' includes every section.",
"items": {
"enum": [
"executive_summary",
"sample_snapshot",
"malware_family_identification",
"component_inventory",
"runtime_requirements",
"sources",
"capabilities",
"indicators_of_compromise",
"analysis_details",
"what_we_dont_know",
"infection_vector",
"detection_engineering",
"about_this_report",
"appendix_analysis_environment",
"appendix_analysis_scripts",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "malware_review_report",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's comparative analysis framework for evaluating multiple security companies side by side. Returns structured scoring rubric, evaluation dimensions, evidence tiering guidance, and comparison-type-specific instructions. Requires comparative analysis content. This server never requests your product plans and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"company_count": {
"description": "Number of companies being compared (2-10).",
"maximum": 10,
"minimum": 2,
"type": "integer"
},
"comparison_type": {
"description": "Type of comparison. 'competition': direct/adjacent competitors. 'market_segment': companies in same segment. 'portfolio': cohort evaluation.",
"enum": [
"competition",
"market_segment",
"portfolio"
],
"type": "string"
},
"include_scoring_rubric": {
"description": "Include the structured 1-5 scoring rubric. Default: true.",
"type": "boolean"
}
},
"required": [
"comparison_type",
"company_count"
],
"type": "object"
},
"name": "product_compare_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert strategic guidelines for a specific product strategy topic. Topics: market (segmentation), capabilities (AI, agents, MVP, positioning), sales (GTM, channels, distribution, POCs), pricing (models, retention), delivery (deployment, APIs), trust (compliance, security program), platform (ecosystem positioning), team (expertise, gaps), competitive (differentiation, moats), defensibility (AI-era defensibility rubric scoring a product across seven dimensions), smb (SMB market dynamics), endpoint (endpoint viability), ai_security (AI security vertical), role (product manager responsibilities), category_creation (new category strategy), comparative (multi-company analysis), evidence_tiering (evidence classification framework). This server never requests your product plans and instructs your AI to keep them local—guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"topic": {
"description": "Specific topic to get guidelines for. Omit or use 'all' for a complete overview.",
"enum": [
"market",
"capabilities",
"sales",
"pricing",
"delivery",
"trust",
"platform",
"team",
"competitive",
"defensibility",
"smb",
"endpoint",
"ai_security",
"role",
"category_creation",
"comparative",
"evidence_tiering",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "product_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's fill-in-the-blank template for planning a security product strategy. Includes strategic questions organized by section with evidence columns. This server never requests your product plans and instructs your AI to keep them local—guidelines flow to your AI for local analysis. The template is Copyright (c) 2026 Lenny Zeltser; any content you create using it is entirely yours.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "product_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's product strategy context for local analysis. Returns expert strategic frameworks, principles, and guidance for evaluating or creating security product plans. Includes rating-sheet items (the lens taxonomy: structure, words, tone) as concrete reference points for grounded feedback on the plan's writing. This server never requests your plans and instructs your AI to keep them local. Use detail_level to control response size: \"minimal\" (~2k tokens), \"standard\" (~5k tokens), \"compact\" (~3-4k tokens, all sections but stripped), or \"comprehensive\" (~12k tokens). Use market_segment: \"smb\" for SMB-specific guidance. Use product_focus: \"endpoint\" for endpoint security viability assessment. Set include_template: true to include the fill-in-the-blank template in the response.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"analysis_mode": {
"description": "'internal': planning your own product (default). 'external': evaluating another company from outside. External mode reframes questions and adjusts evidence standards.",
"enum": [
"internal",
"external"
],
"type": "string"
},
"company_context": {
"description": "Filter guidance to startup or large company perspective. Stage values (pre_seed, seed, series_a, series_b, growth, late_stage) imply startup context with stage-specific emphasis.",
"enum": [
"startup",
"large_company",
"pre_seed",
"seed",
"series_a",
"series_b",
"growth",
"late_stage"
],
"type": "string"
},
"detail_level": {
"description": "Level of detail to return. \"minimal\": market + capabilities only (~2k tokens). \"standard\": core strategy sections (~5k tokens, default). \"compact\": all sections with stripped subsections (~3-4k tokens, good for batch analysis). \"comprehensive\": everything + examples (~12k tokens).",
"enum": [
"minimal",
"standard",
"compact",
"comprehensive"
],
"type": "string"
},
"evaluation_perspective": {
"description": "Emphasize framework sections relevant to a specific perspective. Composes with analysis_mode.",
"enum": [
"builder",
"analyst",
"investor",
"buyer"
],
"type": "string"
},
"include_examples": {
"description": "Include examples in framework sections. Default: false.",
"type": "boolean"
},
"include_template": {
"description": "Include the fill-in-the-blank strategy template at the end of the context response. Default: false. Saves a separate product_get_template call.",
"type": "boolean"
},
"market_segment": {
"description": "Include SMB-specific guidance (distribution, buying triggers, readiness).",
"enum": [
"smb"
],
"type": "string"
},
"product_focus": {
"description": "Include vertical-specific guidance. 'endpoint': platform entrapment, defensibility. 'ai_security': AI threat landscape, buyer personas, regulatory alignment.",
"enum": [
"endpoint",
"ai_security"
],
"type": "string"
},
"topics": {
"description": "Specific topics to include. Overrides detail_level for fine-grained control.",
"items": {
"enum": [
"market",
"capabilities",
"sales",
"pricing",
"delivery",
"trust",
"platform",
"team",
"competitive",
"defensibility",
"integrations",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "product_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing product strategy plan. Returns focused guidance for constructive critique—what to check in each section, strategic coherence issues, and how to frame feedback collaboratively. Includes rating-sheet items (the lens taxonomy: structure, words, tone) as concrete reference points for grounded feedback on the plan's writing. This server never requests your plan and instructs your AI to keep it local. Use market_segment: \"smb\" to include SMB-specific review criteria. Use product_focus: \"endpoint\" to include endpoint viability assessment.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "What aspects to focus on. 'completeness': is everything covered? 'strategy': are decisions coherent? 'feasibility': can this team execute?",
"items": {
"enum": [
"completeness",
"strategy",
"feasibility",
"all"
],
"type": "string"
},
"type": "array"
},
"market_segment": {
"description": "Include SMB-specific review criteria.",
"enum": [
"smb"
],
"type": "string"
},
"product_focus": {
"description": "Include vertical-specific review criteria. 'endpoint': endpoint viability. 'ai_security': AI security market assessment.",
"enum": [
"endpoint",
"ai_security"
],
"type": "string"
},
"review_type": {
"description": "'internal': reviewing your own plan (default). 'external-analysis': reviewing an analysis of another company. Adjusts criteria to focus on evidence tiering, source attribution, and marketing language.",
"enum": [
"internal",
"external-analysis"
],
"type": "string"
},
"sections": {
"description": "Specific sections to get review criteria for. Omit or use 'all' for complete review criteria.",
"items": {
"enum": [
"market_segmentation",
"product_capabilities",
"sales_gtm",
"pricing",
"delivery",
"trust",
"platform",
"team",
"competitive_landscape",
"defensibility_rubric",
"integration_priorities",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "product_review_plan",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's cybersecurity-writing rating sheet(s) so your AI can apply the rubric. Returns the structured rubric (groups, items, scoring bands) WITHOUT computing a score. Use `rating_score_writing` if you also want a numeric score, gap analysis, or rubric-anchored feedback. This server never requests your draft and instructs your AI to keep it local—rating sheets and scoring instructions flow to your AI.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"sheet": {
"description": "Which sheet to return. 'structure' / 'look' / 'words' / 'tone' apply to any document. 'info-ir' / 'info-assessment' / 'info-threat' are document-type-specific. 'all' returns the full bundle (default).",
"enum": [
"structure",
"look",
"words",
"tone",
"info-ir",
"info-assessment",
"info-threat",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "rating_get_sheet",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's complete cybersecurity-writing rating toolkit: all 7 sheets, scoring policy, scoring playbook, and cross-references to the writing guidelines. This server never requests your draft and instructs your AI to keep it local—rating sheets and scoring instructions flow to your AI.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "minimal: sheet metadata + scoring playbook only (~2k tokens). standard: full sheets + scoring playbook + cross-references (~6k tokens, default). comprehensive: everything including related articles and errata (~9k tokens).",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
}
},
"type": "object"
},
"name": "rating_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's scoring playbook so your AI can score a draft locally against a cybersecurity-writing rating sheet. THIS IS THE ONLY TOOL THAT PRODUCES NUMERIC SCORES — the writing-coach tools (`get_security_writing_guidelines`, `ir_*`, `product_*`) never score. Returns the rubric plus step-by-step instructions for applying it. This server never requests your draft and instructs your AI to keep it local—rating sheets and scoring instructions flow to your AI.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "minimal: scoring playbook only. standard: rubric + scoring playbook (default). comprehensive: rubric + scoring playbook + cross-references to writing guidelines + related articles.",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"mode": {
"description": "score: per-item pass/fail + total + band classification (default). gaps: enumerate items the draft does NOT satisfy (best fit for Information sheets). feedback: per-item pass/fail + total + band, then constructive critique in the writing-coach voice.",
"enum": [
"score",
"gaps",
"feedback"
],
"type": "string"
},
"sheet": {
"description": "Which sheet to apply. The 7 canonical IDs name a specific rubric. 'auto' picks among the three Information sheets (info-ir / info-assessment / info-threat) based on the document type the user describes; for lens sheets (structure / look / words / tone), pass the sheet ID directly.",
"enum": [
"structure",
"look",
"words",
"tone",
"info-ir",
"info-assessment",
"info-threat",
"auto"
],
"type": "string"
}
},
"required": [
"sheet"
],
"type": "object"
},
"name": "rating_score_writing",
"outputSchema": null
},
{
"description": "Search Lenny Zeltser's Website by keywords. Security articles on malware analysis, incident response, and security leadership. Searches across titles, abstracts, full content, and topics.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"limit": {
"description": "Maximum number of results to return (default: 10, max: 25)",
"maximum": 25,
"minimum": 1,
"type": "number"
},
"query": {
"description": "Search terms to find relevant content",
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "search_zeltser",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"count": {
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"query": {
"type": "string"
},
"results": {
"items": {
"additionalProperties": false,
"properties": {
"abstract": {
"type": "string"
},
"date": {
"type": "string"
},
"title": {
"minLength": 1,
"type": "string"
},
"topics": {
"items": {
"type": "string"
},
"type": "array"
},
"url": {
"minLength": 1,
"type": "string"
}
},
"required": [
"url",
"title"
],
"type": "object"
},
"type": "array"
},
"site": {
"additionalProperties": false,
"properties": {
"domain": {
"minLength": 1,
"type": "string"
},
"name": {
"minLength": 1,
"type": "string"
}
},
"required": [
"name",
"domain"
],
"type": "object"
}
},
"required": [
"query",
"site",
"count",
"results"
],
"type": "object"
}
},
{
"description": "Get Lenny Zeltser's Vuln one-page executive brief template. Standalone variant of `vuln_get_template` for callers that only want the brief without the long-form report. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "vuln_get_brief_template",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Vuln cross-server handoff routes — when this MCP server can't fulfill a request, which other MCP servers (or fallback workflows) to consult. Surfaces a compact subset of `vuln_load_context`. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "vuln_get_cross_server_routes",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's Vuln frameworks (primary frameworks the brief structurally derives from) plus optional sibling frames (adjacent frameworks that aren't the structural backbone). Pass `include_siblings: false` to skip sibling blocks. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"include_siblings": {
"description": "Include the siblingFrames block (adjacent frameworks with whyOmitted notes) and the siblingArtifacts block (related templates) in the response. Default: true.",
"type": "boolean"
}
},
"type": "object"
},
"name": "vuln_get_frameworks",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert vulnerability-brief writing guidelines. Topics include tone, words, structure, voice, articles, summary, fields (per-field guidance), handoffs (cross-server routing), and vuln-specific topics: significance (calibrated insecurity, no vendor passthrough — note this is the Vuln Brief's Significance row, distinct from CVSS/vendor severity scoring), actions (action-enabling What/Why/When/Who), gaps (calibrated uncertainty), sources (evidence synthesis), are_we_affected (scope discipline), and anti_patterns. Pair the 'fields' topic with field_id for single-field guidance. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"field_id": {
"description": "Only meaningful with topic='fields'. When supplied, returns guidance for the named field id. When omitted under topic='fields', returns a directory of available field ids.",
"type": "string"
},
"topic": {
"description": "Which topic to surface. Defaults to a 'summary' overview when omitted.",
"enum": [
"tone",
"words",
"structure",
"voice",
"articles",
"summary",
"significance",
"actions",
"gaps",
"sources",
"anti_patterns",
"are_we_affected",
"fields",
"handoffs",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "vuln_get_guidelines",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's one-page Vulnerability Advisory Brief template. Covers Bottom Line, Quick Facts, Are We Affected?, Defensive Actions (with What/Why/When/Who), What We Don't Know, and More Information. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "vuln_get_template",
"outputSchema": null
},
{
"description": "Load Lenny Zeltser's Vulnerability Investigation Brief context for local analysis. Returns a JSON payload with brief section guidance, completeness criteria, significance discipline (renamed from 'severity' in 1.1.0 — the Vuln Brief's Significance row, distinct from CVSS or vendor severity scoring), evidence-source guidance, frameworks (CVSS / CVE / NVD / CISA KEV / Vendor Advisory), and ALWAYS embeds the mcpHandoffs array — six pointers that tell the AI when to reach for rating_score_writing, rating_get_sheet, get_security_writing_guidelines, cti_load_context, ir_load_context, or search_zeltser. This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail_level": {
"description": "Response size: minimal, standard, or comprehensive.",
"enum": [
"minimal",
"standard",
"comprehensive"
],
"type": "string"
},
"include_examples": {
"description": "Include exampleGood/examplePoor in fieldGuidance entries.",
"type": "boolean"
},
"topics": {
"description": "Narrow the response to specific topics; 'all' includes everything.",
"items": {
"enum": [
"completeness",
"sections",
"writing",
"significance",
"actions",
"gaps",
"sources",
"frameworks",
"handoffs",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "vuln_load_context",
"outputSchema": null
},
{
"description": "Get Lenny Zeltser's expert criteria for reviewing an existing Vulnerability Investigation Brief. Surfaces per-theme review criteria (significance, scope, actions, gaps, sources), cross-cutting criteria, anti-patterns, and inline mcpHandoffs pointers when the requested focus triggers scoring or writing-mechanics themes (e.g., focus=tone surfaces rating_score_writing). This server never requests your vulnerability notes and instructs your AI to keep them local—the brief template and guidelines flow to your AI for local analysis.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"focus": {
"description": "Focus areas: completeness, clarity, tone, structure, significance, actions, sources, or all.",
"items": {
"enum": [
"completeness",
"clarity",
"tone",
"structure",
"significance",
"actions",
"sources",
"anti_patterns",
"all"
],
"type": "string"
},
"type": "array"
},
"sections": {
"description": "Narrow to specific brief sections; 'all' includes every section.",
"items": {
"enum": [
"bottom_line",
"quick_facts",
"are_we_affected",
"defensive_actions",
"what_we_dont_know",
"more_information",
"all"
],
"type": "string"
},
"type": "array"
}
},
"type": "object"
},
"name": "vuln_review_brief",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:504a403954fbe76df6e21f866c653d833e4b662f6580e32d267f9a08cd352b63 | sha256sum