Skip to content

feat: MCP server / AI-agent surface - #25

Merged
Hacks4Snacks merged 1 commit into
mainfrom
hacks4snacks/mcpsupport
Jul 9, 2026
Merged

Hacks4Snacks merged 1 commit into
mainfrom
hacks4snacks/mcpsupport

Conversation

@Hacks4Snacks

@Hacks4Snacks Hacks4Snacks commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

feat: MCP server / AI-agent surface

What & why

This PR adds a tmforge mcp server so an AI agent can drive Threat Model Forge end-to-end — read, author, analyze, and report on models — over the same engine Studio and the CLI use. The durable move comes first: imperative authoring (add/connect/set/rename/remove) and declarative manifests (apply/export) were CLI-only, so before exposing anything we lifted that orchestration out of the CLI into the shared engine facade. The surface is stateless and additive: every tool takes a canonical tmforge-json model in and returns the edited model out.

Highlights

  • Lifted authoring facade: authoring + manifest orchestration moves out of the CLI into the engine as AuthoringOperations (a ThreatModel-level core) and AuthoringService (a stateless tmforge-json façade). The five imperative verbs plus apply/export become thin argument-parsers over it. CLI behavior (exit codes and --json output) is unchanged, and the /v1 OpenAPI is byte-identical.
  • tmforge mcp stdio server: a Model Context Protocol server (official ModelContextProtocol SDK) that projects the facade as 20 tools; agents launch it with command: "tmforge", args: ["mcp"] — no separate binary or deployment.
  • Full tool surface: grounding (formats, stencils, property_schema, rules, rule_packs, manifest_schema, detect), model I/O + analysis (read, save, analyze, threats, report, merge), and authoring (apply, export_manifest, add, connect, set, rename, remove).
  • Stateless, model-threaded: no server-side session state — the agent loop apply → analyze → set → analyze → save passes the model call-to-call, which maps cleanly onto MCP's request/response tools.
  • Agent-friendly mapping: tools accept kind nouns, property maps ({ "Protocol": "HTTPS" }), and file paths, marshaled onto the typed facade requests; an unknown kind or invalid property comes back as a structured { success: false, error }, never a crash.
  • .tm7 fidelity preserved: the CLI still edits the file-loaded model directly (full threat-register / geometry fidelity, no DTO round-trip); only the agent/HTTP/WASM facade round-trips through tmforge-json, so imperative CLI edits never silently lose register data.
  • Clean protocol channel: all diagnostics are routed to stderr so stdout carries only the JSON-RPC stream.
  • CLI-only host, by design (and documented): /v1 and the in-browser WASM engine are not wired to authoring in this PR

@Hacks4Snacks
Hacks4Snacks merged commit e3e4a1a into main Jul 9, 2026
0 of 7 checks passed
@Hacks4Snacks
Hacks4Snacks deleted the hacks4snacks/mcpsupport branch July 9, 2026 12:41
This was referenced Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant