Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "generate_architecture" and "run_ai_governance_audit" (16 tools before, 18 now)
Generate architecture & threat model from prompt — Generate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.
Audit architecture or scan against AI regulations — Audit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.
Changed the definition of "compliance_status", "discover_shadow_ai", "get_framework_coverage" and 1 more
Company-level compliance posture rollup across all frameworks (passEUrate,AIcontrolAct,complianceDORA,mitigatedNIST,countsISO,per-frameworkSOCcoverage2).Suitablesuitable foraCIgate. Wraps thegatestraceabilityand
Certificate recorded, valid to 2026-11-22
Authorization not required
First tool surface recorded: 16 tools (server version 1.0.0)
Showing the latest 5 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨3 unchanged words⟩ :{"diagram_id":{"description":"Optional diagramto add framework coverageidforfilter","type":"string"},"scan_id":{"description":"Optionalanchor scan; latest is usedscanifidomittedfilter","type":"string"}},"required": ⟨2 unchanged words⟩
before
—after
Discover Shadow AI & APIsShadow-AI posture (part of Code Security): unsanctioned /ScanunknownconnectedAI-servicerepositoriesusageanddiscoverednetworkintrafficcodefor—unmanagedtotalsLLMs,risk score,foundationalprovider/typemodelbreakdownendpoints,hardcoded-keyvectorcountdatabases,and top discoveries. Companyagentlatestframeworks,or one scan withand`scan_id`.leakedReadsAPIcode_reviewkeysShadowAIReport/ShadowAIDiscovery.(async).
{"additionalProperties":false,"properties":{"limit":{"default":15,"description":"Max discoveries to return","type":"integer"},"scan_id":{"description":"OptionalScanCodeReviewScanidid;withcompany-wideuploadedlatestcodeiforomittedrepository","type":"string"}},"required":["scan_id"],"type":"object"}
before
—after
{"destructiveHint":false,"openWorldHint":true,"readOnlyHint":false,"title":"Discover Shadow AI & APIs"}Compliance-framework coverageGetforrealaControlCodeMap-backeddiagramcoverage(realpercentages,ControlCodeMap-backed)gap counts,optionallyand mapped controls foroneEUframework,AIplusAct,anDORA,optionalNISTcrossmapAIrelationshipRMF,graph.ISOWraps27001,derive_framework_coverageSOC+2,crossmap_cypher.build_graph.etc.
{"additionalProperties":false,"properties":{"diagram_id":{"description":"Diagrampk or uuidid/uuid","type":"string"},"framework":{"description":"Optional framework filter (e.g.'NIST-800-53'eu-ai-act,'SOC2'dora, nist, iso)","type":"string"},"include_graph":{"default":false,"description":"Also return theInclude crossmapnode/edgerelationship graph","type":"boolean"}},"required ⟨3 unchanged words⟩
Verify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploadedcode. Withcode`threat_id`,orverifiesAST.oneIfthreatthreat_idsynchronouslyisandprovided, returnsthesynchronous verdict;without it, verifies every diagramotherwisethreatdispatchesinbatchtheverificationbackground.acrossWrapsallcode_reviewdiagramThreatVerificationService.threats.
{"additionalProperties":false,"properties":{"async_":{"default":true,"type":"boolean"},"code_content":{"description":"Optional inline codecontextsnippet to verify","type":"string"},"repository_id":{"description":"Optionalconnected repo to fetch coderepositoryfromid","type":"string"},"scan_id":{"description":"CodeReviewScanCodeidreview(uuid)scan id","type":"string"},"threat_id":{"description":"Optional:a singlespecific threatidid/codeortocodeverify","type":"string"}},"required": ⟨3 unchanged words⟩