ait-testbed / ait-testbed/attackmate

MCP server for attackmate

Open
#239 1 comment 0 reactions 1 assignee Claimed by @thorinaboenke View on GitHub
Dominant language
Python
Stars
51
Forks
10
Avg merge
1d 6h
Merged PRs (30d)
3

Description

**Context**
implement an MCP server so that LLMs can interact with AttackMate

**Alternatives**
1) MCP server wraps the REST API (thin client)
The MCP server is a thin layer that translates LLM tool calls into HTTP requests to attackmate-api-server. AttackMate never runs in-process.

2) MCP server imports AttackMate directly (same pattern as api-server)
The MCP server instantiates AttackMate, calls run_command() / main() directly, same as commands.py and playbooks.py do now.

-> Choosing option 1 for less code duplication.

**why not use "just" fast api and llms interact with that?**
The REST API exposes AttackMate over the network but is not directly usable by LLMs, has no structured tool definitions.
The MCP server will act as a **thin translation layer**: it wraps the REST API, and exposes each operation as a typed _**tool**_ (with schemas auto-generated from the Pydantic models), and serves the existing RST **_resources._**
--> makes AttackMate directly drivable from MCP-compatible clients like Cursor or Claude Desktop **without any changes to the API server itself.**
TLDR:
fastAPI spec: describes only what endpoinds exist
whereas The MCP tools and docstrings and resource URIs embed behavioural guidance for an LLM

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.