What’s new here
This server breaks threat modeling into nine phases, each with structured input validation and phase-completion checks. Phase 7.5 adds optional code-validation evidence, where the agent records which threats and mitigations it found implemented in the actual source. The server uses the client’s own configured LLM (Amazon Q, Kiro, Cline) rather than calling a separate model API.
What it does
The server exposes 11 MCP tools that manage workflow state, system context, architecture components, threat actors, trust boundaries, asset flows, threats, mitigations, and code validation evidence. A manage_workflow tool returns per-phase guidance and tracks completion status. When every phase passes its checks, export_threat_model writes a Threat Composer .tc.json file and a Markdown report into a .threatmodel directory inside the project.
The STRIDE categories (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) structure Phase 6. Assumptions are documented to scope out irrelevant threats before the analysis runs.
All state lives in memory for the current process. Exports are snapshots; the server does not reload them on restart.
Who it’s for
Security engineers or developers who want structured threat model output from a coding agent rather than a one-shot LLM response. The README documents Kiro, Cline, and Amazon Q as MCP clients. For Kiro CLI, a pre-packaged agent configuration in .kiro/agents/threat-modeler.json runs all nine phases non-interactively.
Try it
First, install uvx from Astral. Then add to your MCP client config and restart the IDE. For Amazon Q (~/.aws/amazonq/mcp.json):
{
"mcpServers": {
"threat-modeling-mcp-server": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/awslabs/threat-modeling-mcp-server.git",
"threat-modeling-mcp-server"
],
"env": {
"FASTMCP_LOG_LEVEL": "ERROR"
},
"disabled": false,
"autoApprove": ["manage_workflow","export_threat_model","manage_system_context","manage_assumptions","manage_architecture","manage_threat_actors","manage_trust_boundaries","manage_asset_flows","manage_threats","inspect_data_models","manage_code_validation"]
}
}
}Then in your agent chat:
Threat model this project using the threat modeling MCP Server
For non-interactive Kiro CLI runs, first install the bundled agent from a clone (./install-kiro-agent.sh for a global install, or copy the repo’s .kiro directory into your project):
kiro-cli chat --agent threat-modeler --no-interactive "Threat model this project"How mature is it
113 stars, 20 forks, 5 contributors, 0 releases. Created December 2025, last pushed October 2026. 8 commits in the past 90 days. 2 open issues and 9 open pull requests. Apache-2.0.