Run an attack-graph analysis
Kill-chain patterns are synthesized from capability co-existence - which MCP server capabilities can combine if the servers were wired into one agent. There are two ways to run one, and a registry-wide reference feed below them. Every pattern here is hypothetical: a path the configuration permits, never an observed data flow. A cross-server flow is only ever observed in a sandbox run of your own config (Mode A); everything else is inferred.
Submit the client config you actually run to get cross-server analysis over the servers you wire together: the kill-chain patterns (always hypothetical - what the configuration permits, not something we watched happen), the inferred cross-server flow joined statically from what the servers declare, and - when a sandbox run is possible - the observed cross-server flow, the only place an edge is ever witnessed.
Not sure what you would get back? See a worked example first.
Choose tool-bearing servers from the registry and run the analysis over that selection right here. This composes a hypothetical “if you co-configured these” chain - not an observed flow and not a verdict on any one server. Use the picker just below.
Pick tool-bearing servers from the registry and run the multi-step attack-graph analysis over that selection in real time. This asks “IF you co-configured these servers into one agent, which CVE-backed kill-chain template (KC01–KC07) could their capabilities compose?” - a hypothetical, inferred co-existence composition. The unit of value is the kill-chain-template match (the KC0X shape it discovers), not the exploitability score, which is a lower-confidence inferred estimate. It is not a witnessed flow, and not a score against any one server.
Below is the precomputed registry-wide co-existence feed - a separate, hypothetical reference unit over the whole registry, distinct from the interactive runs above and from a config-scoped flow. Its framing is unchanged.
Hypothetical compositions - not witnessed data flow
Every chain here is synthesized from capability co-existence across the registry: which server capabilities can combine if the servers were wired into one agent, drawn from the risk-matrix P01–P12 edges. It is not witnessed, observed, or executed data flow — the connecting hop is an agent at runtime, not code anyone watched run.
Read each as a hypothetical kill-chain pattern — “if these servers were wired into one agent” — a capability co-existence chain, not an attack path. Nothing on this page has been observed crossing between servers, and no real deployment is claimed to compose these servers together.
This unit is registry-wide and hypothetical. A per-server score stays intrinsic to that one server; a witnessed cross-server flow is a property of one specific client configuration. For the higher-fidelity, config-scoped picture, submit a client config below.
Kill Chain Analysis
Hypothetical kill-chain patterns synthesized from registry-wide capability co-existence — which MCP server capabilities can combine, never a witnessed data flow. Each pattern maps to a real-world CVE or published research and is exploitability- scored. 7 kill chain templates (KC01–KC07) with 7-factor exploitability scoring.
The chains above are registry-wide co-existence — hypothetical, and never a claim about any one deployment. A submitted client config gets the higher-fidelity, config-scoped view instead: a static join (inferred binding) proving reader→sink pairs across the servers you actually wired together, and — with observe_cross_server_flow — a runtime-observed flow observed in an egress-denied sandbox. That is the only place an edge here can ever be labelled observed. See an illustrative walkthrough on the Cross-Server Toxic Flow demo.
Kill Chain Templates
Each template models a real-world multi-step attack. A chain is synthesized only when the required cross-server capability co-existence patterns and edges (P01–P12) are present in the registry — it is a hypothetical composition, not a witnessed intrusion.
Chain synthesis composes registry-wide capability co-existence (the P01–P12 risk-matrix edges) into hypothetical kill-chain patterns. None have been synthesized from the current registry snapshot.
This is not a clean-bill result and is not scored as one — it means no capability co-existence chain has been composed yet, not that any deployment was checked and found safe. A per-server score is separate and intrinsic; a config-scoped cross-server flow is available by submitting a client config on the scan page.