
How Dropbox uses MCP and Dash to close the design-to-code security gap
6/12/2026
Introduced a system leveraging Model Context Protocol (MCP) and Dash to automatically retrieve and analyze threat models during code review. This system uses foundational LLMs to compare code changes against documented security requirements, aiming to close the design-to-code security gap. The post details the architecture, the problem of the design-to-code gap (highlighting that only 12% of PRs link to threat models and a median delay of five weeks between review and implementation), and the validation of the approach through semantic search analysis.
