mcp-server-scf
Related Servers
Alternatives to mcp-server-scf
No user-submitted related servers found.
Related Servers
- FlicenseCqualityAmaintenanceEnables AI agents to interact with the ComplianceCow platform to retrieve compliance insights, dashboard data, and auditable evidence through a Compliance Graph. It also supports automated remediation actions such as fixing policies and creating tickets in external tools.10013-
- AlicenseAqualityCmaintenanceEnables AI agents to query SOC 2 and ISO 27001 control evidence with server-enforced authorization, including scoped access, column masking, and audit logging.8MIT
- AlicenseAqualityCmaintenanceEnables searching and bidirectional mapping of 1,451 security controls across 262 SCF-mapped frameworks, including ISO 27001, NIST CSF, DORA, and many others, through natural language queries.142,162 PyPI9Apache 2.0
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to query software supply chain compliance data, including asset status, security vulnerabilities, and evidence lineage. It allows for natural language analysis of compliance posture, policy violations, and deployment blockers across an organization.-
- AlicenseNot gradedqualityDmaintenanceProvides comprehensive access to NIST cybersecurity frameworks and controls, enabling AI assistants and applications to query, analyze, and manage NIST security controls through a standardized interface.10MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI assistants to search and retrieve security, privacy, and AI-governance controls from multiple compliance frameworks (e.g., NIST, HIPAA, OWASP) with cross-references, providing authoritative cited control text.-
TDQS
Scored across 196 tools
Most tools are cleanly separated by a consistent verb+resource pattern and unusually detailed descriptions, so list/get/summary variants are usually distinguishable. However, the 196-tool surface reuses the same vocabulary across different concepts (capability vs capability_theme vs system_capability) and has near-neighbor pairs like review_window_assessment vs review_window_assessment_verdict that can mislead before the description is read.
Names are almost uniformly scf_ + snake_case verb_noun, and resource nouns remain stable across list/get/create/update/delete operations. Minor deviations—batch vs bulk, get_systems_for_evidence, and long chains like review_window_assessment_verdict—add noise but do not break the overall pattern.
196 tools is far beyond a coherent single-server surface, even for a broad GRC platform. It would be much more navigable split into per-domain servers (evidence, risk, vendor, engagement, documents, admin). The sheer namespace forces agents to scan a huge list for any task.
Across controls, evidence, risks, vendors, teams, engagements, documents, and webhooks, the set provides comprehensive lifecycle coverage with create/read/update/delete or deliberate status-transition alternatives. Minor gaps exist—no update_webhook, no delete for systems/vendors/evidence tracking records—but they are workable and often appear to be retention-by-design.