Skip to main content
Glama
MarkAC007

mcp-server-scf

by MarkAC007

Related Servers

Alternatives to mcp-server-scf

No user-submitted related servers found.

    Related Servers

    • F
      license
      C
      quality
      A
      maintenance
      Enables AI agents to interact with the ComplianceCow platform to retrieve compliance insights, dashboard data, and auditable evidence through a Compliance Graph. It also supports automated remediation actions such as fixing policies and creating tickets in external tools.
      100
      13
      -
    • A
      license
      A
      quality
      C
      maintenance
      Enables searching and bidirectional mapping of 1,451 security controls across 262 SCF-mapped frameworks, including ISO 27001, NIST CSF, DORA, and many others, through natural language queries.
      14
      2,162 PyPI
      9
      Apache 2.0
    • F
      license
      Not graded
      quality
      C
      maintenance
      Enables AI assistants to query software supply chain compliance data, including asset status, security vulnerabilities, and evidence lineage. It allows for natural language analysis of compliance posture, policy violations, and deployment blockers across an organization.
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      Provides comprehensive access to NIST cybersecurity frameworks and controls, enabling AI assistants and applications to query, analyze, and manage NIST security controls through a standardized interface.
      10
      MIT

    TDQS

    A3.6/5.0

    Scored across 196 tools

    Disambiguation3/5

    Most tools are cleanly separated by a consistent verb+resource pattern and unusually detailed descriptions, so list/get/summary variants are usually distinguishable. However, the 196-tool surface reuses the same vocabulary across different concepts (capability vs capability_theme vs system_capability) and has near-neighbor pairs like review_window_assessment vs review_window_assessment_verdict that can mislead before the description is read.

    Naming Consistency4/5

    Names are almost uniformly scf_ + snake_case verb_noun, and resource nouns remain stable across list/get/create/update/delete operations. Minor deviations—batch vs bulk, get_systems_for_evidence, and long chains like review_window_assessment_verdict—add noise but do not break the overall pattern.

    Tool Count1/5

    196 tools is far beyond a coherent single-server surface, even for a broad GRC platform. It would be much more navigable split into per-domain servers (evidence, risk, vendor, engagement, documents, admin). The sheer namespace forces agents to scan a huge list for any task.

    Completeness4/5

    Across controls, evidence, risks, vendors, teams, engagements, documents, and webhooks, the set provides comprehensive lifecycle coverage with create/read/update/delete or deliberate status-transition alternatives. Minor gaps exist—no update_webhook, no delete for systems/vendors/evidence tracking records—but they are workable and often appear to be retention-by-design.

    Maintenance

    ActivityActive
    ResponsivenessResponsive