Sadu MCP Server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| corf_overviewA | Summary of the CBK Cyber and Operational Resilience Framework v1.0: the three baselines, counts of domains, sub-domains, control areas and controls, the crosswalk targets and the official source. Start here. |
| corf_list_baselinesB | The three CORF baselines with their ids, titles and counts of domains, sub-domains, areas and controls. |
| corf_list_domainsA | The 27 CORF domains with their baseline, reference number, title and counts. Optionally limited to one baseline. |
| corf_list_subdomainsA | The 93 CORF sub-domains with their domain, title, official page and counts of areas and controls. Optionally limited to one baseline or one domain id such as "crb:5". |
| corf_list_areasA | Control areas with their own-words summary and control counts. Limit to a baseline, a domain id ("orb:6") or a sub-domain id ("crb:5.6"). Paged. |
| corf_get_areaA | One control area by id ("crb:5.6.1", "5.6.1" defaults to crb, "tprm 10.1.1"): its own-words summary, sub-domain and domain, the ids and official pages of its controls, and its ISO 27001, PCI DSS and SWIFT CSCF references. The official text is at the page given. |
| corf_searchB | Search control areas by id, title or summary in English or Arabic. Optionally limited to one baseline. Paged. |
| corf_crosswalkB | The ISO 27001 Annex A controls, PCI DSS v4.0.1 requirement groups and SWIFT CSCF v2026 controls woven to one CORF control area. The mapping is this project's analysis, not an official mapping. |
| corf_reverse_crosswalkA | Start from an ISO 27001 control ("A.5.19"), a PCI DSS requirement group ("8.4") or a SWIFT CSCF control ("2.9") and get the CORF areas mapped to it, plus what the other two frameworks say about those areas (derived through the CORF hub). |
| corf_list_frameworkB | The full list of ISO 27001:2022 Annex A controls (93), PCI DSS v4.0.1 requirements and groups (12 and 63) or SWIFT CSCF v2026 controls (32, with mandatory or advisory status), each with the number of CORF areas mapped to it. |
| corf_readiness_reportA | Score an assessment exported from the Sadu web app (schema "sadu/1": status per control, maturity 1 to 5 per sub-domain, applicability per sub-domain, notes). Returns overall and per baseline readiness, maturity averages, applicability counts and the largest gaps. Unknown ids and invalid values are ignored. |
| corf_sourcesB | The official sources used, what each was used for, and the provenance note including the count discrepancy in the CBK document. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
Each tool targets a distinct aspect of the CORF reference domain: overview, hierarchical listing, area lookup/search, bidirectional crosswalks, external framework listing, and readiness scoring. The only mild overlap is list_areas vs. search, but the browsing-vs-query intent is clearly described.
All tool names use lowercase snake_case with a consistent corf_ prefix. The mix of verb_noun names and clear noun names (overview, crosswalk, sources) remains predictable within the same namespace.
12 tools is well-scoped for a structured framework reference, crosswalk, and readiness-reporting server. Each tool earns its place by covering a distinct facet of navigation or analysis.
The surface covers overview, hierarchy, area retrieval, search, bidirectional crosswalks, external framework lists, readiness reporting, and sources. Direct get_control or get_subdomain detail tools are absent, but control IDs and official pages are exposed through area/subdomain listings, making this a minor gap.