MCP Server for OSCAL
Related Servers
Alternatives to MCP Server for OSCAL
No user-submitted related servers found.
Related Servers
- AlicenseAqualityFmaintenanceProvides AI assistants with specialized tools to interact with NIST's Open Security Controls Assessment Language (OSCAL) framework. It enables agents to retrieve schemas, explore models, and generate valid OSCAL documentation for security compliance automation.4053Apache 2.0
- AlicenseNot gradedqualityDmaintenanceProvides comprehensive access to NIST cybersecurity frameworks and controls, enabling AI assistants and applications to query, analyze, and manage NIST security controls through a standardized interface.10MIT
- AlicenseAqualityDmaintenanceProvides structured access to the full NIST cybersecurity catalog, including SP 800/1800 publications, security controls, CSF 2.0, and the NVD database. It enables AI assistants to search and retrieve cybersecurity standards, CVEs, and compliance guidance directly from a local SQLite index.201MIT
- AlicenseNot gradedqualityAmaintenanceEnables AI assistants and IDEs to work with the AGNTCY Agent Directory, providing tools for validating, publishing, searching agent records, and navigating OASF taxonomies.3Apache 2.0
- AlicenseAqualityAmaintenanceEnables AI agents to safely query FINOS data standards with typed, read-only tools for AIGF risks and controls, CDM type and validation, and FDC3 intents and context schemas.11Apache 2.0
- AlicenseNot gradedqualityBmaintenanceEnables AI agents and builders to run local, audit-traceable governance assessments, including an A³ scorecard, ISO/IEC 42001 and NIST evidence templates, compliance checklists, passport lookup, and sensitive-text screening.MIT
TDQS
Scored across 40 tools
The server uses a deliberate list_/query_ duality (e.g. list_catalogs vs query_catalog, list_poams vs query_poam) where the boundary is documented but still easy to confuse; the component-definition family (list_component_definitions, list_components, list_capabilities, get_capability, query_component_definition) breaks this pattern and adds further ambiguity. Descriptions are detailed and mostly disambiguate, and the many list_*_child_element tools are clearly scoped by OSCAL model and element type.
Mostly consistent snake_case verb_noun (list_x, query_x, get_x, validate_x). Minor deviations: query_assessment_plan is singular while its peers are plural (list_assessment_plans), text_search_oscal inverts the noun/verb order, and the bare 'about' tool breaks the pattern.
40 tools is heavy for this surface and exceeds the comfortable range; many list_*_child_* tools could arguably be folded into query tools with an element-type parameter. The breadth mirrors OSCAL's many model types but still feels over-expanded.
Covers listing/querying of catalog, profile, SSP, component-definition, assessment-plan/results, POA&M, and mapping collections, plus full-text search, schema retrieval, validation (content and file), and child-element lookup. Read/query/validate coverage is strong; write operations (create/update/delete) are absent, but a validation-and-query server may not need them.