FedRAMP Docs MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| FEDRAMP_DOCS_PATH | No | Path to an existing FedRAMP/docs checkout. | ~/.cache/fedramp-docs |
| FEDRAMP_DOCS_BRANCH | No | Branch to checkout when cloning. | main |
| FEDRAMP_DOCS_REMOTE | No | Remote used when cloning. | https://github.com/FedRAMP/docs |
| FEDRAMP_DOCS_AUTO_UPDATE | No | Automatically check for and fetch repository updates. | true |
| FEDRAMP_DOCS_INDEX_PERSIST | No | Persist the in-memory index under `~/.cache/fedramp-docs/index-v1.json`. | true |
| FEDRAMP_DOCS_ALLOW_AUTO_CLONE | No | Clone automatically when the path is missing. | true |
| FEDRAMP_DOCS_UPDATE_CHECK_HOURS | No | Hours between automatic update checks (when auto-update is enabled). | 24 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_frmr_documentsA | List available FRMR JSON documents and metadata. This is usually the first tool to call to discover what FedRAMP data is available. Returns KSI (Key Security Indicators), MAS (Minimum Assessment Standard), VDR (Vulnerability Detection), SCN (Significant Change Notifications), FRD (Definitions), and ADS (Authorization Data Sharing) documents. |
| get_frmr_documentA | Retrieve a FRMR document with metadata, raw JSON, and summary. Use this to get KSI categories (like KSI-IAM, KSI-CNA), MAS requirements, or other FRMR content. First use list_frmr_documents to find available documents, then use this tool with the path. For KSI, use path 'FRMR.KSI.key-security-indicators.json'. |
| list_versionsB | List detected FRMR versions and associated metadata from documents. |
| list_ksiB | List individual KSI requirement entries (like KSI-IAM-01, KSI-CNA-02) with optional filters. To see all KSI categories and their descriptions, use get_frmr_document with path 'FRMR.KSI.key-security-indicators.json' instead. This tool filters specific requirements within categories. |
| get_ksiC | Retrieve a single KSI entry by id. |
| filter_by_impactB | Filter Key Security Indicators (KSI) by impact level. Returns all KSI items that apply to the specified impact level (low, moderate, or high). |
| get_theme_summaryA | Get comprehensive guidance for a KSI theme. Returns all indicators in the theme, impact breakdown, related NIST controls, and links to relevant documentation. |
| get_evidence_examplesB | Get suggested evidence examples for KSI compliance. Returns automation-friendly evidence collection sources (APIs, CLI commands, artifacts) for each KSI. NOTE: These are community suggestions, not official FedRAMP guidance. |
| list_controlsC | Return flattened control mappings across FRMR sets. |
| get_control_requirementsA | Get all FedRAMP requirements mapped to a specific NIST control. Returns KSI items and FRMR requirements that reference the control. |
| analyze_control_coverageA | Analyze which NIST control families have FedRAMP requirements. Returns a coverage report showing which control families are addressed and how many controls/mappings exist for each. |
| search_markdownA | Full-text search across FedRAMP markdown documentation and guidance. Use this to find information about policies, procedures, requirements, and guidance. Examples: 'continuous monitoring', 'incident response', 'significant change', 'authorization boundary'. |
| read_markdownC | Read a markdown file and return its contents and digest. |
| search_definitionsB | Search FedRAMP definitions (FRD document) by term. Returns matching definitions with their full text and any alternate terms. |
| get_requirement_by_idA | Get any FedRAMP requirement by its ID. Works with KSI indicators (KSI-), FRR requirements (FRR-), and FRD definitions (FRD-*). |
| diff_frmrC | Compute a structured diff between two FRMR documents by identifier. |
| grep_controls_in_markdownC | Search markdown files for occurrences of a control identifier. |
| get_significant_change_guidanceC | Aggregate markdown sections and FRMR references related to Significant Change. |
| health_checkB | Verify the index is ready and report status. Returns: indexed file count, repository path, FedRAMP docs commit hash and date, last update check time, and auto-update settings. |
| update_repositoryA | Force update the cached FedRAMP docs repository to get the latest data. This fetches and resets to the latest version from GitHub. The server automatically checks for updates every 24 hours by default, but you can use this tool to update immediately. After updating, you may need to restart the MCP server or rebuild the index to see changes. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 20 tools
Most tools have clearly distinct purposes targeting specific FedRAMP resources like FRMR documents, KSI requirements, or markdown files. However, some overlap exists between get_frmr_document and list_ksi/list_frmr_documents for accessing KSI data, which could cause minor confusion. The descriptions help clarify the distinctions, but the boundaries aren't perfectly sharp.
Tool names follow a highly consistent verb_noun pattern throughout (e.g., analyze_control_coverage, get_control_requirements, list_frmr_documents). All tools use snake_case with clear, descriptive verbs like get, list, search, filter, and update, making the set predictable and readable.
With 20 tools, the count is slightly high but reasonable for the comprehensive FedRAMP documentation domain. It covers a wide range of operations from retrieval and listing to analysis and updates, though it might feel a bit heavy compared to more focused servers. Each tool appears to serve a specific purpose without obvious redundancy.
The tool set provides complete coverage for working with FedRAMP documentation, including CRUD-like operations (e.g., get, list, search, update), analysis tools (e.g., analyze_control_coverage, diff_frmr), and domain-specific features like filtering by impact and accessing guidance. There are no apparent gaps that would hinder an agent's ability to navigate and utilize the data effectively.