gridwork-privacy
Official# gridwork-privacy
MCP server that audits websites for GDPR, CCPA, and ePrivacy compliance.
## What it does
- Detects 30+ third-party trackers (Google Analytics, Facebook Pixel, TikTok, Criteo, etc.)
- Analyzes cookie consent mechanisms (CMP detection, reject options, pre-checked boxes)
- Checks privacy policy presence and required disclosures
- Reviews data collection forms for sensitive fields
- Classifies each tracker's GDPR concern level
- Identifies specific regulatory articles for each finding
## Install
```bash
npx gridwork-privacy
```
## MCP tools
| Tool | Description |
|------|-------------|
| `audit_privacy` | Full privacy audit — trackers, consent, policy, data collection |
| `scan_trackers` | Quick tracker detection with GDPR concerns |
| `check_consent` | Cookie consent mechanism compliance check |
| `compare_privacy` | Side-by-side privacy comparison of two sites |
## Claude Desktop config
```json
{
"mcpServers": {
"gridwork-privacy": {
"command": "npx",
"args": ["-y", "gridwork-privacy"]
}
}
}
```
## License
MIT — [Gridwork](https://thegridwork.space)
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: scan_trackers detects trackers, check_consent evaluates consent mechanisms, compare_privacy compares two sites, and audit_privacy performs a comprehensive audit. No overlap or ambiguity.
All tool names follow a consistent verb_noun pattern: scan_trackers, check_consent, compare_privacy, audit_privacy. The verbs ('scan', 'check', 'compare', 'audit') are distinct and the nouns are clear.
With 4 tools, the set is well-scoped for a privacy analysis server: quick scan, consent check, comparison, and comprehensive audit. Each tool earns its place without being excessive or insufficient.
The tool surface covers the core privacy analysis workflow: tracker detection, consent evaluation, comparison, and full audit. There are no obvious missing operations for the domain.