1. Conduid
  2. Developer Tools
  3. Hackathon 12 MCP Compliance
MCP server · Developer Tools

Hackathon 12 MCP Compliance

An mcp server to support compliance operations in AI agents

Unclaimed last commit 6 months ago devtools
48Fair

Scored 4 months ago · breakdown

About Hackathon 12 MCP Compliance

Hackathon 12 MCP Compliance is an MCP server published by grafana in the Developer Tools category: an mcp server to support compliance operations in AI agents. It has been installed 0 times through Conduid.

The repository has 4 stars and 2 forks, with the last commit 6 months ago. Six months or more without a commit doesn't mean the server is broken, but check the open issues (0) before depending on it in production.

Install

Install
npx hackathon-12-mcp-compliance

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Hackathon 12 MCP Compliance

Powered by Claude · Grounded in docs

I know everything about Hackathon 12 MCP Compliance. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • !Scoped permissionsDoesn't declare a permission scope. Assume it can do anything its process can.

README

MCP Compliance

A project for compliance that provides CLI tools and an MCP server for agents to interact with compliance data.

Overview

The FedRAMP Compliance MCP Server is designed to support users throughout their compliance journey, which consists of three main phases:

  1. Understanding - Learning about security controls, their requirements, and how they apply to your system
  2. Implementing - Designing and implementing controls in your system to meet compliance requirements
  3. Evidencing - Collecting and documenting evidence to demonstrate compliance with controls

This project provides tools for working with FedRAMP compliance data, including:

  1. CLI tools for processing and querying FedRAMP baseline data
  2. An MCP server that exposes compliance data to LLM agents

Roadmap

This project is missing the automation of evidence collection. There needs to be a way to securely store what may be sensitive data in a shared location that provides the proper ACLs and data protection. This is intended to be added in a future hackathon or additional roadmap time.

Easy Button Quick Start

For the quickest setup:

# Create the directory for the MCP compliance binary
mkdir -p ~/.mcp-compliance/bin

# Add to your PATH (add this to your .bashrc or .zshrc for persistence)
export PATH=$PATH:~/.mcp-compliance/bin

# Clone the repository
git clone https://github.com/grafana/hackathon-12-mcp-compliance.git
cd hackathon-12-mcp-compliance

# Build and deploy locally
make deploy-local

Now you can configure your agent (Cursor or Claude Desktop) to use the MCP compliance server. See the Getting Started Guide for configuration details.

Documentation

MCP Server

The MCP server provides the following tools for LLM agents:

  • get_control: Get detailed information about a specific control
  • get_control_family: Get all controls in a specific family
  • list_control_families: List all control families in a program
  • search_controls: Search for controls by keyword
  • get_control_evidence_guidance: Get detailed guidance for evidence about a specific control

Data Sources

The FedRAMP baseline files are sourced from the official GSA FedRAMP Automation GitHub repository:

README mirrored from the source repository 4 months ago. The original is authoritative.

Questions

About Hackathon 12 MCP Compliance

How do I install Hackathon 12 MCP Compliance?

Run npx hackathon-12-mcp-compliance, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Hackathon 12 MCP Compliance safe to use with an AI agent?

Its trust score is 48 out of 100 (fair). It passes 0 of 1 static security checks; the failures are listed above. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Hackathon 12 MCP Compliance still maintained?

The last commit was 6 months ago, with 0 open issues. That's long enough that you should check whether the maintainer is responding to issues before depending on it.