Query FedRAMP 20x KSIs, NIST controls, and compliance docs via 20 MCP tools.
⚠️ This project is sunsetting This MCP server is no longer under active development. The FedRAMP search and FRMR parsing capabilities are being folded into GRC Clanker and myctrl.tools, where they live inside an actual GRC workflow instead of as a standalone subprocess. The npm package and this repository remain available for existing users, but no new features will land here. For the reasoning…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
analyze_control_coverageNo description publishedThis tool published no description. Forge does not invent one.
diff_frmrNo description publishedThis tool published no description. Forge does not invent one.
filter_by_impactNo description publishedThis tool published no description. Forge does not invent one.
get_control_requirementsNo description publishedThis tool published no description. Forge does not invent one.
get_evidence_checklistNo description publishedThis tool published no description. Forge does not invent one.
get_evidence_examplesNo description publishedThis tool published no description. Forge does not invent one.
get_frmr_documentNo description publishedThis tool published no description. Forge does not invent one.
get_ksiNo description publishedThis tool published no description. Forge does not invent one.
get_requirement_by_idNo description publishedThis tool published no description. Forge does not invent one.
get_significant_change_guidanceNo description publishedThis tool published no description. Forge does not invent one.
get_theme_summaryNo description publishedThis tool published no description. Forge does not invent one.
grep_controls_in_markdownNo description publishedThis tool published no description. Forge does not invent one.
health_checkNo description publishedThis tool published no description. Forge does not invent one.
list_controlsNo description publishedThis tool published no description. Forge does not invent one.
list_frmr_documentsNo description publishedThis tool published no description. Forge does not invent one.
list_ksiNo description publishedThis tool published no description. Forge does not invent one.
list_versionsNo description publishedThis tool published no description. Forge does not invent one.
read_markdownNo description publishedThis tool published no description. Forge does not invent one.
search_definitionsNo description publishedThis tool published no description. Forge does not invent one.
search_markdownNo description publishedThis tool published no description. Forge does not invent one.
search_toolsNo description publishedThis tool published no description. Forge does not invent one.
update_repositoryNo description publishedThis tool published no description. Forge does not invent one.
0 of 22 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
## ⚠️ This project is sunsetting This MCP server is no longer under active development. The FedRAMP search and FRMR parsing capabilities are being folded into GRC Clanker and myctrl.tools, where they live inside an actual GRC workflow instead of as a standalone subprocess. The npm package and this repository remain available for existing users, but no new features will land here. For the reasoning and post-mortem, see the project writeup. Disclaimer: This is an unofficial, community project and…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.