# io.github.martc03/us-safety-recalls

NHTSA vehicle recalls and FDA food/drug recalls. 4 tools.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** io.github.martc03
- **License:** Unknown
- **Endpoints:** streamable-http https://us-safety-recalls-mcp.apify.actor/mcp
- **Source:** https://github.com/martc03/gov-mcp-servers
- **Endpoint health:** degraded (last checked 2026-09-06T05:54:32.201Z, 2 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-06T14:08:35.487Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `entity_search_uk_companies` tool: Links to undeclared domain: developer.company-information.service.gov.uk

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `entity_search_global` — Search the GLEIF global LEI (Legal Entity Identifier) database for companies worldwide. Free, no API key required. Returns company name, LEI, jurisdiction, lega
- `entity_get_lei_record` — Get full GLEIF LEI record details for a company by its LEI code. Returns complete entity data including addresses, registration authority, legal form, and relat
- `entity_search_uk_companies` — Search UK Companies House for British company registrations. Returns company name, number, status, type, incorporation date, and registered address. Requires CO
- `entity_search_sec_companies` — Search SEC EDGAR for US public company filings and CIK lookup. Returns entity name, form type, filing date, description, and direct filing URL. Useful for KYC a
- `intel_company_filings` — Search SEC EDGAR for a company's regulatory filings (10-K, 10-Q, 8-K, proxy, etc.). Returns filing date, form type, description, period of report, and direct ED
- `intel_company_news` — Search recent news articles about a company using Google News RSS. Returns article title, link, publication date, and source outlet.
- `intel_company_contracts` — Search USASpending.gov for federal contracts, grants, or loans awarded to a company. Returns award amounts, agencies, dates, and descriptions sorted by award am
- `intel_company_profile` — Get a comprehensive competitive intelligence snapshot for a company. Combines SEC EDGAR filings, Google News articles, and USASpending.gov federal contracts int
- `court_search_opinions` — Search US court opinions and case law. Returns case name, court, date, citations, and opinion snippets. Covers federal and state courts.
- `court_search_dockets` — Search US court dockets and case filings. Returns case name, court, filing date, suit nature, cause, and assigned judge. Covers federal RECAP archive.
- `court_search_judges` — Search judges and people in the US court system. Returns name, court, birth info, political affiliation, and appointer.
- `vuln_lookup_cve` — Look up a CVE by ID and get enriched intelligence: NVD details (CVSS score, description, references), CISA KEV active exploitation status, EPSS exploitation pro
- `vuln_search` — Search the NIST National Vulnerability Database for CVEs by keyword, severity, and date range. Returns CVSS scores, descriptions, and weakness classifications.
- `vuln_kev_latest` — Get recently added entries from the CISA Known Exploited Vulnerabilities (KEV) catalog. These are vulnerabilities confirmed to be actively exploited in the wild
- `vuln_kev_due_soon` — Get CISA KEV vulnerabilities with upcoming remediation deadlines. Federal agencies are required to patch these by the due date. Useful for compliance tracking a
- `vuln_epss_top` — Get CVEs with the highest Exploit Prediction Scoring System (EPSS) probabilities. EPSS scores predict how likely a CVE is to be exploited in the next 30 days. A
- `vuln_trending` — Get recently published critical and high severity CVEs from the NVD. Useful for staying on top of emerging threats and new vulnerability disclosures.
- `vuln_by_vendor` — Search CVEs for a specific vendor or product using CPE matching. Cross-references with CISA KEV to flag actively exploited vulnerabilities for the vendor. Essen
- `env_get_air_quality` — Get current air quality data from EPA AirNow. Returns AQI readings for reporting areas across the US, filterable by state, AQI range, pollutant category, and pa
- `env_search_hud_foreclosures` — Search HUD foreclosure listings from the HUD Home Store. Returns property details including price, bedrooms, location, and listing URLs.
- `finance_search_sec_filings` — Search SEC EDGAR for company filings (10-K, 10-Q, 8-K, etc). Returns entity name, form type, filing date, description, and direct filing URL.
- `finance_get_employment_stats` — Get BLS employment statistics: unemployment rate, nonfarm payrolls, CPI, hourly earnings. Provide series IDs and year range.
- `finance_get_crop_prices` — Get USDA crop and commodity prices (corn, soybeans, wheat, etc). Query by commodity, state, and year range.
- `contracts_search_opportunities` — Search SAM.gov for active federal contract opportunities (solicitations, RFPs, RFQs). Filter by keyword, NAICS code, and date range. Requires a SAM.gov API key.
- `contracts_search_spending` — Search USASpending.gov for federal award spending data (contracts, grants, loans). No API key required. Filter by keyword, award type, date range, and agency.
- `contracts_lookup_entity` — Search SAM.gov for registered entities (contractors, grantees). Look up by business name, UEI, CAGE code, or state. Requires a SAM.gov API key.
- `grants_search_opportunities` — Search Grants.gov for federal funding opportunities. Filter by keyword, status, agency, funding category, instrument type, and eligibility. Returns matching gra
- `grants_get_opportunity` — Get detailed information about a specific grant opportunity by its opportunity number. Returns full description, eligibility requirements, funding amounts, dead
- `grants_search_by_agency` — Search for grants from a specific federal agency. Convenience tool that searches Grants.gov filtered by agency code. Common agencies: HHS (Health & Human Servic
- `grants_get_filter_options` — Get available filter options (agencies, funding categories, eligibilities, instruments, statuses) from Grants.gov. Useful for discovering valid filter values to
- `travel_get_visa_wait_times` — Scrapes the US State Department's global visa wait times page.
- `travel_get_border_wait_times` — Fetches real-time US border crossing wait times from the CBP API.
- `travel_get_airport_delays` — Fetches real-time FAA airport delay and event information.
- `disaster_search_fema_declarations` — Search FEMA disaster declarations by state, incident type, and date range. Returns official federal disaster declaration records.
- `disaster_get_weather_alerts`
- `disaster_search_earthquakes` — Search USGS earthquake data by magnitude, date range, and alert level. Returns recent seismic events worldwide.
- `health_get_cdc_data`
- `health_get_who_indicator`
- `health_list_who_indicators`
- `reg_search_documents`

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"us-safety-recalls\": {\n      \"type\": \"http\",\n      \"url\": \"https://us-safety-recalls-mcp.apify.actor/mcp\"\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on someone else's infrastructure; read-only tool surface.
- Floor 9, ceiling 27 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.martc03%2Fus-safety-recalls
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.martc03%2Fus-safety-recalls/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.martc03%2Fus-safety-recalls
- HTML page: https://forgeregistry.com/registry/io.github.martc03%2Fus-safety-recalls
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
