Mmcp.market

Oscal Generator MCP server

by CSOAI-ORG·io.github.CSOAI-ORG/oscal-generator-mcp·v0.1.2

Generate machine-readable NIST OSCAL packages (SSP/component-definition) + FedRAMP RFC-0024

C65/100grade C
What users say
No reviews yet
Be the first
Safety scan
C65/100

full report

Adoption
Not measured yet

Usage numbers are collected on the next scan

Reviews

Write one

Nobody has reviewed Oscal Generator yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Oscal Generator tools (8)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • generate_component_definition

    Generate a NIST OSCAL Component Definition for a reusable component (e.g. an MCP server, a service).

  • generate_protocol_package

    Generate ONE Ed25519-signed OSCAL Component Definition describing an entire protocol — every component (e.g. each Layer-0 bridge/MCP) mapped to its frameworks' NIST controls. Makes the whole protocol a machine-readable, signed, offline-verifiable compliance package. components: [{name, type?, frameworks[]}].

  • generate_ssp

    Generate a NIST OSCAL System Security Plan (SSP) skeleton for a system. impact_level: low|moderate|high. controls: NIST 800-53 control ids (e.g. AC-2, AU-6); defaults to a baseline set.

  • rfc0024_readiness

    Score readiness for FedRAMP RFC-0024 (machine-readable OSCAL packages, first deadline 30 Sep 2026).

  • sign_oscal

    Ed25519-sign an OSCAL document (canonical JSON) → a cryptographically signed, offline-verifiable package. Satisfies the RFC-0024 signed-package requirement; same scheme as the CSOAI Compliance Passport.

  • validate_oscal

    Validate an OSCAL document's structure (root model, uuid, metadata, oscal-version, control-implementation).

  • validate_oscal_strict

    Strictly validate an OSCAL document against the standard community toolchain (oscal-compass/compliance-trestle's NIST-schema-derived models). If trestle isn't installed (pip install 'oscal-generator-mcp[validate]'), this gracefully falls back to the built-in structural validator and says so. A pass here = "validates under the standard OSCAL toolchain" — the credibility claim for the FedRAMP RFC-00

  • verify_oscal_signature

    Verify an Ed25519 signature over an OSCAL document — offline, no account. Returns valid True/False.

Public scan report

scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it

1 low
  • Code scan2 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenanceno repository listed3/15
  • Maintainer identityno repository or website to verify2/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 65/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add oscal-generator-mcp -- uvx oscal-generator-mcp
Add to Cursor

Oscal Generator: common questions

Is Oscal Generator MCP server safe?
With care: it is graded C, so read the findings first (65/100). Read the Oscal Generator safety report
How do I install Oscal Generator?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Oscal Generator need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Oscal Generator maintained?
The latest release is v0.1.2.
What can I use instead of Oscal Generator?
Servers from other publishers that do the same job: Ignite UI Theming MCP Server.

Alternatives to Oscal Generator

Same job from other publishers: the closest match first, then the best rated.

More from CSOAI-ORG →