Oscal Generator MCP server
Generate machine-readable NIST OSCAL packages (SSP/component-definition) + FedRAMP RFC-0024
Usage numbers are collected on the next scan
Reviews
Write oneNobody has reviewed Oscal Generator yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Oscal Generator tools (8)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
generate_component_definitionGenerate a NIST OSCAL Component Definition for a reusable component (e.g. an MCP server, a service).
generate_protocol_packageGenerate ONE Ed25519-signed OSCAL Component Definition describing an entire protocol — every component (e.g. each Layer-0 bridge/MCP) mapped to its frameworks' NIST controls. Makes the whole protocol a machine-readable, signed, offline-verifiable compliance package. components: [{name, type?, frameworks[]}].
generate_sspGenerate a NIST OSCAL System Security Plan (SSP) skeleton for a system. impact_level: low|moderate|high. controls: NIST 800-53 control ids (e.g. AC-2, AU-6); defaults to a baseline set.
rfc0024_readinessScore readiness for FedRAMP RFC-0024 (machine-readable OSCAL packages, first deadline 30 Sep 2026).
sign_oscalEd25519-sign an OSCAL document (canonical JSON) → a cryptographically signed, offline-verifiable package. Satisfies the RFC-0024 signed-package requirement; same scheme as the CSOAI Compliance Passport.
validate_oscalValidate an OSCAL document's structure (root model, uuid, metadata, oscal-version, control-implementation).
validate_oscal_strictStrictly validate an OSCAL document against the standard community toolchain (oscal-compass/compliance-trestle's NIST-schema-derived models). If trestle isn't installed (pip install 'oscal-generator-mcp[validate]'), this gracefully falls back to the built-in structural validator and says so. A pass here = "validates under the standard OSCAL toolchain" — the credibility claim for the FedRAMP RFC-00
verify_oscal_signatureVerify an Ed25519 signature over an OSCAL document — offline, no account. Returns valid True/False.
Public scan report
scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it
- Code scan2 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenanceno repository listed3/15
- Maintainer identityno repository or website to verify2/10
Findings (1)
- lowNo source repository listed
maint.no-repo
Install directly
claude mcp add oscal-generator-mcp -- uvx oscal-generator-mcp
Oscal Generator: common questions
- Is Oscal Generator MCP server safe?
- With care: it is graded C, so read the findings first (65/100). Read the Oscal Generator safety report
- How do I install Oscal Generator?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Oscal Generator need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Oscal Generator maintained?
- The latest release is v0.1.2.
- What can I use instead of Oscal Generator?
- Servers from other publishers that do the same job: Ignite UI Theming MCP Server.
Alternatives to Oscal Generator
Same job from other publishers: the closest match first, then the best rated.
- Ignite UI Theming MCP ServerGenerate Sass palettes, typography, elevations, and themes for Ignite UI components.not reviewedEstablishedA