RCO-A2A - Regulatory Compliance Objects MCP server
Signed, deterministic compliance state per object per jurisdiction, resolved upstream
0 stars
Reviews
Write oneNobody has reviewed RCO-A2A - Regulatory Compliance Objects yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
RCO-A2A - Regulatory Compliance Objects tools (5, 1 write)
write = sends, deletes, buys or postsget_recordFreeReturn any RCO by record_id, including superseded records - the audit trail, retained byte-identical.
list_issuersFreeReturn the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.
list_rule_setsFreeList the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.
publish_recordwrite actionFreePublish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.
resolve_complianceFreeReturn the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 1507ms20/20
- Tool poisoning5 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenancelast push 2 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Findings (1)
- highWrite-action tools reachable without authentication
auth.open-write
Grade history
- 2026-09-19restoreD → Bscore 79: Write-action tools reachable without authentication
Install directly
claude mcp add --transport http rco-a2a https://mcp.rco-a2a.ai/mcp
RCO-A2A - Regulatory Compliance Objects: common questions
- Is RCO-A2A - Regulatory Compliance Objects MCP server safe?
- Mostly: it is graded B (79/100). Read the RCO-A2A - Regulatory Compliance Objects safety report
- How do I install RCO-A2A - Regulatory Compliance Objects?
- It runs remotely at mcp.rco-a2a.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does RCO-A2A - Regulatory Compliance Objects need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is RCO-A2A - Regulatory Compliance Objects maintained?
- The last commit was 3 days ago (2026-09-17). The latest release is v1.0.2.
- Is RCO-A2A - Regulatory Compliance Objects up?
- 100% of our last 3 checks got an answer. We check remote servers about four times a day.
- What can I use instead of RCO-A2A - Regulatory Compliance Objects?
- Servers from other publishers that do the same job: State Memory MCP server.
Alternatives to RCO-A2A - Regulatory Compliance Objects
Same job from other publishers: the closest match first, then the best rated.
State Memory MCPDeterministic, persistent graph server for tracking workflow state, decisions, and blockers.not reviewedEstablishedA