{"_id":"@auditpilot/compliance-kb-mcp","name":"@auditpilot/compliance-kb-mcp","dist-tags":{"latest":"0.2.0"},"versions":{"0.2.0":{"name":"@auditpilot/compliance-kb-mcp","version":"0.2.0","description":"NIST SP 800-53 Rev 5 knowledge-base MCP server (324 controls) with SOC 2 TSC mappings and BM25 search.","license":"Apache-2.0","type":"module","main":"index.js","module":"index.js","types":"index.d.ts","exports":{".":"./index.js"},"bin":{"compliance-kb-mcp":"index.js"},"scripts":{"build":"node -e \"console.log('compliance-kb-mcp: no npm build step')\"","lint":"node -e \"console.log('compliance-kb-mcp: no npm lint step')\"","test":"node -e \"console.log('compliance-kb-mcp: tests run with pytest')\"","typecheck":"node -e \"console.log('compliance-kb-mcp: type checks run with mypy')\""},"repository":{"type":"git","url":"git+https://github.com/Tharanitharan-M/auditpilot.git"},"homepage":"https://github.com/Tharanitharan-M/auditpilot","bugs":{"url":"https://github.com/Tharanitharan-M/auditpilot/issues"},"publishConfig":{"access":"public"},"keywords":["mcp","model-context-protocol","nist-800-53","soc2","auditpilot","compliance"],"gitHead":"94a7b176360390a5eb7e87b39cd5219a179a005a","_id":"@auditpilot/compliance-kb-mcp@0.2.0","_nodeVersion":"22.14.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-RM5jokV7qV3AKJC/l36HUmfAWfBkeLIz8TMWqUg/rAEZxyRlUhxrkCQ9uoeHY9ELPeclAA44JH6LfV5CdNSk0w==","shasum":"a6114a2049dc15cb186aea8f3a03d5d4ec11e68f","tarball":"https://registry.npmjs.org/@auditpilot/compliance-kb-mcp/-/compliance-kb-mcp-0.2.0.tgz","fileCount":6,"unpackedSize":21869,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC83JASuYKMtPx6+Ji5bXRpfMo6hOCSIX7g7+YU4u+8eQIgLwgBFc+0nqOR9w1bgyMy9INvXOpe5o3Ll48Zvt/B2jE="}]},"_npmUser":{"name":"tharanitharan","email":"tharanimtharan@gmail.com"},"directories":{},"maintainers":[{"name":"tharanitharan","email":"tharanimtharan@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/compliance-kb-mcp_0.2.0_1778037028818_0.9668168100116399"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-06T03:10:28.700Z","0.2.0":"2026-05-06T03:10:28.949Z","modified":"2026-05-06T03:10:29.115Z"},"maintainers":[{"name":"tharanitharan","email":"tharanimtharan@gmail.com"}],"description":"NIST SP 800-53 Rev 5 knowledge-base MCP server (324 controls) with SOC 2 TSC mappings and BM25 search.","homepage":"https://github.com/Tharanitharan-M/auditpilot","keywords":["mcp","model-context-protocol","nist-800-53","soc2","auditpilot","compliance"],"repository":{"type":"git","url":"git+https://github.com/Tharanitharan-M/auditpilot.git"},"bugs":{"url":"https://github.com/Tharanitharan-M/auditpilot/issues"},"license":"Apache-2.0","readme":"# compliance-kb-mcp\n\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![PyPI](https://img.shields.io/pypi/v/compliance-kb-mcp)](https://pypi.org/project/compliance-kb-mcp/)\n[![npm](https://img.shields.io/npm/v/@auditpilot/compliance-kb-mcp)](https://www.npmjs.com/package/@auditpilot/compliance-kb-mcp)\n\n`compliance-kb-mcp` is a typed MCP server that exposes the canonical\n**NIST Special Publication 800-53 Revision 5** control catalog (324 base\ncontrols across 20 families) over stdio transport. Each control is annotated\nwith the SOC 2 Trust Services Criteria identifiers it helps satisfy, derived\nfrom publicly available crosswalks.\n\nThis package is part of the AuditPilot SOC 2 readiness reference architecture\nand is designed to be easy to fork for other control catalogs.\n\n## Why NIST 800-53?\n\n- **Public domain.** NIST 800-53 is a U.S. federal government work and is in\n  the public domain (17 U.S.C. 105). The full canonical control text can be\n  redistributed without licensing concerns.\n- **Machine-readable canonical source.** NIST publishes the catalog in OSCAL\n  JSON, XML, and YAML at\n  [usnistgov/oscal-content](https://github.com/usnistgov/oscal-content).\n- **Well-mapped to SOC 2.** The AICPA publishes a TSC to 800-53 mapping\n  (registration required); supplementary public crosswalks like the\n  [Open Security Architecture project](https://opensecurityarchitecture.org/frameworks/soc2-tsc)\n  make the relationship transparent.\n\n## Positioning\n\n> AuditPilot maps your environment to NIST 800-53 controls and shows which\n> SOC 2 Trust Services Criteria are satisfied by your 800-53 coverage. The\n> included `compliance-kb-mcp` ships with NIST 800-53 Rev 5 (public domain)\n> and curated SOC 2 TSC mappings. For canonical SOC 2 TSC text, refer to\n> AICPA-CIMA's published 2017 Trust Services Criteria -- that text is\n> copyright-protected and is not redistributed in this package.\n\n## Features\n\n- Strict Pydantic v2 schemas with `extra=\"forbid\"`.\n- 324 NIST 800-53 Rev 5 base controls with parameter-substituted statements.\n- Curated SOC 2 TSC to 800-53 mapping covering Common Criteria, Availability,\n  Confidentiality, Processing Integrity, and Privacy clauses.\n- Four MCP tools: `lookup_control`, `lookup_by_soc2_tsc`, `search_controls`,\n  `list_controls`.\n- Naive BM25 ranking for lexical search across statement, guidance, title, and\n  family text.\n- Zero external runtime dependencies beyond `mcp>=1.0` and `pydantic>=2.0`.\n\n## Installation\n\n### Python (for running the stdio MCP server)\n\n```bash\npip install compliance-kb-mcp\n```\n\nOr with uv:\n\n```bash\nuv add compliance-kb-mcp\n```\n\n### npm / Node.js (thin shim that delegates to the Python server)\n\n```bash\nnpm install -g @auditpilot/compliance-kb-mcp\n```\n\nOr run without installation via npx:\n\n```bash\nnpx @auditpilot/compliance-kb-mcp\n```\n\n## MCP Client Configuration\n\nAdd the server to your MCP client config (e.g. Claude Desktop's\n`claude_desktop_config.json`, or your project's `.mcp.json`).\n\n**Using the installed Python package (recommended):**\n\n```json\n{\n  \"mcpServers\": {\n    \"compliance-kb\": {\n      \"command\": \"compliance-kb-mcp\"\n    }\n  }\n}\n```\n\n**Using uvx (no global install required):**\n\n```json\n{\n  \"mcpServers\": {\n    \"compliance-kb\": {\n      \"command\": \"uvx\",\n      \"args\": [\"compliance-kb-mcp\"]\n    }\n  }\n}\n```\n\n**Using npx (Node shim delegates to Python):**\n\n```json\n{\n  \"mcpServers\": {\n    \"compliance-kb\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@auditpilot/compliance-kb-mcp\"]\n    }\n  }\n}\n```\n\n> Note: The npx shim requires Python to be available on PATH. It spawns\n> `python -m compliance_kb_mcp.server` using the `PYTHON` env var if set,\n> otherwise falls back to `python`.\n\n## Tool Reference\n\n### `lookup_control`\n\n- **Input:** `control_id: str` -- NIST 800-53 base identifier, e.g. `\"AC-1\"`\n- **Output:** `Control | None`\n- **Behavior:** Returns the canonical 800-53 control payload (title,\n  statement, guidance, assessment objectives, SOC 2 TSC mappings, citation).\n  Returns `null` if the identifier is not found.\n\n### `lookup_by_soc2_tsc`\n\n- **Input:** `tsc_id: str` -- SOC 2 TSC identifier, e.g. `\"CC6.1\"`, `\"A1.2\"`\n- **Output:** `list[Control]`\n- **Behavior:** Returns all 800-53 controls mapped to the given SOC 2 TSC.\n\n### `search_controls`\n\n- **Input:** `query: str`, `k: int` (1-20, default 5)\n- **Output:** `list[Control]`\n- **Behavior:** Returns top `k` BM25-ranked controls matching the query terms.\n\n### `list_controls`\n\n- **Input:** `family_id: str | None` -- e.g. `\"ac\"`, `\"sc\"`, `\"ia\"`\n- **Output:** `list[ControlSummary]`\n- **Behavior:** Lists all 324 controls (or scoped to a single family) as\n  lightweight summaries including id, title, and SOC 2 TSC mappings.\n\n## Local Development\n\n```bash\n# Install the package in editable mode with dev dependencies\nuv sync --directory packages/compliance-kb-mcp\n\n# Run tests\nuv run --directory packages/compliance-kb-mcp pytest tests/\n\n# Run the server locally (stdio transport)\nuv run --directory packages/compliance-kb-mcp python -m compliance_kb_mcp\n```\n\n## Data Sources\n\n- **Control catalog:** NIST Special Publication 800-53 Revision 5\n  ([DOI 10.6028/NIST.SP.800-53r5](https://doi.org/10.6028/NIST.SP.800-53r5))\n  via the OSCAL JSON catalog at\n  [`usnistgov/oscal-content`](https://github.com/usnistgov/oscal-content/blob/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json).\n- **License:** Public domain (17 U.S.C. 105).\n- **SOC 2 TSC mapping:** Curated from the AICPA-published\n  [Mapping: 2017 Trust Services Criteria to NIST 800-53](https://www.aicpa-cima.com/resources/download/mapping-2017-trust-services-criteria-to-nist-800-53)\n  (registration required) and the publicly available\n  [Open Security Architecture SOC 2 TSC to SP 800-53 crosswalk](https://opensecurityarchitecture.org/frameworks/soc2-tsc).\n- **SOC 2 TSC text:** Copyright AICPA. **Not redistributed in this package.**\n  Refer to the AICPA-CIMA-published\n  [2017 Trust Services Criteria (with revised points of focus - 2022)](https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022)\n  for canonical SOC 2 TSC criteria text.\n\n### How to Refresh the Dataset When NIST Republishes the Catalog\n\n1. Pull the latest catalog from `usnistgov/oscal-content`:\n   ```bash\n   curl -sL https://raw.githubusercontent.com/usnistgov/oscal-content/main/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json \\\n       -o /tmp/nist_catalog.json\n   ```\n2. Regenerate the dataset:\n   ```bash\n   python scripts/build_dataset.py --oscal-source /tmp/nist_catalog.json\n   ```\n3. Re-run the test suite:\n   ```bash\n   uv run --directory packages/compliance-kb-mcp pytest tests/\n   ```\n4. Update `CHANGELOG.md` and the source citation `oscal_last_modified` line in\n   the resulting JSON.\n\n## How To Fork For Another Catalog\n\n1. Copy `packages/compliance-kb-mcp` to a new package folder (for example\n   `packages/iso-27001-kb-mcp` or `packages/cmmc-kb-mcp`).\n2. Rename the Python package and npm metadata.\n3. Replace `src/compliance_kb_mcp/data/nist_800_53_rev5_controls.json` with\n   the new catalog (matching the `Control` Pydantic schema).\n4. Update `Control.framework` literals and validation patterns in `schemas.py`.\n5. Keep the tool signatures unchanged so existing LangGraph integrations\n   continue to work.\n6. Run tests and dry-run packaging:\n   - `pytest tests/`\n   - `npm pack --dry-run`\n   - `uv build`\n\n## License\n\nApache-2.0. See [LICENSE](./LICENSE).\n","readmeFilename":"README.md","_rev":"1-d094e7e4ae56242a41703fb28e0b6d43"}