{"_id":"@callmarcus/securityscorecard-mcp","_rev":"6-43679c6aee220e87482569afbab2aa76","name":"@callmarcus/securityscorecard-mcp","dist-tags":{"latest":"1.2.0"},"versions":{"1.0.1":{"name":"@callmarcus/securityscorecard-mcp","version":"1.0.1","_id":"@callmarcus/securityscorecard-mcp@1.0.1","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"bin":{"ssc-mcp":"build/index.js"},"dist":{"shasum":"1cb2d1a6f61dcc6e7e5cf550fd5b051107963f05","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.0.1.tgz","fileCount":1220,"integrity":"sha512-OQG4fZKeUxdbge/3dJ3ZYMVJSSSWEedbV8dgPjKa6ejNT9cDFRaciPO5S/gR5aKEb8z+W7unQ9smOSzhSyyRKQ==","signatures":[{"sig":"MEUCIQCwtGjPJuIJmmdKo6Ja6m31bLGifm6iE9te6UZY/Jw1TAIgPZiylfKXlh/P0JCsqe/U3z9p2fwW69QKMgW5BEk2rt8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15035527},"main":"build/index.js","type":"module","engines":{"node":">=18"},"gitHead":"ca36c700c8a443f9aebae27afdb15f9b9d77df30","mcpName":"io.github.callmarcus/securityscorecard-mcp","scripts":{"test":"node --test tests/*.test.js","build":"tsc","start":"node build/index.js","dev:api":"npm run api:update && npm run build","test:ts":"node --test tests/*.test.ts","api:full":"npm run api:fetch && npm run api:update && npm run build","api:test":"npm run test","validate":"python validate_mcp_tools.py","api:embed":"node --loader ts-node/esm src/integration/api-reference-embeddings.ts","api:fetch":"bash tools/update_api_spec.sh","api:update":"npm run api:generate && npm run api:embed","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","api:generate":"python split_swagger.py","api:validate":"node examples/basic_usage.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","prepublishOnly":"npm run build:fast","test:validation":"npm run test"},"_npmUser":{"name":"callmarcus","email":"westermark@gmail.com"},"_npmVersion":"11.6.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","directories":{},"_nodeVersion":"20.19.4","dependencies":{"zod":"^4.3.6","dotenv":"^17.4.1","@huggingface/transformers":"^4.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.27.7","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/securityscorecard-mcp_1.0.1_1780766986994_0.506745335619698","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@callmarcus/securityscorecard-mcp","version":"1.0.2","_id":"@callmarcus/securityscorecard-mcp@1.0.2","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"bin":{"ssc-mcp":"build/index.js"},"dist":{"shasum":"23f1eb71854a64a19076ac4e98c2e0591efa95fc","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.0.2.tgz","fileCount":1143,"integrity":"sha512-qya6xY4n7aATtttLIf73vWo1O1r3LkxC5EgEtSRhfhifqZ5pIhx0IlkUhF23wQrivYMwq49KuJ1HcOz1uFXNcA==","signatures":[{"sig":"MEUCIHpMBwCNZvBoucH4XiZziAv3UBavKBlieE6InaDk0V2nAiEA3rASH3HmXWd9DpttooxJE7Y/Ra7fvTFNIZ5iGCbBWA0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14979291},"main":"build/index.js","type":"module","engines":{"node":">=18"},"gitHead":"05ed90ba8a13bf8abb47aeacb26d9cc009ca5c01","mcpName":"io.github.callmarcus/securityscorecard-mcp","scripts":{"test":"node --test tests/*.test.js","build":"tsc","start":"node build/index.js","dev:api":"npm run api:update && npm run build","test:ts":"node --test tests/*.test.ts","api:full":"npm run api:fetch && npm run api:update && npm run build","api:test":"npm run test","validate":"python validate_mcp_tools.py","api:embed":"node --loader ts-node/esm src/integration/api-reference-embeddings.ts","api:fetch":"bash tools/update_api_spec.sh","api:update":"npm run api:generate && npm run api:embed","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","api:generate":"python split_swagger.py","api:validate":"node examples/basic_usage.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","prepublishOnly":"npm run build:fast","test:validation":"npm run test"},"_npmUser":{"name":"callmarcus","email":"westermark@gmail.com"},"_npmVersion":"11.6.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","directories":{},"_nodeVersion":"20.19.4","dependencies":{"zod":"^4.3.6","dotenv":"^17.4.1","@huggingface/transformers":"^4.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.27.7","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/securityscorecard-mcp_1.0.2_1780767459850_0.5164190826985604","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@callmarcus/securityscorecard-mcp","version":"1.0.3","_id":"@callmarcus/securityscorecard-mcp@1.0.3","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"bin":{"ssc-mcp":"build/index.js"},"dist":{"shasum":"2cd41eec07e37f2f4adeb3a60d212b43162030e2","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.0.3.tgz","fileCount":1143,"integrity":"sha512-sdrChbg8hVJ86qPwCK47xTu4yb4HPeUUHg+9uORIy1Ck5vEtnS9dAVzdUJrZTkp0lGE+A/jxEuTRjSRrZFQIJQ==","signatures":[{"sig":"MEQCIBJ86k+/Wd2ta4+EJo8FyuaHkM2DVbzl3FzOJP7Hmd/1AiAd9rdsfQ82T0QZtQh0f2GVkxncuk7bfbDKjfwDhIG0dw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14979291},"main":"build/index.js","type":"module","engines":{"node":">=18"},"gitHead":"335d7686d9e147171cdd6479347a50ed41c33756","mcpName":"io.github.CallMarcus/securityscorecard-mcp","scripts":{"test":"node --test tests/*.test.js","build":"tsc","start":"node build/index.js","dev:api":"npm run api:update && npm run build","test:ts":"node --test tests/*.test.ts","api:full":"npm run api:fetch && npm run api:update && npm run build","api:test":"npm run test","validate":"python validate_mcp_tools.py","api:embed":"node --loader ts-node/esm src/integration/api-reference-embeddings.ts","api:fetch":"bash tools/update_api_spec.sh","api:update":"npm run api:generate && npm run api:embed","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","api:generate":"python split_swagger.py","api:validate":"node examples/basic_usage.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","prepublishOnly":"npm run build:fast","test:validation":"npm run test"},"_npmUser":{"name":"callmarcus","email":"westermark@gmail.com"},"_npmVersion":"11.6.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","directories":{},"_nodeVersion":"20.19.4","dependencies":{"zod":"^4.3.6","dotenv":"^17.4.1","@huggingface/transformers":"^4.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.27.7","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/securityscorecard-mcp_1.0.3_1780768721243_0.20352687758028076","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@callmarcus/securityscorecard-mcp","version":"1.1.0","_id":"@callmarcus/securityscorecard-mcp@1.1.0","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"bin":{"ssc-mcp":"build/index.js"},"dist":{"shasum":"920cf111c3e2906823878b6797e5e15f703d3bcc","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.1.0.tgz","fileCount":523,"integrity":"sha512-Wh9MVcFItsNLzFOnpZOYsPxSXAztiFKnfBzi8/r1rh4rySKrb8Oi67HLFy/IrTacf/hhXE8GDT1XNiktPGszhA==","signatures":[{"sig":"MEUCIEmtttR27odDn4j2nsBLXu0YiSsj6iVImamNoHo0c+5rAiEAm2Hl+/9vufe+1ImhElUogxRppGZLmZRC1H1hJoLV5qw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":9693371},"main":"build/index.js","type":"module","engines":{"node":">=18"},"gitHead":"ac26b8403b45fe2f900e7bcb784fc83d02f8ef32","mcpName":"io.github.CallMarcus/securityscorecard-mcp","scripts":{"test":"node --test tests/*.test.js","build":"tsc","start":"node build/index.js","dev:api":"npm run api:update && npm run build","test:ts":"node --test tests/*.test.ts","api:full":"npm run api:fetch && npm run api:update && npm run build","api:test":"npm run test","validate":"python validate_mcp_tools.py","api:embed":"node --loader ts-node/esm src/integration/api-reference-embeddings.ts","api:fetch":"bash tools/update_api_spec.sh","api:update":"npm run api:generate && npm run api:embed","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","api:generate":"python split_swagger.py","api:validate":"node examples/basic_usage.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","prepublishOnly":"npm run build:fast","test:validation":"npm run test"},"_npmUser":{"name":"callmarcus","email":"westermark@gmail.com"},"_npmVersion":"11.6.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","directories":{},"_nodeVersion":"20.19.4","dependencies":{"zod":"^4.3.6","dotenv":"^17.4.1","@huggingface/transformers":"^4.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.27.7","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/securityscorecard-mcp_1.1.0_1780834801205_0.6307245780648532","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@callmarcus/securityscorecard-mcp","version":"1.1.1","license":"MIT","_id":"@callmarcus/securityscorecard-mcp@1.1.1","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"homepage":"https://github.com/CallMarcus/security-scorecard-mcp#readme","bugs":{"url":"https://github.com/CallMarcus/security-scorecard-mcp/issues"},"bin":{"ssc-mcp":"build/index.js"},"dist":{"shasum":"044b606a9661ef4dbba77abea20a6729fd4eb3e7","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.1.1.tgz","fileCount":523,"integrity":"sha512-0MTX3jZ5RibUIUh/jv0EhJWb/afOPiCfyW6HIX4nI4WM+4ArxnWJXpRApw425bg+TboqWsGvXKukfEau8/GPVg==","signatures":[{"sig":"MEUCIQCKexYDX2wCzWkgY16u7A2FL+KSb7LmG4tp2gL1JakXzAIgKTsCjVNdszGAiZtI93drI4U4kdtOx2vwAVQrWESyAhI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@callmarcus%2fsecurityscorecard-mcp@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":9693512},"main":"build/index.js","type":"module","engines":{"node":">=18"},"gitHead":"07e3d22c068f733c8328f123f0d11ffa579552e5","mcpName":"io.github.CallMarcus/securityscorecard-mcp","scripts":{"test":"node --test tests/*.test.js","build":"tsc","start":"node build/index.js","dev:api":"npm run api:update && npm run build","test:ts":"node --test tests/*.test.ts","api:full":"npm run api:fetch && npm run api:update && npm run build","api:test":"npm run test","validate":"python validate_mcp_tools.py","api:embed":"node --loader ts-node/esm src/integration/api-reference-embeddings.ts","api:fetch":"bash tools/update_api_spec.sh","api:update":"npm run api:generate && npm run api:embed","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","api:generate":"python split_swagger.py","api:validate":"node examples/basic_usage.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","prepublishOnly":"npm run build:fast","test:validation":"npm run test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:53555775-da5e-4230-b2e9-3ceb3e4d88fa"}},"repository":{"url":"git+https://github.com/CallMarcus/security-scorecard-mcp.git","type":"git"},"_npmVersion":"11.16.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"zod":"^4.3.6","dotenv":"^17.4.1","@huggingface/transformers":"^4.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.27.7","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/securityscorecard-mcp_1.1.1_1780857232387_0.4188078312500152","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@callmarcus/securityscorecard-mcp","version":"1.2.0","description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","license":"MIT","mcpName":"io.github.CallMarcus/securityscorecard-mcp","repository":{"type":"git","url":"git+https://github.com/CallMarcus/security-scorecard-mcp.git"},"main":"build/index.js","type":"module","bin":{"ssc-mcp":"build/index.js"},"scripts":{"prepublishOnly":"npm run build:fast","build":"tsc","build:fast":"esbuild src/*.ts src/**/*.ts --outdir=build --format=esm --platform=node --target=es2020","start":"node build/index.js","test":"node --test tests/*.test.js","test:coverage":"node --test --experimental-test-coverage tests/*.test.js","test:ts":"node --test tests/*.test.ts","api:fetch":"bash tools/update_api_spec.sh","api:generate":"python split_swagger.py","api:embed":"tsc && node build/integration/api-reference-embeddings.js","api:test":"npm run test","api:validate":"node examples/basic_usage.js","api:update":"npm run api:generate && npm run api:embed","api:full":"npm run api:fetch && npm run api:update && npm run build","dev:api":"npm run api:update && npm run build","validate":"python validate_mcp_tools.py","validate:full":"powershell -ExecutionPolicy Bypass -File run_validation.ps1","test:validation":"npm run test"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","@huggingface/transformers":"^4.2.0","dotenv":"^17.4.1","zod":"^4.3.6"},"engines":{"node":">=20"},"overrides":{"adm-zip":"^0.6.0","sharp":"^0.35.0"},"devDependencies":{"@types/node":"^26.1.1","esbuild":"^0.28.0","typescript":"^7.0.2"},"gitHead":"90d53c0f2c709c0073dc5c3a90ef16a1da01dab2","_id":"@callmarcus/securityscorecard-mcp@1.2.0","bugs":{"url":"https://github.com/CallMarcus/security-scorecard-mcp/issues"},"homepage":"https://github.com/CallMarcus/security-scorecard-mcp#readme","_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-eL4TtB93Rv6Kz4LCg4G8IN8nPp1vENSSlhSu1zuPqvbUEHYCSu4+B062Ycb5kwkljWmGnirxNfebDP75FtqdiA==","shasum":"f58c97523e935c8fdd57b975785e2223b7d4c991","tarball":"https://registry.npmjs.org/@callmarcus/securityscorecard-mcp/-/securityscorecard-mcp-1.2.0.tgz","fileCount":534,"unpackedSize":9935835,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@callmarcus%2fsecurityscorecard-mcp@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIA2vEHDrOHInXjPteNXgX2LF0SqVEx/SYRkdJJVTPondAiAFqcNdYJ4K0/IfM7Ep5k7MiFPuUgviBa60yUCGURIqYA=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:53555775-da5e-4230-b2e9-3ceb3e4d88fa"}},"directories":{},"maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/securityscorecard-mcp_1.2.0_1786534462285_0.945640273328268"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-06T17:29:46.822Z","modified":"2026-08-12T11:34:22.822Z","1.0.1":"2026-06-06T17:29:47.292Z","1.0.2":"2026-06-06T17:37:40.099Z","1.0.3":"2026-06-06T17:58:41.464Z","1.1.0":"2026-06-07T12:20:01.473Z","1.1.1":"2026-06-07T18:33:52.577Z","1.2.0":"2026-08-12T11:34:22.510Z"},"bugs":{"url":"https://github.com/CallMarcus/security-scorecard-mcp/issues"},"license":"MIT","homepage":"https://github.com/CallMarcus/security-scorecard-mcp#readme","repository":{"type":"git","url":"git+https://github.com/CallMarcus/security-scorecard-mcp.git"},"description":"A community-built, comprehensive MCP server for the SecurityScorecard API. Not affiliated with SecurityScorecard, Inc.","maintainers":[{"name":"callmarcus","email":"westermark@gmail.com"}],"readme":"# SSC MCP Server\r\n\r\n[![npm version](https://img.shields.io/npm/v/@callmarcus/securityscorecard-mcp.svg)](https://www.npmjs.com/package/@callmarcus/securityscorecard-mcp)\r\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)\r\n\r\nA community-built, comprehensive Model Context Protocol (MCP) server that integrates with the [SecurityScorecard API](https://securityscorecard.readme.io/). It runs over stdio, so it works with any MCP-compatible client — Claude Desktop, Claude Code, Cursor, VS Code, and others.\r\n\r\n> Published on npm as [`@callmarcus/securityscorecard-mcp`](https://www.npmjs.com/package/@callmarcus/securityscorecard-mcp) and listed in the [MCP Registry](https://registry.modelcontextprotocol.io) as `io.github.CallMarcus/securityscorecard-mcp`.\r\n\r\n> **Disclaimer:** This is an independent, community-built open-source project. It is **not affiliated with, endorsed by, sponsored by, or associated with SecurityScorecard, Inc.** in any way. It is built solely against SecurityScorecard's publicly available API documentation. \"SecurityScorecard\" and all related names, marks, and logos are trademarks of SecurityScorecard, Inc. and are used here for identification purposes only. You must supply your own API credentials and comply with SecurityScorecard's terms of service.\r\n\r\n## Quick Start\r\n\r\n### Prerequisites\r\n\r\n1. **Node.js 20+** - [Download](https://nodejs.org/)\r\n2. **SecurityScorecard API Token** - Get from your [SecurityScorecard dashboard](https://platform.securityscorecard.io/)\r\n\r\n### Option A — Install from npm (recommended)\r\n\r\nNo clone or build required. The server runs over stdio via `npx`, so any MCP-compatible client can launch it. `npx -y` always fetches the latest published version.\r\n\r\n**Most clients** — Claude Desktop, Cursor, Cline, Windsurf, and others — share the same `mcpServers` JSON. Add this block to the client's MCP config:\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"security-scorecard\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"-y\", \"@callmarcus/securityscorecard-mcp\"],\r\n      \"env\": {\r\n        \"SECURITY_SCORECARD_API_TOKEN\": \"your-api-token-here\",\r\n        \"COMPANY_DOMAIN\": \"example.com\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nWhere that config file lives:\r\n\r\n| Client | Config file |\r\n|--------|-------------|\r\n| Claude Desktop (Windows) | `%APPDATA%\\Claude\\claude_desktop_config.json` |\r\n| Claude Desktop (macOS) | `~/Library/Application Support/Claude/claude_desktop_config.json` |\r\n| Cursor | `~/.cursor/mcp.json` (global) or `.cursor/mcp.json` (project) |\r\n\r\nReplace the credentials with your own, then restart the client.\r\n\r\n**Claude Code** — add it from the CLI instead:\r\n\r\n```bash\r\nclaude mcp add security-scorecard \\\r\n  --env SECURITY_SCORECARD_API_TOKEN=your-api-token-here \\\r\n  --env COMPANY_DOMAIN=example.com \\\r\n  -- npx -y @callmarcus/securityscorecard-mcp\r\n```\r\n\r\nOn Windows, wrap the launcher in `cmd /c`: `... -- cmd /c npx -y @callmarcus/securityscorecard-mcp`.\r\n\r\n**VS Code** (Copilot) — uses a `servers` key with an explicit `type`, in `.vscode/mcp.json`:\r\n\r\n```json\r\n{\r\n  \"servers\": {\r\n    \"security-scorecard\": {\r\n      \"type\": \"stdio\",\r\n      \"command\": \"npx\",\r\n      \"args\": [\"-y\", \"@callmarcus/securityscorecard-mcp\"],\r\n      \"env\": {\r\n        \"SECURITY_SCORECARD_API_TOKEN\": \"your-api-token-here\",\r\n        \"COMPANY_DOMAIN\": \"example.com\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### Option B — Run from source (for development)\r\n\r\n```bash\r\n# Clone the repository\r\ngit clone https://github.com/CallMarcus/security-scorecard-mcp.git\r\ncd security-scorecard-mcp\r\n\r\n# Install dependencies\r\nnpm install\r\n\r\n# Build (use build:fast to avoid memory issues)\r\nnpm run build:fast\r\n```\r\n\r\nThen point your MCP client at the local build. For clients that use the `mcpServers` format (Claude Desktop, Cursor, …):\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"security-scorecard\": {\r\n      \"command\": \"node\",\r\n      \"args\": [\"/path/to/security-scorecard-mcp/build/index.js\"],\r\n      \"env\": {\r\n        \"SECURITY_SCORECARD_API_TOKEN\": \"your-api-token-here\",\r\n        \"COMPANY_DOMAIN\": \"example.com\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n**Important:** Replace the path and credentials with your actual values, then restart your MCP client. (For Claude Code, run `claude mcp add security-scorecard --env SECURITY_SCORECARD_API_TOKEN=your-api-token-here -- node /path/to/security-scorecard-mcp/build/index.js`.)\r\n\r\n## Available Tools\r\n\r\nThe server (`index.js`) provides 9 specialized tools:\r\n\r\n| Tool | Purpose |\r\n|------|---------|\r\n| `security_dashboard` | Score, grade, and key security metrics |\r\n| `analyze_security_risks` | Issue prioritization and risk analysis |\r\n| `create_improvement_plan` | Actionable remediation roadmaps |\r\n| `discover_assets` | Asset inventory with security context |\r\n| `analyze_email_security` | SPF/DMARC/DKIM analysis |\r\n| `api_discovery` | Search 517 API endpoints with hybrid semantic/keyword search |\r\n| `analyze_issue_types` | Granular issue type breakdowns |\r\n| `validate_data_completeness` | Cross-tool data verification |\r\n| `query_security_data` | Direct API access with discovery |\r\n\r\n### Response Modes\r\n\r\nEach tool supports three response modes for token efficiency:\r\n- **minimal** - Quick answers (15-50 tokens)\r\n- **standard** - Overview with context (200-300 tokens)\r\n- **detailed** - Comprehensive analysis (800+ tokens)\r\n\r\n## Environment Variables\r\n\r\n| Variable | Required | Description |\r\n|----------|----------|-------------|\r\n| `SECURITY_SCORECARD_API_TOKEN` | Yes | Your API token |\r\n| `COMPANY_DOMAIN` | No | Default domain for queries |\r\n| `DEBUG_MODE` | No | Set `true` for verbose logging |\r\n\r\nOptional rate limiting and caching:\r\n\r\n```\r\nREQUEST_CACHE_TTL_MS=300000\r\nREQUESTS_PER_INTERVAL=5\r\nREQUEST_INTERVAL_MS=1000\r\n```\r\n\r\n## API Discovery\r\n\r\nThe server includes hybrid search (semantic + keyword) for finding SecurityScorecard API endpoints:\r\n\r\n```\r\nUse api_discovery to search for \"email security\"\r\n```\r\n\r\nThis searches 517 indexed endpoints and returns matching paths with confidence scores, required parameters, and curl examples.\r\n\r\nTo update the API reference after changes:\r\n\r\n```bash\r\nnpm run api:embed    # Regenerate semantic embeddings\r\nnpm run api:update   # Regenerate docs + embeddings\r\n```\r\n\r\n## Development\r\n\r\n### Build Commands\r\n\r\n```bash\r\nnpm run build:fast   # Recommended - uses esbuild (~130ms)\r\nnpm run build        # TypeScript compiler (may OOM on some systems)\r\nnpm test             # Run tests\r\n```\r\n\r\n### Project Structure\r\n\r\n```\r\nsrc/\r\n  index.ts               # MCP server (9 tools)\r\n  api/client.ts          # SecurityScorecard API client\r\n  integration/           # API discovery system\r\ndocs/api/                # Self-contained API reference\r\n  index.jsonl            # Endpoint index (517 endpoints)\r\n  index-embeddings.json  # Semantic search embeddings\r\nbuild/                   # Compiled JavaScript\r\n```\r\n\r\n### Testing\r\n\r\n```bash\r\nnpm test             # Run test suite\r\n```\r\n\r\n## Troubleshooting\r\n\r\n### Build fails with out of memory\r\n\r\nUse the fast build instead:\r\n```bash\r\nnpm run build:fast\r\n```\r\n\r\n### \"Cannot find module\" errors\r\n\r\nReinstall dependencies:\r\n```bash\r\nrm -rf node_modules\r\nnpm install\r\nnpm run build:fast\r\n```\r\n\r\n### Semantic search degrades to keyword-only (Windows + WSL)\r\n\r\nInstall for the platform that runs the server. Claude Desktop on Windows\r\nlaunches the server with Windows `node`, so if `npm install` ran under WSL\r\nthe native modules (`onnxruntime-node`, `sharp`) only have linux binaries —\r\nthe embeddings layer fails to load and `api_discovery` silently degrades to\r\nkeyword-only search (results still come back, but confidence scoring is\r\ncruder). Run `npm install && npm run build:fast` from PowerShell or cmd in\r\nthe repo directory instead — or keep two clones, one per platform.\r\n\r\n### Your client doesn't see the server\r\n\r\n1. Double-check the config file location for your client (see [Quick Start](#quick-start))\r\n2. For a from-source install, verify the path to `build/index.js` is correct\r\n3. Restart the client completely\r\n4. Sanity-check that the server starts on its own: `npx -y @callmarcus/securityscorecard-mcp` (it should launch and wait silently on stdio)\r\n\r\n### API returns 401 Unauthorized\r\n\r\nYour API token is invalid or expired. Get a new one from SecurityScorecard dashboard.\r\n\r\n## License\r\n\r\nMIT\r\n\r\n## Links\r\n\r\n- [SecurityScorecard API Docs](https://securityscorecard.readme.io/)\r\n- [Model Context Protocol](https://modelcontextprotocol.io/)\r\n- [Report Issues](https://github.com/CallMarcus/security-scorecard-mcp/issues)\r\n","readmeFilename":"README.md"}