[DEPRECATED] MCP server for exploring the FedRAMP docs repository. Consolidated into GRC Clanker and myctrl.tools — see README.
The server has 21 tools with reasonable naming conventions (all start with verbs), and most have descriptions. However, there are significant gaps in schema completeness, parameter descriptions, and output documentation. Input schemas are visible in code (e.g., search_tools.ts uses Zod), but many tools lack explicit output schema documentation. Parameter descriptions vary in quality, some are thorough, others are minimal. The tool catalog static entries lack detailed descriptions for several tools (e.g., list_frmr_documents, get_frmr_document have only 1-2 sentences). Error handling is minimal, no recovery guidance, no categorization of error types. The server is READ_ONLY dominant (20/21 tools), which reduces risk but also limits the need for robust error handling patterns.
Analyze which NIST 800-53 control families have FedRAMP requirements. Returns a coverage report showing control families, number of controls and mappings per family, and which FRMR sources contribute. Useful for gap analysis and compliance dashboards. [Category: Controls]
Compute a structured diff between two FRMR documents by identifier. Compares versions side-by-side showing added, removed, and modified items with field-level change details. Use list_versions to discover available versions for comparison. [Category: Analysis]
Filter Key Security Indicators (KSI) by FIPS 199 impact level. Returns all KSI items that apply to the specified impact level (low, moderate, or high). Useful for scoping compliance requirements to your system's authorization level. [Category: KSI]
Get all FedRAMP requirements mapped to a specific NIST 800-53 control. Returns KSI items and FRMR requirements that reference the control, with source details and theme categorization. Useful for understanding what FedRAMP expects for a given control. [Category: Controls]
Get suggested evidence examples for KSI compliance with automation sources.
Output schemas not documented for any tool. Tool execution returns data, but LLMs cannot infer what fields to expect without explicit output schema documentation. E.g., search_tools returns {total, results: ToolSearchResult[]}, but ToolSearchResult structure is not visible in tool definitions.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 48 | 1.25.1+ | v1 |
Retrieve a FRMR document with metadata, raw JSON, and summary.
Retrieve a single KSI entry by its ID with full details.
Get any FedRAMP requirement by its ID across all document types.
Aggregate guidance related to FedRAMP Significant Change requirements.
Get comprehensive guidance for a KSI theme with indicators, impact breakdown, and related controls.
Search markdown files for NIST control identifier occurrences.
Verify index status and report server health.
Return flattened NIST control mappings across all FRMR sets.
List available FRMR documents and metadata. Starting point for exploring FedRAMP datasets.
List and filter Key Security Indicators with text search, category, and status filters.
List detected FRMR versions and metadata for comparison.
Read a FedRAMP markdown file and return its full contents.
Search FedRAMP definitions (FRD) by term with alternate terms.
Full-text search across FedRAMP markdown documentation and guidance.
Search and discover available FedRAMP MCP tools by keyword or category. Use this to find the right tool for your task. Returns tool names, descriptions, categories, and parameters. Supports browsing all tools (empty query) or searching by keyword. Categories: Discovery, KSI, Controls, Search, Analysis, System. [Category: System]
Force update the cached FedRAMP docs repository from GitHub.
Minimal descriptions for discovery and utility tools. list_frmr_documents ('List available FRMR documents and metadata. Starting point for exploring FedRAMP datasets.'), list_versions ('List detected FRMR versions and metadata for comparison.'), health_check ('Verify index status and report server health.'), and update_repository ('Force update the cached FedRAMP docs repository from GitHub.') are under 150 chars and lack LLM-optimized guidance on when/why to call them.
No input schemas visible in source code for most tools. Tool definitions in tool_catalog.ts are static metadata entries (ToolCatalogEntry) with only names, descriptions, keywords, and parameter names, they do NOT include Zod schemas, JSON Schema, or type definitions. Only search_tools has an explicit Zod schema (src/tools/search_tools.ts). The remaining 20 tools cannot be validated by LLMs or clients without access to their actual registration code, which is not shown.
No error handling or recovery guidance documented. Tools have no documented error responses, error categories (retryable vs fatal), or recovery steps. E.g., if get_frmr_document fails because the path does not exist, what error does it return? Can the agent retry? Should it call list_frmr_documents first? No guidance.
update_repository is a destructive/state-changing tool but lacks warnings and confirmation semantics. Description ('Force update the cached FedRAMP docs repository from GitHub.') does not convey that this is irreversible and may interrupt concurrent reads. No dry-run mode documented.
Parameter descriptions are sparse for many tools. E.g., list_controls has 'Control family (e.g., AC, SC, IA)' for family but does not state if this is required, if partial matches are allowed, or what happens if omitted. get_frmr_document has 'FRMR document type' without explaining valid types. Enum constraints are not visible in parameter definitions.
No pagination guidance for list tools. list_ksi, list_controls, search_markdown, and search_definitions accept limit and offset parameters, but descriptions do not specify default limits, max results, or best practices. An LLM may request 10000 items, causing performance issues.
Package.json marks the server as DEPRECATED. 'This package is no longer maintained. Functionality has been folded into GRC Clanker (https://github.com/hackIDLE/grclanker) and myctrl.tools.' This signals end-of-life and reduces confidence in long-term use, though the code may still function.