AI agent tools for Open Security Controls Assessment Language (OSCAL). Provides tools to support evaluation and implementation of NIST's OSCAL for security governance, risk, and compliance (GRC) automation.
The OSCAL MCP server provides 40 tools with basic descriptions and parameter documentation. Most tools follow verb_noun naming conventions (list_*, query_*, get_*) and have descriptions. The 40-tool structure suggests domain completeness, but definition quality is mediocre for production use.
Get metadata about the server itself
Get details of a specific capability
Get details of a specific child element from an OSCAL document
Get OSCAL schema in JSON or XSD format for a specified model type
List activities within an assessment plan
List tasks within an assessment plan
List available assessment plan documents
List available assessment results documents
Input schemas not verifiable in source code. Only parameter descriptions visible in tool metadata; no JSON Schema definitions found.
Output schemas not documented. No response field definitions visible for any tool. LLMs cannot infer what data structure each tool returns or what fields are available for downstream tool chaining.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 38 | - | v1 |
List findings within an assessment results document
List results within an assessment results document
List capabilities for a component
List controls within a catalog
List control groups within a catalog
List available catalog documents
List available component definition documents
List components within a component definition
List mappings within a mapping collection
List available mapping collection documents
List available OSCAL model types
List OSCAL resources available in the knowledge base
List items within a Plan of Action and Milestones document
List available Plan of Action and Milestones documents
List imports within a profile
List modifications within a profile
List available profile documents
List control implementations within an SSP
List system components within an SSP
List available System Security Plan documents
Query assessment plan documents
Query assessment results documents
Query catalog documents
Query component definition documents
Query mapping collection documents
Query OSCAL documentation and learn materials
Query Plan of Action and Milestones documents
Query profile documents
Query System Security Plan documents
Full-text search across all OSCAL documents
Validate OSCAL content provided as a string
Validate an OSCAL file by path or URI
Descriptions too brief and lack context. Most descriptions are under 80 characters and do not explain WHEN/WHY to use the tool vs similar ones (e.g., list_catalogs vs query_catalog both search catalogs; distinction unclear). No guidance on dependencies or prerequisite calls.
No error handling or recovery guidance documented. Tools lack specification of what errors can occur, whether they are retryable, and what the LLM should do next. No examples of failure modes or mitigation.
Naming ambiguity: multiple tools with overlapping scope (query_* vs list_*). Both query_catalog and list_catalogs appear to operate on the same resource but with unclear distinction. LLMs will struggle to choose correctly.
No pagination documented. 'list_*' and 'query_*' tools do not specify limits, offsets, or total counts. No guidance on how to handle large result sets or prevent context window exhaustion.
Tool composition unclear. Response fields for tools like list_catalogs are not documented, so it is impossible to verify whether get_catalog_controls receives the correct UUID format or field name to chain properly.
Tool 'list_assessment_results_results' has ambiguous naming (results_results). Violates clarity rule, the noun is repeated, making it unclear what the tool returns vs its parent container.