An MCP server for querying FedRAMP compliance controls and security baselines
The server provides 6 well-named compliance tools with reasonable verb-noun naming conventions (list_, get_, search_). All tools have brief descriptions (13-62 chars) and input schemas with parameter types and enums. However, descriptions are minimal and lack LLM-optimized guidance on WHEN to call each tool and WHAT the relationships are between them. Parameters are described but descriptions are terse (e.g., 'The FedRAMP program'). Output schemas are not documented, we cannot verify what fields the LLM will receive back. No error handling guidance is visible. The compliance domain is moderately well-covered with 6 complementary tools, but the implementation lacks the polish expected of production-grade agent tools.
Get detailed information about a specific control
Get detailed guidance for evidence about a specific control
Get all controls in a family (e.g., AC for Access Control)
List all available compliance programs
List all control families in a program
Search for controls by keyword
Descriptions lack LLM-optimized context: no explicit guidance on WHEN to call each tool or how they relate. For example, 'Get detailed information about a specific control' doesn't explain whether to call this after search_controls or as part of initial discovery.
Output schemas are not documented in the source code. We cannot verify what fields the LLM will receive, whether pagination is supported, or what IDs/references are included for chaining downstream calls.
Parameter descriptions are minimal and generic. E.g., 'The FedRAMP program (High or Moderate)' and 'The search query' lack context on format, valid examples, or constraints beyond the enum/type.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 45 | - | v1 |
No error handling documentation visible. If a control ID is invalid or a search returns no results, the LLM has no guidance on what to do next (retry, refine query, ask user).
Tool relationships and discovery flow not documented. For example, the natural workflow (list_compliance_programs → list_control_families → get_control_family → get_control → get_control_evidence_guidance) should be made explicit in descriptions.