MCP server for the SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
The server demonstrates good overall quality with well-structured tool definitions, comprehensive parameter schemas, and consistent naming conventions. All 17 tools have explicit descriptions and input schemas. However, several tools lack descriptions for key parameters, and output schemas are not documented in the source code provided. Tool composition is strong, with clear chaining support (UUIDs returned enable subsequent calls). Error handling and security patterns are present but could be more explicit in descriptions.
Apply a previewed reconciliation run (write — admin role). Asynchronous. The run must be 'previewed' and expected_to_version must match, so a stale preview is refused rather than applied.
Cancel a reconciliation run that has not been applied (write — admin role). The organization stays on its current catalog version.
Create a system in the organization's infrastructure inventory (write — editor+ role). Systems can be linked to capabilities and evidence.
Get a single capability theme (KSI) with full posture, multi-axis scores, band, and legacy posture_percentage.
Get the multi-axis KSI scorecard for every capability theme. Returns per-theme Implementation Coverage, Maturity, Evidence Coverage, Evidence Quality, and composite KSI Posture Score bands.
Output schemas not documented in source code. Tool definitions include input schemas but no documented return types or response field structures. LLMs cannot infer what fields to expect from responses, limiting composition and causing agents to guess at available data.
Pagination parameters (limit, offset, scope_status) lack constraint documentation in descriptions. While JSON Schema includes minimum/maximum for numeric types, the descriptions do not spell out ranges (1 - 200, 1 - 500) or explain pagination semantics in plain language for LLM consumption.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 75 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Get this organization's catalog changelog (read — viewer role): what changed across reconciliations, newest first. Answers 'when did this control change, and what did we decide?'
Get this organization's catalog position (read — viewer role): its catalog version, the platform's current version, and whether reconciliation is due or in flight. Start here.
Get one reconciliation run in detail (read — viewer role): the computed diff, every deprecated entity needing a decision, and the planned action currently recorded against each.
List an organization's capabilities. Capabilities map to systems and evidence, showing what security functions the infrastructure supports.
List SCF controls mapped to a capability theme (KSI), with scoping status, implementation status, and maturity level. Supports pagination and scope filtering — ideal for KSI drill-down.
List an organization's 11 KSI capability themes. Themes group NIST 800-53 controls into security capability areas for a high-level posture view.
List this organization's catalog reconciliation runs, newest first (read — viewer role), with each run's status and target version.
List the organization's infrastructure systems — the tools and platforms that implement security capabilities. Optionally filter by linked vendor.
Create a reconciliation preview run (write — admin role): what moving to the target catalog version would do to scoped controls, evidence and mappings. Changes nothing until apply.
Roll an applied reconciliation run back (destructive write — admin role). Asynchronous, and requires the typed confirmation string the run detail states.
Record decisions for a reconciliation run (write — admin role). REPLACES the run's planned actions, so send the complete list. Each deprecated entity gets migrate, retain or retire_only.
Update an existing system record (write — editor+ role). All fields are optional; only provided fields are applied.
Error handling and recovery guidance absent from tool descriptions. Descriptions do not state what errors might occur, what values are invalid, or what the agent should do if a call fails. E.g., scf_apply_catalog_reconciliation requires 'expected_to_version' to match but does not explain the error if it doesn't or what to do.
scf_set_reconciliation_actions parameter 'actions' is documented as 'The complete set of planned actions for this run' but lacks a detailed schema description of the nested object structure. The object properties (key, entity, action, justification, successor_scf_id) are visible in JSON but not explained in text form, an LLM reading the parameter description alone cannot understand the structure.
Destructive/high-risk operations (scf_apply_catalog_reconciliation, scf_rollback_catalog_reconciliation) are not marked with explicit risk annotations in tool definitions. While risk is noted in the specifications above, the actual MCP tool schemas do not appear to include readOnlyHint/destructiveHint annotations per the current spec.
Confirmation/dry-run patterns missing for destructive operations. scf_apply_catalog_reconciliation and scf_rollback_catalog_reconciliation require confirmation text, but there is no dry-run or preview step to let the agent validate the action before committing, increasing risk of accidental data loss.