
MCP Server for OSCAL
io.github.dfkunstlerv0.5.0Updated Sep 30, 2026
AI agent tools for Open Security Controls Assessment Language (OSCAL)
Installation
In SourceWeft
- Open MCP Server for OSCAL in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
MCP Server for OSCAL
Instant OSCAL expertise for your favorite AI agentA Model Context Protocol (MCP) server that provides AI assistants (Claude, Cline, Kiro, Claude Code, etc.) with tools to work with NIST's Open Security Controls Assessment Language (OSCAL). Like many early adopters, we needed help implementing OSCAL proofs-of-concept to demonstrate value to business stakeholders. Perhaps due to limited availability of examples in the public domain, we found that most AI agents/LLMs alone produced inconsistent results related to OSCAL. The tools in this MCP server minimized that problem for our use-case and we hope it does the same for you.
[!TIP] To get started, see Installation below.
Features
Together, the tools provided by this MCP server are meant to enable your preferred AI assistant to provide accurate, authoritative guidance about OSCAL architecture, models, use-cases, requirements, and implementation. You don't need to understand the tools to use them, but details are in the tools directory.
The server is lightweight and meant to run locally without additional setup. By default, it uses stdio protocol for MCP transport. Do not attempt to use the server with streamable-http transport, as we've not yet implemented transport security or authentication.
The default tools should not connect to any remote services or resources - all required content is bundled with the server. As a security measure, we've implemented basic file integrity verification for bundled content. At build-time we generate manifests including SHA-256 hashes of all content files. Each time the server starts, all content files are verified against the hash manifests. Any mismatch should produce an error and prevent startup.
In addition to the MCP server, the package includes a standalone OSCAL agent built with Strands Agents. See the OSCAL Agent section below.
What is OSCAL?
OSCAL (Open Security Controls Assessment Language) is a set of framework-agnostic, vendor-neutral, machine-readable schemas developed by NIST that describe the full life cycle of GRC (governance, risk, compliance) artifacts, from controls to remediation plans. OSCAL enables automation of GRC workflows by replacing digital paper (spreadsheets, PDFs, etc.) with a standard-based structured data format. To learn more about OSCAL, install this MCP server then ask your AI. Or see the official OSCAL website.
What is MCP?
MCP (Model Context Protocol) is an open-source standard for connecting AI applications to external systems. Think of MCP like a USB-C port for AI applications. Just as USB-C provides a standardized way to connect electronic devices, MCP provides a standardized way to connect AI applications to external systems.
How to use / examples
Examples below were created with kiro-cli, but should work with any AI assistant that supports MCP servers.
Example 1: Learn about available OSCAL models
Example 2: OSCAL template generation
Example 3: Discover open source OSCAL catalogs
Example 4: Query component definitions for information about AWS services
Installation
Follow these instructions to setup the MCP server for use with your preferred IDE, AI agent, chatbot, etc. The server is published as Python package on PyPI. The uvx command (shown below) automatically downloads the latest version of the server from PyPI on startup.
[!NOTE] To setup for development instead, see DEVELOPING.md
Prerequisites
uvpackage manager for Python (Installation instructions)- Python 3.11 or higher (
uv install python 3.12). The server may work with later versions of Python, but we only test 3.11 & 3.12 for now.
Configuring IDEs and AI Tools
This server communicates via stdio (standard input/output) and can be integrated with various IDEs and agentic tools that support the Model Context Protocol. The configuration examples shown below are for your preferred IDE / chatbot / agent.
Configuration Format
Most MCP-compatible tools use a JSON configuration format described in the FastMCP documentation. Here's the basic structure:
For typical, runtime use of the MCP server, additional configuration should not be required. If needed, runtime environment variables can be configured in an "env": {} object as described in the FastMCP documentation. See the file dotenv.example for available options.
[!Note] A dotenv file is only needed in a development environment.
Kiro Configuration
See Kiro's MCP documentation for additional options. Add to your .kiro/settings/mcp.json:
Claude Desktop
Add to your ~/.claude/claude_desktop_config.json:
VS Code
Run the MCP: Open User Configuration command, which opens the mcp.json file in your user profile. You can then manually add the server configuration to the file. See the VSCode/Copilot docs for additional options and details.
Using your own OSCAL Content
By default, the server ships with bundled OSCAL content (AWS component definitions, OSCAL documentation, and schemas). You can also point the server at a directory of your own OSCAL JSON files — catalogs, SSPs, profiles, assessment plans, assessment results, POA&Ms, or mapping collections. The server indexes them at startup and makes them available through all query and list tools.
Set the OSCAL_DOCUMENTS_DIR environment variable to the path of your OSCAL content directory. The path can be absolute or relative to the server's package directory. For example, in your MCP configuration:
The server scans the directory recursively for .json files and indexes any valid OSCAL documents it finds. Your content is merged with the bundled content — both are queryable in the same session.
Two additional environment variables control the OSCAL store behavior:
[!TIP] Setting
OSCAL_STORE_DB_PATHis recommended if you have a large collection of OSCAL documents. The server only needs to index new or changed files on subsequent startups.
OSCAL Agent
In addition to the MCP server, the package includes a standalone OSCAL agent built with Strands Agents. The agent uses the same tools as the MCP server and can be run directly:
The agent requires AWS Bedrock access and uses the same configuration environment variables as the MCP server.
Session Persistence
The agent supports session persistence so that conversation history and agent state survive across invocations. Choose between local filesystem or Amazon S3 storage:
When session storage is enabled without a --session-id, a UUID is auto-generated and displayed so you can resume later. Session defaults can also be set via environment variables (see DEVELOPING.md).
Conversation Management
For long-running workflows, you can select a conversation manager to control how the agent's context window is maintained:
Existing tools and features cover a variety of use-cases but are far from comprehensive. Please share your feedback, feature requests, questions, or bug reports in a GitHub issue. Direct contributions are wanted and welcome.
Development
See DEVELOPING to get started.
Security
See CONTRIBUTING for more information.
Known limitations
- It's not yet possible to use this MCP server with ChatGPT due to limited MCP support by ChatGPT.
- The
streamable-httptransport does not yet implement authentication or transport security. Usestdiofor production workloads.
Related projects
Experimental Component Definitions for AWS services are bundled with this MCP server. You can find that content in the AWS Labs project OSCAL Content for AWS Services.
MCP Server for OSCAL uses compliance-trestle for certain capabilities, including OSCAL content validation.
License
This project is licensed under the Apache-2.0 License.
Source: README.md at commit 5716b65
Tools
0Version history
1- v0.5.0LatestSep 30, 2026

