Back to Home
ethanolivertroy icon

fedramp-docs-mcp

Verified Safe

by ethanolivertroy

Overview

A Model Context Protocol (MCP) server for querying FedRAMP compliance documentation and NIST controls, designed to be used by AI agents and developers.

Installation

Run Command
npx fedramp-docs-mcp

Security Notes

The server uses 'simple-git' to clone and update the official 'FedRAMP/docs' GitHub repository. While 'simple-git' is a well-established library for Git operations, any execution of external commands ('git') inherently introduces a potential attack surface. However, the repository source and branch are configurable via environment variables, not directly by user input to tools, which mitigates command injection risks. The Docker setup provides strong security hardening (e.g., non-root user, read-only filesystem, dropped capabilities, no-new-privileges, network isolation) which significantly enhances security in containerized deployments. No direct 'eval' or intentional obfuscation is observed.

Similar Servers

Stats

Interest Score41
Security Score8
Cost ClassLow
Avg Tokens1000
Stars15
Forks3
Last Update2026-01-14

Tags

FedRAMPComplianceNISTSecurityDocumentation