gitlab-mcp
A Model Context Protocol (MCP) server for GitLab
Crawler Summary
Model Context Protocol server for exploring the FedRAMP docs repository. FedRAMP Docs MCP Server $1 **Disclaimer:** This is an unofficial, community project and is not affiliated with, endorsed by, or associated with FedRAMP or the U.S. federal government. The author is not officially affiliated with FedRAMP. The FedRAMP name and any related marks are property of their respective owners. Custom Model Context Protocol (MCP) server that makes the FedRAMP/docs repository queryable with FRMR- Capability contract not published. No trust telemetry is available yet. 16 GitHub stars reported by the source. Last updated 2/25/2026.
Freshness
Last checked 2/25/2026
Best For
fedramp-docs-mcp is best for mcp, model-context-protocol, fedramp workflows where MCP compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB MCP, runtime-metrics, public facts pack
Model Context Protocol server for exploring the FedRAMP docs repository. FedRAMP Docs MCP Server $1 **Disclaimer:** This is an unofficial, community project and is not affiliated with, endorsed by, or associated with FedRAMP or the U.S. federal government. The author is not officially affiliated with FedRAMP. The FedRAMP name and any related marks are property of their respective owners. Custom Model Context Protocol (MCP) server that makes the FedRAMP/docs repository queryable with FRMR-
Public facts
5
Change events
1
Artifacts
0
Freshness
Feb 25, 2026
Capability contract not published. No trust telemetry is available yet. 16 GitHub stars reported by the source. Last updated 2/25/2026.
Trust score
Unknown
Compatibility
MCP
Freshness
Feb 25, 2026
Vendor
Ethanolivertroy
Artifacts
0
Benchmarks
0
Last release
0.2.5
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. 16 GitHub stars reported by the source. Last updated 2/25/2026.
Setup snapshot
git clone https://github.com/ethanolivertroy/fedramp-docs-mcp.gitSetup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Ethanolivertroy
Protocol compatibility
MCP
Adoption signal
16 GitHub stars
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
bash
npm install
bash
npm run build
bash
node dist/index.js
bash
npm install -g . fedramp-docs-mcp
bash
# Show help and usage information npx fedramp-docs-mcp help # Install Claude Code plugin npx fedramp-docs-mcp setup # Print MCP server configuration for Claude Desktop/Code npx fedramp-docs-mcp mcp-config # Start MCP server (used by MCP clients) npx fedramp-docs-mcp
json
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "false"
}
}
}
}Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB MCP
Editorial quality
ready
Model Context Protocol server for exploring the FedRAMP docs repository. FedRAMP Docs MCP Server $1 **Disclaimer:** This is an unofficial, community project and is not affiliated with, endorsed by, or associated with FedRAMP or the U.S. federal government. The author is not officially affiliated with FedRAMP. The FedRAMP name and any related marks are property of their respective owners. Custom Model Context Protocol (MCP) server that makes the FedRAMP/docs repository queryable with FRMR-
Disclaimer: This is an unofficial, community project and is not affiliated with, endorsed by, or associated with FedRAMP or the U.S. federal government. The author is not officially affiliated with FedRAMP. The FedRAMP name and any related marks are property of their respective owners.
Custom Model Context Protocol (MCP) server that makes the FedRAMP/docs repository queryable with FRMR-aware tooling. The server scans FRMR JSON datasets and supporting markdown guidance, exposes structured tools for analysis, and can optionally clone and cache the upstream repository for you.
See the FedRAMP Docs MCP Server in action with Claude Desktop:
https://github.com/user-attachments/assets/653c3956-0bfb-46c4-9e72-8a6d75e3a80d
| Resource | Description | |----------|-------------| | Quick Start Guide | Get running in under 5 minutes | | Full Documentation | Complete guides and reference | | MCP Client Setup | Configure Claude Desktop, Cursor, VS Code | | Tools Reference | All 21 MCP tools with parameters | | Troubleshooting | Common issues and solutions |
Additional resources:
tools/site/content/ (Zensical static site content).| Type | Full Name | |------|-----------| | KSI | Key Security Indicators | | MAS | Minimum Assessment Scope | | VDR | Vulnerability Detection and Response | | SCN | Significant Change Notifications | | FRD | FedRAMP Definitions | | ADS | Authorization Data Sharing | | CCM | Collaborative Continuous Monitoring | | FSI | FedRAMP Security Inbox | | ICP | Incident Communications Procedures | | PVA | Persistent Validation and Assessment | | SCG | Secure Configuration Guide | | UCM | Using Cryptographic Modules |
npm install
npm run build
node dist/index.js
To install globally and use the fedramp-docs-mcp command:
npm install -g .
fedramp-docs-mcp
Note: Global installation is required if you want to use fedramp-docs-mcp as the command in MCP client configurations (Claude Desktop, Goose, etc.). Alternatively, you can use the full path to the built server: node /path/to/fedramp-docs-mcp/dist/index.js
The package includes helpful CLI commands:
# Show help and usage information
npx fedramp-docs-mcp help
# Install Claude Code plugin
npx fedramp-docs-mcp setup
# Print MCP server configuration for Claude Desktop/Code
npx fedramp-docs-mcp mcp-config
# Start MCP server (used by MCP clients)
npx fedramp-docs-mcp
During startup the server ensures a FedRAMP/docs repository is available, indexes FRMR JSON and markdown content, then begins serving requests on MCP stdio.
Environment variables control repository discovery and indexing behaviour:
| Variable | Default | Description |
| --- | --- | --- |
| FEDRAMP_DOCS_PATH | ~/.cache/fedramp-docs | Path to an existing FedRAMP/docs checkout. |
| FEDRAMP_DOCS_REMOTE | https://github.com/FedRAMP/docs | Remote used when cloning. |
| FEDRAMP_DOCS_BRANCH | main | Branch to checkout when cloning. |
| FEDRAMP_DOCS_ALLOW_AUTO_CLONE | true | Clone automatically when the path is missing. |
| FEDRAMP_DOCS_AUTO_UPDATE | true | Automatically check for and fetch repository updates. |
| FEDRAMP_DOCS_UPDATE_CHECK_HOURS | 24 | Hours between automatic update checks (when auto-update is enabled). |
| FEDRAMP_DOCS_INDEX_PERSIST | true | Persist the in-memory index under ~/.cache/fedramp-docs/index-v1.json. |
Set FEDRAMP_DOCS_PATH if you maintain a local clone. Otherwise leave it unset and allow the server to create a shallow cached copy.
The server includes automatic update checking to keep the FedRAMP docs current:
Automatic Updates (Default Behavior):
Manual Updates:
update_repository tool to force an immediate updateDisabling Auto-Update:
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "false"
}
}
}
}
Custom Update Frequency (check every 6 hours):
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"env": {
"FEDRAMP_DOCS_UPDATE_CHECK_HOURS": "6"
}
}
}
}
The server provides 21 tools organized into categories. All tools follow the error model and respond with JSON payloads.
| Tool | Description |
|------|-------------|
| list_frmr_documents | Enumerate indexed FRMR JSON documents |
| get_frmr_document | Return full JSON and summary for a document |
| list_versions | Collate version metadata by FRMR document type |
| Tool | Description |
|------|-------------|
| list_ksi | Filter and inspect Key Security Indicators |
| get_ksi | Get a specific KSI item by ID |
| filter_by_impact | Filter KSI items by impact level (low/moderate/high) |
| get_theme_summary | Get comprehensive guidance for a KSI theme (IAM, CNA, etc.) |
| get_evidence_examples | Get automation-friendly evidence suggestions for KSI compliance (community suggestions, not official FedRAMP) |
| Tool | Description |
|------|-------------|
| list_controls | Flatten FRMR → control mappings |
| get_control_requirements | Get all requirements mapped to a specific control |
| analyze_control_coverage | Report which control families have FedRAMP requirements |
| Tool | Description |
|------|-------------|
| search_markdown | Full-text search across documentation |
| read_markdown | Read specific markdown file contents |
| search_definitions | Search FedRAMP definitions (FRD) by term |
| get_requirement_by_id | Get any FRMR requirement by ID (KSI-, FRR-, FRD-*) |
| Tool | Description |
|------|-------------|
| diff_frmr | Structured diff of two FRMR datasets |
| grep_controls_in_markdown | Locate control references in markdown |
| get_significant_change_guidance | Curated Significant Change references |
| Tool | Description |
|------|-------------|
| search_tools | Search and discover available tools by keyword or category |
| health_check | Confirm the server indexed successfully |
| update_repository | Force update the cached FedRAMP docs |
The get_evidence_examples tool provides community-suggested evidence examples for each KSI. These are automation-friendly suggestions showing how to programmatically collect compliance evidence via APIs, CLI commands, and security tools.
Important: These are NOT official FedRAMP guidance. Always verify requirements with official FedRAMP documentation.
For each of the 72 KSI indicators, we provide:
| Theme | Example Sources | |-------|----------------| | IAM | Okta/Entra MFA policies, AWS IAM credential reports, PAM tools (CyberArk, Vault) | | CNA | AWS Security Groups, VPC Flow Logs, Container scans (Trivy), CSPM (Wiz, Prisma) | | MLA | SIEM config (Splunk, Sentinel), CloudTrail, IaC scans (Checkov, tfsec) | | CMT | Git history, CI/CD pipelines (GitHub Actions), Change tickets (ServiceNow, Jira) | | SVC | TLS scans (SSL Labs), Secrets Manager rotation, Patch compliance (SSM) | | INR | PagerDuty incidents, Post-mortems (Blameless), ServiceNow tickets | | RPL | AWS Backup reports, DR test logs, Chaos engineering results | | TPR | Vendor ratings (SecurityScorecard), Dependency scans (Dependabot, Snyk) |
"What evidence do I need for KSI-IAM-01 (Phishing-Resistant MFA)?"
→ Returns suggested API calls, CLI commands, and artifacts to collect
"Get evidence checklist for the CNA theme"
→ Returns automation sources for all Cloud Native Architecture indicators
See src/tools/ for the precise schemas implemented with Zod. Each tool returns either a successful object or an error payload containing code, message, and optional hint.
When using the MCP server with Claude Desktop or other MCP clients, here are some example queries:
Getting KSI Information:
"List all available FedRAMP documents"
→ Uses list_frmr_documents
"Show me all KSI items for moderate impact systems"
→ Uses filter_by_impact with impact='moderate'
"Give me a summary of the IAM theme requirements"
→ Uses get_theme_summary with theme='IAM'
"What evidence do I need for IAM compliance?"
→ Uses get_evidence_examples with theme='IAM'
Searching Documentation:
"Search for information about continuous monitoring"
→ Uses search_markdown with query 'continuous monitoring'
"What does 'federal customer data' mean in FedRAMP?"
→ Uses search_definitions with term='federal customer data'
"Get the details for requirement KSI-IAM-01"
→ Uses get_requirement_by_id with id='KSI-IAM-01'
Working with Controls:
"What FedRAMP requirements map to control AY-01?"
→ Uses get_control_requirements with control='AY-01'
"Which control families have the most FedRAMP coverage?"
→ Uses analyze_control_coverage
"Find all markdown files that reference AC-2"
→ Uses grep_controls_in_markdown with control='AC-2'
Analyzing Changes:
"What's new in the latest KSI release?"
→ Uses list_versions then diff_frmr to compare versions
"Show significant change guidance"
→ Uses get_significant_change_guidance
These prompts combine FedRAMP data with Claude's analytical capabilities to help you design compliance dashboards and features:
Dashboard Architecture:
"Using the FedRAMP KSI data, design a compliance dashboard architecture.
What components would I need? How should I structure the data for real-time monitoring?"
"Get all KSI themes and their indicators. Then recommend how to organize
them into a dashboard with drill-down navigation."
Visualization Design:
"Analyze the FedRAMP control coverage data. What would be the best
chart types to visualize control family coverage? Suggest a color
scheme for compliance status."
"List the KSIs filtered by impact level. Design a risk heat map
visualization showing low/moderate/high impact requirements."
Feature Planning:
"Get the evidence checklist from FedRAMP. How would you build a
feature that tracks evidence collection progress with percentage
completion per KSI theme?"
"What are the requirements for AC-2 (Account Management)? Design a
feature that helps users track their implementation status against
these requirements."
Data Modeling:
"Analyze the structure of KSI indicators and their control mappings.
What database schema would you recommend for a compliance tracking app?"
"Get a theme summary for IAM. How would you model the relationship
between KSIs, NIST controls, and evidence in a graph database?"
Executive Reporting:
"Using the control coverage analysis, design an executive summary
dashboard that shows compliance posture at a glance."
"Analyze all high-impact KSI requirements and create a prioritized
remediation roadmap template."
With 21 tools, this MCP server is a great candidate for deferred tool loading (also known as tool search). Instead of loading all tools upfront, clients can load a small set of essential tools and discover the rest on demand via the search_tools tool.
search_tools ToolThe search_tools tool lets clients discover available tools by keyword or category:
"What tools help with KSI compliance?"
→ search_tools(query="ksi compliance")
→ Returns: list_ksi, get_ksi, filter_by_impact, get_theme_summary, get_evidence_examples
"What analysis tools are available?"
→ search_tools(category="Analysis")
→ Returns: diff_frmr, grep_controls_in_markdown, get_significant_change_guidance
When using deferred loading, keep these 5 tools always loaded:
| Tool | Why Always Loaded |
|------|-------------------|
| search_tools | Required for discovering other tools |
| search_markdown | Most common entry point for documentation queries |
| list_frmr_documents | Starting point for FRMR data exploration |
| health_check | Diagnostics and status verification |
| get_requirement_by_id | Universal ID lookup across all document types |
When using the Claude API with mcp_toolset, you can configure deferred loading:
import anthropic
client = anthropic.Anthropic()
response = client.messages.create(
model="claude-sonnet-4-20250514",
max_tokens=1024,
mcp_servers=[
{
"type": "stdio",
"command": "fedramp-docs-mcp",
"name": "fedramp-docs",
}
],
messages=[{"role": "user", "content": "..."}],
)
The Claude API will use tool annotations (readOnlyHint, destructiveHint, etc.) to make informed decisions about tool selection. All 21 tools include annotations.
The FedRAMP Docs MCP server works with any MCP-compatible client. Below are setup instructions for the most popular and reliable clients.
Recommended clients:
Add the server to your Claude Desktop configuration file:
Location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Option 1: Using npx (Recommended - no install required)
{
"mcpServers": {
"fedramp-docs": {
"command": "npx",
"args": ["fedramp-docs-mcp"],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Option 2: Global installation
npm install -g fedramp-docs-mcp
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"env": {
"FEDRAMP_DOCS_PATH": "/path/to/FedRAMP/docs"
}
}
}
}
After updating the config, restart Claude Desktop. The FedRAMP Docs tools will appear in your conversations.
Claude Code is Anthropic's official CLI tool with built-in MCP support.
# Add the FedRAMP Docs MCP server
claude mcp add --transport stdio fedramp-docs fedramp-docs-mcp
# With full path
claude mcp add --transport stdio fedramp-docs /path/to/node/bin/fedramp-docs-mcp
# List configured servers
claude mcp list
# Remove if needed
claude mcp remove fedramp-docs
Claude Code supports three configuration scopes:
.mcp.json in project root~/.claude/settings.local.json.claude/settings.local.json in project rootExample .mcp.json (project-scoped, can be version-controlled):
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"args": [],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
With environment variable expansion:
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"args": [],
"env": {
"FEDRAMP_DOCS_PATH": "${HOME}/fedramp-docs",
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Testing:
/mcp command for interactive management--mcp-debug flag for troubleshooting: claude --mcp-debugclaude mcp listNote: Project-scoped configurations in .mcp.json enable team collaboration by ensuring all team members have access to the same MCP tools.
LM Studio (v0.3.17+) has native MCP support and works great with local models for privacy-focused workflows.
Config file location:
~/.lmstudio/mcp.json%USERPROFILE%\.lmstudio\mcp.jsonBasic configuration:
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"args": [],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Using full path (recommended if command not found):
{
"mcpServers": {
"fedramp-docs": {
"command": "/path/to/node/bin/fedramp-docs-mcp",
"args": [],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true",
"FEDRAMP_DOCS_PATH": "/path/to/FedRAMP/docs"
}
}
}
}
Note: Requires global installation (npm install -g .) or use the full path to the executable. Find your path with: which fedramp-docs-mcp
OpenCode is a powerful AI coding agent built for the terminal with native MCP support.
Config file location:
~/.config/opencode/opencode.jsonopencode.json (in your project root)Basic configuration:
{
"mcp": {
"fedramp-docs": {
"type": "local",
"command": ["fedramp-docs-mcp"],
"enabled": true
}
}
}
With full path:
{
"mcp": {
"fedramp-docs": {
"type": "local",
"command": ["/path/to/node/bin/fedramp-docs-mcp"],
"enabled": true
}
}
}
With environment variables:
{
"mcp": {
"fedramp-docs": {
"type": "local",
"command": ["fedramp-docs-mcp"],
"enabled": true,
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true",
"FEDRAMP_DOCS_PATH": "/path/to/FedRAMP/docs"
}
}
}
}
Note: MCP servers add to your context, so enable only the ones you need. Use "enabled": false to temporarily disable a server without removing it.
Goose is Block's open-source AI agent. You can add the FedRAMP Docs MCP server using any of these methods:
goose configure
Then select:
Add ExtensionCommand-line ExtensionFedRAMP Docsfedramp-docs-mcp300FedRAMP DocsSTDIOfedramp-docs-mcp300FEDRAMP_DOCS_PATH: /path/to/FedRAMP/docsFEDRAMP_DOCS_AUTO_UPDATE: trueEdit ~/.config/goose/config.yaml (Linux/macOS) or %USERPROFILE%\.config\goose\config.yaml (Windows):
extensions:
fedramp-docs:
name: FedRAMP Docs
cmd: fedramp-docs-mcp
enabled: true
type: stdio
timeout: 300
envs:
FEDRAMP_DOCS_PATH: "/path/to/FedRAMP/docs" # optional
FEDRAMP_DOCS_AUTO_UPDATE: "true" # optional
After configuration, restart Goose or reload extensions. You can test by asking: "What FedRAMP tools are available?"
Note: Goose's MCP support is still maturing and may have issues discovering tools from stdio servers. If you experience problems with tool discovery, consider using Claude Desktop, Claude Code CLI, LM Studio, or OpenCode instead.
Kiro is AWS's spec-driven IDE with native MCP support.
Open Kiro MCP settings:
~/.kiro/settings/mcp.json.kiro/settings/mcp.json (takes precedence)Add the FedRAMP Docs configuration:
{
"mcpServers": {
"fedramp-docs": {
"command": "npx",
"args": ["-y", "fedramp-docs-mcp"],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
With global installation:
{
"mcpServers": {
"fedramp-docs": {
"command": "fedramp-docs-mcp",
"args": [],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Note: Requires global installation (npm install -g fedramp-docs-mcp) or use npx. Find your path with: which fedramp-docs-mcp
Cursor supports MCP servers via project or global configuration.
Config file location: .cursor/mcp.json (project) or ~/.cursor/mcp.json (global)
{
"mcpServers": {
"fedramp-docs": {
"command": "npx",
"args": ["-y", "fedramp-docs-mcp"],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Restart Cursor after saving. You can also configure via Cursor Settings > MCP.
VS Code has native MCP support through GitHub Copilot (no extensions required).
Config file location: .vscode/mcp.json (workspace-scoped)
Note: VS Code uses servers (not mcpServers) and requires "type": "stdio".
{
"servers": {
"fedramp-docs": {
"type": "stdio",
"command": "npx",
"args": ["-y", "fedramp-docs-mcp"]
}
}
}
After saving, Copilot will detect the new server automatically. Manage MCP servers from the Command Palette (Ctrl+Shift+P > "MCP: List Servers").
Windsurf is an AI-powered IDE with native MCP support.
Config file location: ~/.codeium/windsurf/mcp_config.json
{
"mcpServers": {
"fedramp-docs": {
"command": "npx",
"args": ["-y", "fedramp-docs-mcp"],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Restart Windsurf after saving.
Codex is OpenAI's open-source coding agent with MCP support via TOML configuration.
Config file location: ~/.codex/config.toml (global) or .codex/config.toml (project)
[mcp_servers.fedramp-docs]
command = "npx"
args = ["-y", "fedramp-docs-mcp"]
[mcp_servers.fedramp-docs.env]
FEDRAMP_DOCS_AUTO_UPDATE = "true"
You can also manage MCP servers via codex mcp.
Gemini CLI is Google's command-line AI agent with MCP support.
Config file location: ~/.gemini/settings.json (global) or .gemini/settings.json (project)
{
"mcpServers": {
"fedramp-docs": {
"command": "npx",
"args": ["-y", "fedramp-docs-mcp"],
"env": {
"FEDRAMP_DOCS_AUTO_UPDATE": "true"
}
}
}
}
Restart Gemini CLI after saving.
The MCP Inspector is an official tool for testing and debugging MCP servers. It provides a visual UI to interactively call tools and explore resources.
Requirements: Node.js 22.7.5 or later
Interactive UI:
# Start the inspector with fedramp-docs-mcp
npx @modelcontextprotocol/inspector node dist/index.js
# Or if installed globally
npx @modelcontextprotocol/inspector fedramp-docs-mcp
Open http://localhost:6274 to access the UI, then test tools like:
health_check - Verify the server is workinglist_frmr_documents - See all indexed FedRAMP documentslist_ksi - Browse Key Security IndicatorsCLI Mode (Quick Testing):
# List all available tools
npx @modelcontextprotocol/inspector --cli node dist/index.js --method tools/list
# Call a specific tool
npx @modelcontextprotocol/inspector --cli node dist/index.js \
--method tools/call --tool-name health_check
Export Configuration: The Inspector UI includes buttons to copy server configurations for Claude Desktop, Cursor, and other MCP clients.
The repository includes a Claude Code plugin that provides slash commands, agent skills, and a specialized compliance analyst agent.
In Claude Code, run:
/plugin marketplace add ethanolivertroy/fedramp-docs-mcp
/plugin install fedramp-docs
That's it! The plugin is ready to use.
<details> <summary>Alternative: Manual Installation</summary># One-command setup
npx fedramp-docs-mcp setup
# Then start Claude Code with the plugin
claude --plugin-dir ~/.fedramp-docs-mcp/plugin
Or add an alias to your shell profile:
alias claude-fedramp='claude --plugin-dir ~/.fedramp-docs-mcp/plugin'
</details>
| Command | Description |
|---------|-------------|
| /fedramp-docs:search <query> | Search FedRAMP documentation |
| /fedramp-docs:search-definitions <term> | Search FedRAMP definitions |
| /fedramp-docs:list-controls [family] | List NIST controls |
| /fedramp-docs:control-requirements <control> | Get requirements for a NIST control |
| /fedramp-docs:control-coverage | Analyze NIST control coverage |
| /fedramp-docs:list-ksi [filter] | List Key Security Indicators |
| /fedramp-docs:filter-impact <level> | Filter KSI by impact level |
| /fedramp-docs:theme-summary <theme> | Get theme guidance |
| /fedramp-docs:evidence-checklist [theme] | Get evidence checklist |
| /fedramp-docs:get-requirement <id> | Get requirement by ID |
| /fedramp-docs:list-documents | List all FRMR documents |
| /fedramp-docs:compare <doc1> <doc2> | Compare document versions |
| /fedramp-docs:health | Check MCP server status |
See plugin/README.md for full documentation.
Run the MCP server in a security-hardened Docker container.
# Build the image
docker build -t fedramp-docs-mcp .
# Run interactively (for MCP stdio)
docker run --rm -i \
--security-opt no-new-privileges:true \
--cap-drop ALL \
--read-only \
--memory 512m \
-v fedramp-cache:/home/mcpuser/.cache/fedramp-docs \
fedramp-docs-mcp
# Start with docker-compose (security hardening included)
docker compose up -d
Configure Claude Desktop to use the Docker container:
{
"mcpServers": {
"fedramp-docs": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"--security-opt", "no-new-privileges:true",
"--cap-drop", "ALL",
"--read-only",
"--memory", "512m",
"-v", "fedramp-cache:/home/mcpuser/.cache/fedramp-docs",
"fedramp-docs-mcp:latest"
]
}
}
}
The Docker setup follows 2025 MCP security best practices:
mcpuser (UID 1001)--cap-drop ALL removes all Linux capabilitiesUse tsx for rapid iteration without building:
npm run dev
This runs the TypeScript source directly, automatically recompiling on changes.
The repository includes Vitest-based unit and contract tests with small fixtures:
npm test
Tests set FEDRAMP_DOCS_PATH to tests/fixtures/repo, ensuring the indexer, search, and diff logic run deterministically without needing the real FedRAMP repo.
Integration tests validate the indexer against the real upstream FedRAMP/docs clone:
npm run test:integration
These tests clone and index the actual upstream repository, verifying that the parser handles current upstream data correctly. Set FEDRAMP_DOCS_PATH to skip the clone and use an existing checkout. When using your own checkout, also set FEDRAMP_DOCS_AUTO_UPDATE=false to prevent the test from modifying it.
The codebase uses:
"type": "module" in package.json)moduleResolution: "NodeNext")src/
index.ts # MCP bootstrap
repo.ts # repo discovery and cloning
indexer.ts # FRMR + markdown indexing logic
frmr.ts # FRMR-centric helpers
search.ts # markdown search + aggregations
diff.ts # structured FRMR diff engine
tools/ # individual MCP tool handlers
Fixtures live under tests/fixtures, while Vitest specs reside in tests/.
Tracks FedRAMP FRMR v0.9.2-beta documents. See CHANGELOG.md for full details.
| Version | Date | Highlights |
|---------|------|------------|
| v0.2.5 | 2026-02-15 | MCP client instructions for Codex, Cursor, Windsurf, VS Code + Copilot, Gemini CLI |
| v0.2.4 | 2026-02-15 | Automated upstream sync workflow, integration test suite |
| v0.2.3 | 2026-02-15 | MCP Security Scan CI with Cisco's MCP Scanner |
| v0.2.1 | 2025-12-30 | Okta/Duo MFA evidence sources, enhanced health_check |
| v0.2.0 | 2025-12-28 | 7 new tools, Claude Code plugin, Docker support, 12 FRMR types |
| v0.1.0 | 2025-10-10 | Initial release with 13 core MCP tools |
Error: Cannot find module '@modelcontextprotocol/sdk'
Ensure you have the correct SDK version installed:
npm install @modelcontextprotocol/sdk@^1.20.0
Error: Module not found or import errors
The project uses ES modules with NodeNext resolution. Make sure you're using Node.js 18+ and that your TypeScript configuration matches:
{
"compilerOptions": {
"module": "NodeNext",
"moduleResolution": "NodeNext"
}
}
Error: REPO_CLONE_FAILED
The server couldn't clone the FedRAMP docs repository. Check:
FEDRAMP_DOCS_PATH to an existing local clone, orFEDRAMP_DOCS_ALLOW_AUTO_CLONE=true (default)Server starts but no tools appear
Verify the build completed successfully:
npm run build
ls dist/ # Should contain index.js, tools/, etc.
TypeScript errors about missing types
Install all development dependencies:
npm install
Required type packages:
@types/node@types/fs-extra@types/lunr@types/globMachine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/contract"
curl -s "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
A Model Context Protocol (MCP) server for GitLab
A Model Context Protocol (MCP) server for GitLab
This agent researches trends, scripts videos, sets up engagement automation, and compiles everything into a shareable document.
This agent analyzes Reddit data to generate trending content concepts tailored to your audience.
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"MCP"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_MCP",
"generatedAt": "2026-10-09T02:26:19.859Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "MCP",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "mcp",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "model-context-protocol",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "fedramp",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "compliance",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "nist",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "security",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "frmr",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "cloud-security",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "cli",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:MCP|unknown|profile capability:mcp|supported|profile capability:model-context-protocol|supported|profile capability:fedramp|supported|profile capability:compliance|supported|profile capability:nist|supported|profile capability:security|supported|profile capability:frmr|supported|profile capability:cloud-security|supported|profile capability:cli|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Ethanolivertroy",
"href": "https://github.com/ethanolivertroy/fedramp-docs-mcp#readme",
"sourceUrl": "https://github.com/ethanolivertroy/fedramp-docs-mcp#readme",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-25T03:19:26.091Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "MCP",
"href": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-02-25T03:19:26.091Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "16 GitHub stars",
"href": "https://github.com/ethanolivertroy/fedramp-docs-mcp",
"sourceUrl": "https://github.com/ethanolivertroy/fedramp-docs-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-25T03:19:26.091Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/mcp-ethanolivertroy-fedramp-docs-mcp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to fedramp-docs-mcp and adjacent AI workflows.