71
/ 100
5 days ago
pulsemcp

AWS OSCAL

Provides AI assistants with tools to work with NIST's Open Security Controls Assessment Language. Includes OSCAL schema access, resource discovery, documentation queries, and component definition tools for security compliance workflows.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configOSCAL_KB_ID
configAWS_PROFILE
configAWS_REGION
configLOG_LEVEL
configOSCAL_MCP_SERVER_NAME
configOSCAL_MCP_TRANSPORT
configOSCAL_MCP_HOST
configOSCAL_MCP_STATELESS_HTTP
configOSCAL_ALLOW_REMOTE_URIS
configOSCAL_REQUEST_TIMEOUT
configOSCAL_MAX_URI_DEPTH
configOSCAL_COMPONENT_DEFINITIONS_DIR
configOSCAL_STORE_DB_PATH_(empty)_ Path to a persistent SQLite database. When set, the index is reused across server restarts instead of being rebuilt each time.
configOSCAL_STORE_CACHE_SIZE100 Maximum number of parsed OSCAL documents to keep in the in-memory LRU cache.
configOSCAL_DOCUMENTS_DIRSet the environment variable to the path of your OSCAL content directory. The path can be absolute or relative to the server's package directory. For example, in your MCP configuration:
configOSCAL_AGENT_SESSION_STORAGE
configOSCAL_AGENT_SESSION_DIR
configOSCAL_AGENT_SESSION_S3_BUCKET
configOSCAL_AGENT_MAX_TOKENS
configOSCAL_AGENT_MAX_RETRY_ATTEMPTS
configOSCAL_AGENT_RETRY_INITIAL_DELAY
configOSCAL_AGENT_RETRY_MAX_DELAY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/awslabs-mcp-server-for-oscal-1pkvp4)](https://m8ven.ai/mcp/awslabs-mcp-server-for-oscal-1pkvp4)
commit: de7f35614f50c9ade5d08b3e1c617112ea573ad1
code hash: f04927b11c8bbd2c8bebb795f4a6c6ccb6e336fe8cae1af21cb78f24292cb3be
verified: 7/26/2026, 8:45:43 AM
view raw JSON →