Provides AI assistants with tools to work with NIST's Open Security Controls Assessment Language. Includes OSCAL schema access, resource discovery, documentation queries, and component definition tools for security compliance workflows.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.OSCAL_KB_IDAWS_PROFILEAWS_REGIONLOG_LEVELOSCAL_MCP_SERVER_NAMEOSCAL_MCP_TRANSPORTOSCAL_MCP_HOSTOSCAL_MCP_STATELESS_HTTPOSCAL_ALLOW_REMOTE_URISOSCAL_REQUEST_TIMEOUTOSCAL_MAX_URI_DEPTHOSCAL_COMPONENT_DEFINITIONS_DIROSCAL_STORE_DB_PATH— _(empty)_ Path to a persistent SQLite database. When set, the index is reused across server restarts instead of being rebuilt each time.OSCAL_STORE_CACHE_SIZE— 100 Maximum number of parsed OSCAL documents to keep in the in-memory LRU cache.OSCAL_DOCUMENTS_DIR— Set the environment variable to the path of your OSCAL content directory. The path can be absolute or relative to the server's package directory. For example, in your MCP configuration:OSCAL_AGENT_SESSION_STORAGEOSCAL_AGENT_SESSION_DIROSCAL_AGENT_SESSION_S3_BUCKETOSCAL_AGENT_MAX_TOKENSOSCAL_AGENT_MAX_RETRY_ATTEMPTSOSCAL_AGENT_RETRY_INITIAL_DELAYOSCAL_AGENT_RETRY_MAX_DELAY[](https://m8ven.ai/mcp/awslabs-mcp-server-for-oscal-1pkvp4)