export-regulation-mcp (touch4645/export-regulation-mcp) is an MCP server listed on the M8ven Trust Index. It scores 57 out of 100, grade D. It declares 11 tools. No publisher has claimed this listing.

D
Caution
57/100

export-regulation-mcp

Provides tools to access Japanese export control laws, annexes, and user lists via e-Gov API, enabling real-time compliance checks for dual-use goods.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

touch4645

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Tool annotations don’t match behaviour
1 read-only tool performs write/delete/exec — export_reg_check_user_list (line 39: userListPattern.exec(html))
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes11 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

export_reg_get_annex

輸出貿易管理令の別表第1(リスト規制品目)を取得します。項番を指定して特定の規制品目カテゴリの詳細を参照できます。

export_reg_get_annex3_2

輸出貿易管理令別表第3の2(国連武器禁輸国・地域)のリストを取得します。キャッチオール規制の客観要件判定に使用します。

export_reg_get_fear_ordinance

おそれ省令(輸出貿易管理令の運用通達)の内容を取得します。キャッチオール規制における用途要件の判定基準を参照できます。

export_reg_get_tariff_items

関税定率法別表の品目分類を取得します。キャッチオール規制の16項中欄(別表第1の16の項)に関連する品目の確認に使用します。

export_reg_get_white_countries

輸出貿易管理令別表第3に規定されるグループA国(旧ホワイト国)のリストを取得します。グループA国への輸出は包括許可が利用可能です。

export_reg_check_country

指定された国の輸出管理上のステータス(グループA/B/C/D)を確認します。国グループにより利用可能な包括許可の種類が異なります。

export_reg_get_law

指定された法令IDの法令本文を取得します。輸出管理関連の法令(輸出貿易管理令、外国為替令、貨物等省令など)を参照できます。

export_reg_search_law

キーワードで輸出管理関連の法令を検索します。法令名や条文の内容で検索できます。

export_reg_get_ministerial_ordinance

輸出貿易管理令の貨物等省令(経済産業省令)の条文を取得します。リスト規制品目の具体的な技術仕様・パラメータ閾値が規定されています。

export_reg_get_parameter_thresholds

輸出管理リスト規制の項番別の技術パラメータ閾値を取得します。別表第1の項番と貨物等省令を組み合わせて、規制対象となる具体的な技術仕様を確認できます。

export_reg_check_user_list

経済産業省の外国ユーザーリスト(懸念企業リスト)に対して組織名を照合します。大量破壊兵器の開発等に関与している懸念のある企業・組織が掲載されています。METIが公開するExcelデータを取得・解析して検索します。

// known CVEs in dependencies2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highxlsx@0.18.5GHSA-4r6h-8v6p-xvw6

Prototype Pollution in sheetJS

highxlsx@0.18.5GHSA-5pgg-2g8v-p4x9

SheetJS Regular Expression Denial of Service (ReDoS)

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// quality suggestions

All four hints declared on every tool

11/11 tools missing one or more hints — export_reg_get_annex (missing: destructiveHint, idempotentHint, openWorldHint); export_reg_get_annex3_2 (missing: destructiveHint, idempotentHint, openWorldHint); export_reg_get_fear_ordinance (missing: destructiveHint, idempotentHint, openWorldHint), +8 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool annotations match behaviour

1 read-only tool performs write/delete/exec — export_reg_check_user_list (line 39: userListPattern.exec(html))

Either remove the readOnlyHint:true annotation, or remove the write/delete call from the tool handler.

Tool inputs are validated

Only 1/11 tool handlers declare input schemas (9%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 2 high severity in production deps — xlsx@0.18.5 (high), xlsx@0.18.5 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/touch4645/export-regulation-mcp?variant=verified)](https://m8ven.ai/mcp/touch4645/export-regulation-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 7f5181b4d052256b1b581fbcc20307724e1488f9
code hash: a72e428a24a3d5aa63a8732597e2614f9e0700dea96fb9d1da7ba9a971584bd7
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client