fedramp-docs

fedramp-docs is an MCP server for Claude Code, Codex, Cursor, Gemini CLI, OpenCode from hackIDLE/fedramp-docs-mcp. Its token cost is not measured, scanned A, original, MIT.

A connection that lets an agent use the fedramp-docs compliance server. The server is configured to update its FedRAMP documents automatically and requires one environment variable to run.

In plain words
What is it for?
Use it to connect an agent to fedramp-docs for searching documents, analysing controls, and tracking compliance-related changes.
Why use it?
It provides access to the fedramp-docs server’s document and compliance functions from an agent setup.

MCP server for Claude CodeCodexCursorGemini CLIOpenCode

Part of the fedramp-docs plugin — 2 skills, 13 commands, 1 agent, 1 MCP server shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add mcp/hackidle/fedramp-docs-mcp/fedramp-docs
Clone the repo
git clone --depth 1 https://github.com/hackIDLE/fedramp-docs-mcp

Made for: Claude Code, Codex, Cursor, Gemini CLI, OpenCode.

Or install fedramp-docs, the plugin that ships this one along with the rest of its 2 skills, 13 commands, 1 agent, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for fedramp-docs

README.md
[![agentmods](https://agentmods.dev/badge/mcp/hackidle/fedramp-docs-mcp/fedramp-docs.svg)](https://agentmods.dev/mcp/hackidle/fedramp-docs-mcp/fedramp-docs)
Your own site
<a href="https://agentmods.dev/mcp/hackidle/fedramp-docs-mcp/fedramp-docs"><img src="https://agentmods.dev/badge/mcp/hackidle/fedramp-docs-mcp/fedramp-docs.svg" alt="Measured on agentmods" height="20"></a>
Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

fedramp-docs scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugin/.mcp.json · 9 lines

What it actually says

{
  "fedramp-docs": {
    "command": "fedramp-docs-mcp",
    "args": [],
    "env": {
      "FEDRAMP_DOCS_AUTO_UPDATE": "true"
    }
  }
}
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 9 lines scan A 73ffa71daac8

Subscribe to this mod's changes

fedramp-docs is an MCP server published in the GitHub repository hackIDLE/fedramp-docs-mcp (18 stars, last pushed 4mo ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other mcp servers, from other repositories

FedRAMP20xMCP

MCP server for querying FedRAMP 20x requirements. Runs locally from the fedramp-20x-mcp Python package.

KevinRabun/FedRAMP20xMCP · not measured

mcp-custos

MCP server for secure coding and compliance — full MITRE CWE corpus, ISO 27001, NIST 800-53, OWASP ASVS, NIST SSDF, ISO 27017 — with official cross-framework mappings and enforcement hooks. Runs locally from the mcp-custos npm package.

an0malous/mcp-custos · not measured

eu-ai-act-compliance-mcp

EU AI Act compliance for AI agents. 410 articles from EUR-Lex via FTS5 search. Instant risk scan, deadline tracker, 42-point audit, documentation generator, penalty calculator. Zero-config free tier. Built by MEOK AI Labs. Runs locally from the eu-ai-act-compliance-mcp Python package.

CSOAI-ORG/eu-ai-act-compliance-mcp · not measured

compliance-evidence-mcp

MCP server "compliance-evidence-mcp" as configured in prayagpadwal/compliance-evidence-mcp. Runs locally from the compliance-evidence-mcp Python package.

prayagpadwal/compliance-evidence-mcp · not measured

document-integrity-validator-mcp

AI reasoning checks any document against known international standards before your agent acts on it. Runs locally from the document-integrity-validator-mcp npm package. Needs 1 environment variable to run.

OjasKord/document-integrity-validator-mcp · not measured

easy2257-mcp

Read your 18 U.S.C. 2257 compliance records: what is outstanding, expiring, or certified. Remote server at easy2257.com.

Agaveis/easy2257-mcp · not measured