For Oscal MCP Server
by awslabsio.github.awslabs/mcp-server-for-oscalv0.4.0
AI agent tools for Open Security Controls Assessment Language (OSCAL)
context tax
queued
security
queued
cold start
queued
freshness
Abandoned6mo ago
Install For Oscal MCP server
Install in Claude Code
claude mcp add for-oscal -- uvx mcp-server-for-oscalInstall in Cursor
{
"mcpServers": {
"for-oscal": {
"command": "uvx",
"args": [
"mcp-server-for-oscal"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"for-oscal": {
"command": "uvx",
"args": [
"mcp-server-for-oscal"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"for-oscal": {
"type": "stdio",
"command": "uvx",
"args": [
"mcp-server-for-oscal"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"for-oscal": {
"command": "uvx",
"args": [
"mcp-server-for-oscal"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| BEDROCK_MODEL_ID | — | — | AWS Bedrock model ID for OSCAL documentation queries |
| OSCAL_KB_ID | — | — | AWS Bedrock Knowledge Base ID for OSCAL documentation |
| AWS_PROFILE | — | — | AWS CLI profile name for credential resolution |
| AWS_REGION | — | — | AWS region for Bedrock API calls |
| LOG_LEVEL | — | — | Logging verbosity level (DEBUG, INFO, WARNING, ERROR) |
Freshness
Abandoned — last maintenance signal 6mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-04-08 · 6mo ago · GitHub
Latest release
2026-04-02 · 6mo ago · GitHub · v0.4.0
Package published
no data · npm/PyPI
Registry entry updated
2026-04-02 · 6mo ago · official registry · v0.4.0
FAQ
›How do I install the For Oscal MCP server in Claude Code?
Run: claude mcp add for-oscal -- uvx mcp-server-for-oscal. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does For Oscal require an API key?
No required environment variables are declared in its published metadata.
›Can I use For Oscal as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is For Oscal in the official MCP registry?
Yes, as io.github.awslabs/mcp-server-for-oscal.
Alternatives to For Oscal
Other security MCP servers.