Scf
MCP server for the SCF Controls Platform — 128 tools for controls, evidence, risk, and TPRM.
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability
Category: Security — see all ranked ›
Work: Regulatory compliance · Risk assessment
Who it is for: Legal / compliance · Security engineer · Product manager
Install (Claude Code):
claude mcp add scf -- npx -y mcp-server-scf“Domain table with tool counts; says plainly there is no hosted default and calls fail”
This grade is wrong ›- tashan score: 69.0
- Instruction depth: 78.0 (solid — documents the job properly, with examples you could follow)
- Adoption: 923/wk
- Upkeep: 94.0
- Freshness: 82.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- GitHub stars: 1
- Contributors: 3
- License: MIT
Security audit
scanned 2026-09-12Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.
What changed recently
- 2026-09-13 mcp-server-scf published 3.0.0, was 2.0.1 A new release is available.
You are reading this because you came looking. tashan Pro gives tashan doctor the history behind it, so a run over your own config says which of YOURS moved.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
We recorded 1 change to Scf in the last 45 days. Pro tells you on the day — for the servers in your own config, not the ones you thought to look up.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
npm ↗ · source ↗ · pkg:mcp-server-scf
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-13 · scorer s5 · how · something wrong here?