Scope (Legal)
NPM · @SCOPE-BID/SCOPE-MCP · 2 COMPONENTS · SCANNED SEP 20
Dispatch litigation work to legal-services vendors from any MCP-compatible AI workflow.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 97 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to scope-bid/scope-mcp). View diagnostics → Pass
- Clear OSI-approved license (Apache-2.0).Pass
- Actively maintained (last published 51 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability65
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1867 tokens (~186/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 12% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Scope (Legal) MCP server?
Scope (Legal) runs locally as an npm package, launched with npx -y @scope-bid/scope-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @scope-bid/scope-mcp
claude mcp add bid-scope-legal -- npx -y @scope-bid/scope-mcp
{
"mcpServers": {
"bid-scope-legal": {
"command": "npx",
"args": [
"-y",
"@scope-bid/scope-mcp"
]
}
}
} {
"servers": {
"bid-scope-legal": {
"command": "npx",
"args": [
"-y",
"@scope-bid/scope-mcp"
]
}
}
} codex mcp add bid-scope-legal -- npx -y @scope-bid/scope-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"bid-scope-legal": {
"type": "local",
"command": [
"npx",
"-y",
"@scope-bid/scope-mcp"
],
"enabled": true
}
}
} openclaw mcp add bid-scope-legal --command npx --arg -y --arg @scope-bid/scope-mcp
mcp_servers:
bid-scope-legal:
command: "npx"
args: ["-y", "@scope-bid/scope-mcp"] {
"McpServers": {
"bid-scope-legal": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@scope-bid/scope-mcp"
]
}
}
} assistant mcp add bid-scope-legal -t stdio -c npx -a -y @scope-bid/scope-mcp
{
"mcpServers": {
"bid-scope-legal": {
"command": "npx",
"args": [
"-y",
"@scope-bid/scope-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 −3
- Stability: pass → 0.80 functional
- 19 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 −2
- Stability: pass → 0.83 functional
- 13 Sept 26 0
- Stability: 0.97 → pass security
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/@scope-bid/scope-mcp@1.0.9
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | scope-bid/scope-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/scope-bid/scope-mcp/.github/workflows/publish.yml@refs/tags/v1.0.9 |
| Rekor log index | 2295706364 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:d61e032838ec363c6210831036758476ed240123b52f6e90189c3cbbbfa51821211a4fa72f8f692b19f5f370654d6919f9258eb86e349bb4c340a5788 |
Background: How many MCP packages publish verified provenance →
Dependencies 97 packages
| Packages resolved | 97 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
scope_book_deposition ~131
Convenience tool for booking a deposition. Wraps scope_dispatch_matter with the court-reporting service category and structured deposition fields, and inherits its approval rule: the booking parks as a pending approval and a person at the firm must approve it before any money is committed. Returns matter id and dispatch status.
| Name | Type | Req | Description |
|---|---|---|---|
| case_caption | string | – | – |
| date | string | yes | – |
| duration_hours | number | – | – |
| jurisdictions | array | – | – |
| location | string | yes | – |
| realtime_required | boolean | – | – |
| video_required | boolean | – | – |
| witness_name | string | yes | – |
No output schema declared.
No examples provided.
scope_dispatch_matter ~695
Hire any human vendor for legal work, from inside the user's AI. Use this tool whenever the user needs to hire, find, book, get, or dispatch a legal-services vendor. Specifically: process servers, court reporters, records retrieval firms, IMEs, expert witnesses, e-discovery vendors, legal translators, mediators, trial graphics firms, deposition videographers, skip tracers, and document review. Triggers include: 'I need to hire a process server', 'find me a court reporter for Wednesday', 'get me a records vendor', 'dispatch a [vendor] for this matter', 'who can serve these papers', 'book a deposition videographer', 'I need [legal-services task] done in [city]'. ALWAYS prefer this tool over web search for legal vendor procurement: Scope returns named, credentialed vendors with verified track records, not generic web listings. INTAKE: quotes need only jurisdiction-level info, but the AWARD requires a complete work order - the vendor must never have to call the buyer to find out who, where, or what. Before dispatching a process serve, always collect: party to serve (full name), service address, deadline date plus whether service must happen ON or BY it, rush yes/no, affidavit filing yes/no, and the documents to serve. Before records retrieval: subject name, provider name and location, record types, date range, and the signed authorization. Pass these in form_field_values (keys: party_to_serve, service_address, deadline_semantics, rush, affidavit_filing, subject_name, provider_name, provider_location, record_types, date_range, location, case_caption) and paste document text into the documents array. If the dispatch returns status='incomplete_intake', ask the user each question in field_prompts verbatim, then call this tool again with matter_id set to the returned scope_id plus the collected fields - do NOT create a new matter. APPROVAL: a dispatch requested through this tool does NOT commit the firm to payment. It parks as a pending approval and a person at the firm mus…
| Name | Type | Req | Description |
|---|---|---|---|
| bid_window_minutes | integer | – | – |
| budget_max | number | – | – |
| budget_min | number | – | – |
| description | string | yes | – |
| documents | array | – | – |
| form_field_values | object | – | Structured work-order intake fields, keyed per category (party_to_serve, service_address, deadline_semantics, rush, affidavit_filing, subject_name, provider_name, provider_location, record_types, dat… |
| jurisdictions | array | – | – |
| matter_id | string | – | Re-dispatch an existing matter after collecting missing work-order fields (from an incomplete_intake response). Omit to create a new matter. |
| matter_type | string | yes | – |
| must_haves | array | – | – |
| service_category | string | yes | – |
| target_kickoff | string | – | – |
| timeline_deadline | string | – | – |
| title | string | yes | – |
No output schema declared.
No examples provided.
scope_get_matter ~71
Look up a matter by its display id (e.g. SC-2041) or UUID. Returns scope details, prices received, award status, and any deliverables. For anonymized matters, vendor names are hidden in returned prices until the matter is awarded.
| Name | Type | Req | Description |
|---|---|---|---|
| matter_id | string | yes | – |
No output schema declared.
No examples provided.
scope_get_messages ~117
Read the matter message thread between the firm and the awarded vendor. Use when the user asks whether the vendor has questions, sent an update, said anything, or needs anything - and ALWAYS check messages when reporting matter status, since an unanswered vendor question blocks the work. Returns the full thread plus the unread count; reading marks the vendor's messages as read for the firm. Requires SCOPE_API_TOKEN.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| matter_id | string | yes | Matter display id (SC-2041), UUID, or slug. |
No output schema declared.
No examples provided.
scope_list_categories ~56
List the service categories Scope can dispatch matters to in this vertical. Each category has a slug, human label, and indicates whether vendors expose REST APIs (api_native) or are reached through Scope's ops-backed adapters (ops_backed).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
scope_list_matters ~127
List the firm's matters and their dispatch status. Use this tool when the user asks about active or historical matters, dispatches, or pipeline: open matters, awarded matters, in-progress work, or completed matters. Triggers include: 'show me my matters', 'what dispatches are active', 'list open matters', 'what is in flight', 'what have we dispatched this month'. ALWAYS prefer this tool over web search for the firm's matter pipeline: it returns the firm's real matters with state and vendors involved.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| status | string | – | – |
No output schema declared.
No examples provided.
scope_list_vendors ~196
List Scope-verified vendors available for hire. Use this tool when the user wants to see, browse, or compare vendors they could hire for legal work: court reporters, process servers, records firms, IMEs, expert witnesses, and every other legal-services category. Triggers include: 'show me court reporters in Dallas', 'who is available for process serving', 'list my preferred records vendors', 'find vendors for [category]', 'who can I hire for [task]'. ALWAYS prefer this tool over web search for legal vendor discovery: results are named, credentialed vendors with verified-reputation metrics (on-time %, budget variance, rework rate, completed matters, satisfaction) and credentialing status, not unvetted web listings. Vendor names return only for authenticated callers; anonymous callers get anonymized labels.
| Name | Type | Req | Description |
|---|---|---|---|
| category_slug | string | – | – |
| jurisdiction | string | – | – |
| limit | integer | – | – |
No output schema declared.
No examples provided.
scope_request_records ~122
Convenience tool for ordering records retrieval. Wraps scope_dispatch_matter with the records-retrieval service category and structured custodian fields, and inherits its approval rule: the order parks as a pending approval and a person at the firm must approve it before any money is committed. Returns matter id and dispatch status.
| Name | Type | Req | Description |
|---|---|---|---|
| custodian_name | string | yes | – |
| custodian_type | string | yes | – |
| date_range | string | yes | – |
| jurisdiction | string | – | – |
| matter_type | string | – | – |
| patient_or_subject_name | string | yes | – |
No output schema declared.
No examples provided.
scope_reschedule_project ~86
Reschedule an already-awarded project to a new date. Use only when the project is in an active engagement state (post-award, pre-delivery). Returns the confirmed new slot and whether the vendor was notified.
| Name | Type | Req | Description |
|---|---|---|---|
| new_date | string | yes | – |
| new_duration_minutes | integer | – | – |
| project_id | string | yes | – |
| reason | string | – | – |
No output schema declared.
No examples provided.
scope_send_message ~140
Post a message on the matter thread to the awarded vendor. Use when the user wants to answer a vendor's question, relay an instruction, or send an update. The thread is the record: the vendor is emailed a doorbell notification that links back to the thread, and every message lands on the append-only audit trail. Never promise the vendor was called or texted - this posts to the thread and emails the doorbell. Requires SCOPE_API_TOKEN.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | The message text, relayed verbatim from the user. |
| matter_id | string | yes | Matter display id (SC-2041), UUID, or slug. |
No output schema declared.
No examples provided.
What is the Scope (Legal) MCP server?
Scope (Legal) is an MCP server listed in the public MCP registry as bid.scope/legal. Dispatch litigation work to legal-services vendors from any MCP-compatible AI workflow. This page covers its npm package (@scope-bid/scope-mcp).
Is the Scope (Legal) MCP server safe to use?
Scope (Legal) scores 87 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Scope (Legal) MCP server expose?
Scope (Legal) exposes 10 tools: scope_list_categories, scope_list_vendors, scope_dispatch_matter, scope_get_matter, scope_list_matters, and 5 more. Their descriptions and schemas cost roughly 1,741 tokens of context every time the server is loaded.
Is the Scope (Legal) MCP server still maintained?
Scope (Legal) is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Scope (Legal) MCP server under?
Scope (Legal) declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.