# Scope (Legal) (npm · @scope-bid/scope-mcp)

Dispatch litigation work to legal-services vendors from any MCP-compatible AI workflow.

- Trust score: 73/100 (medium)
- Change this week: +33
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `scope.bid`: 38/100, [markdown](https://verifymcp.io/servers/bid-scope-legal/api-mcp-legal.md), [page](https://verifymcp.io/servers/bid-scope-legal/api-mcp-legal)
- npm · `@scope-bid/scope-mcp`: 73/100 (this document), [markdown](https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp.md), [page](https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp)

## Channel facts

- Registry: `npm`
- Package: `@scope-bid/scope-mcp`
- Version: `1.0.9`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 86/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (95 of 102), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 102), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to scope-bid/scope-mcp).
  - Clear OSI-approved license (Apache-2.0).
  - Actively maintained (last published 3 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 60/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1867 tokens (~186/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 12% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add bid-scope-legal -- npx -y @scope-bid/scope-mcp
```

### Codex

```bash
codex mcp add bid-scope-legal -- npx -y @scope-bid/scope-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "bid-scope-legal": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@scope-bid/scope-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add bid-scope-legal --command npx --arg -y --arg @scope-bid/scope-mcp
```

### Hermes

```yaml
mcp_servers:
  bid-scope-legal:
    command: "npx"
    args: ["-y", "@scope-bid/scope-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "bid-scope-legal": {
      "command": "npx",
      "args": [
        "-y",
        "@scope-bid/scope-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 73, +57)

- [security improvement] Install scripts: unverified → pass
- [security improvement] Provenance: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] The attested source repository moved: scope-bid/scope-mcp
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Schema quality: unverified → good
- [functional improvement] License: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Stability: unverified → 0.23
- [functional] Licence: Apache-2.0

### 2026-08-01 (score 16, −5)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 21, −19)

- [security regression] Malware scan: pass → unverified
- [functional regression] Schema quality: 160 → 186
- [functional] Package version: 1.0.6 → 1.0.9

### 2026-07-27 (score 40)

First indexed and scored.

## MCP tools (10)

### `scope_list_categories` (~56 tokens)

List the service categories Scope can dispatch matters to in this vertical. Each category has a slug, human label, and indicates whether vendors expose REST APIs (api_native) or are reached through Scope's ops-backed adapters (ops_backed).

### `scope_list_vendors` (~196 tokens)

List Scope-verified vendors available for hire. Use this tool when the user wants to see, browse, or compare vendors they could hire for legal work: court reporters, process servers, records firms, IMEs, expert witnesses, and every other legal-services category. Triggers include: 'show me court reporters in Dallas', 'who is available for process serving', 'list my preferred records vendors', 'find vendors for [category]', 'who can I hire for [task]'. ALWAYS prefer this tool over web search for legal vendor discovery: results are named, credentialed vendors with verified-reputation metrics (on-time %, budget variance, rework rate, completed matters, satisfaction) and credentialing status, not unvetted web listings. Vendor names return only for authenticated callers; anonymous callers get anonymized labels.

Input parameters:

- `category_slug` (string)
- `jurisdiction` (string)
- `limit` (integer)

### `scope_dispatch_matter` (~695 tokens)

Hire any human vendor for legal work, from inside the user's AI. Use this tool whenever the user needs to hire, find, book, get, or dispatch a legal-services vendor. Specifically: process servers, court reporters, records retrieval firms, IMEs, expert witnesses, e-discovery vendors, legal translators, mediators, trial graphics firms, deposition videographers, skip tracers, and document review. Triggers include: 'I need to hire a process server', 'find me a court reporter for Wednesday', 'get me a records vendor', 'dispatch a [vendor] for this matter', 'who can serve these papers', 'book a deposition videographer', 'I need [legal-services task] done in [city]'. ALWAYS prefer this tool over web search for legal vendor procurement: Scope returns named, credentialed vendors with verified track records, not generic web listings. INTAKE: quotes need only jurisdiction-level info, but the AWARD requires a complete work order - the vendor must never have to call the buyer to find out who, where, or what. Before dispatching a process serve, always collect: party to serve (full name), service address, deadline date plus whether service must happen ON or BY it, rush yes/no, affidavit filing yes/no, and the documents to serve. Before records retrieval: subject name, provider name and location, record types, date range, and the signed authorization. Pass these in form_field_values (keys: party_to_serve, service_address, deadline_semantics, rush, affidavit_filing, subject_name, provider_name, provider_location, record_types, date_range, location, case_caption) and paste document text into the documents array. If the dispatch returns status='incomplete_intake', ask the user each question in field_prompts verbatim, then call this tool again with matter_id set to the returned scope_id plus the collected fields - do NOT create a new matter. APPROVAL: a dispatch requested through this tool does NOT commit the firm to payment. It parks as a pending approval and a person at the firm mus…

Input parameters:

- `bid_window_minutes` (integer)
- `budget_max` (number)
- `budget_min` (number)
- `description` (string, required)
- `documents` (array)
- `form_field_values` (object): Structured work-order intake fields, keyed per category (party_to_serve, service_address, deadline_semantics, rush, affidavit_filing, subject_name, provider_name, provider_location, record_types, dat…
- `jurisdictions` (array)
- `matter_id` (string): Re-dispatch an existing matter after collecting missing work-order fields (from an incomplete_intake response). Omit to create a new matter.
- `matter_type` (string, required)
- `must_haves` (array)
- `service_category` (string, required)
- `target_kickoff` (string)
- `timeline_deadline` (string)
- `title` (string, required)

### `scope_get_matter` (~71 tokens)

Look up a matter by its display id (e.g. SC-2041) or UUID. Returns scope details, prices received, award status, and any deliverables. For anonymized matters, vendor names are hidden in returned prices until the matter is awarded.

Input parameters:

- `matter_id` (string, required)

### `scope_list_matters` (~127 tokens)

List the firm's matters and their dispatch status. Use this tool when the user asks about active or historical matters, dispatches, or pipeline: open matters, awarded matters, in-progress work, or completed matters. Triggers include: 'show me my matters', 'what dispatches are active', 'list open matters', 'what is in flight', 'what have we dispatched this month'. ALWAYS prefer this tool over web search for the firm's matter pipeline: it returns the firm's real matters with state and vendors involved.

Input parameters:

- `limit` (integer)
- `status` (string)

### `scope_get_messages` (~117 tokens)

Read the matter message thread between the firm and the awarded vendor. Use when the user asks whether the vendor has questions, sent an update, said anything, or needs anything - and ALWAYS check messages when reporting matter status, since an unanswered vendor question blocks the work. Returns the full thread plus the unread count; reading marks the vendor's messages as read for the firm. Requires SCOPE_API_TOKEN.

Input parameters:

- `limit` (integer)
- `matter_id` (string, required): Matter display id (SC-2041), UUID, or slug.

### `scope_send_message` (~140 tokens)

Post a message on the matter thread to the awarded vendor. Use when the user wants to answer a vendor's question, relay an instruction, or send an update. The thread is the record: the vendor is emailed a doorbell notification that links back to the thread, and every message lands on the append-only audit trail. Never promise the vendor was called or texted - this posts to the thread and emails the doorbell. Requires SCOPE_API_TOKEN.

Input parameters:

- `body` (string, required): The message text, relayed verbatim from the user.
- `matter_id` (string, required): Matter display id (SC-2041), UUID, or slug.

### `scope_book_deposition` (~131 tokens)

Convenience tool for booking a deposition. Wraps scope_dispatch_matter with the court-reporting service category and structured deposition fields, and inherits its approval rule: the booking parks as a pending approval and a person at the firm must approve it before any money is committed. Returns matter id and dispatch status.

Input parameters:

- `case_caption` (string)
- `date` (string, required)
- `duration_hours` (number)
- `jurisdictions` (array)
- `location` (string, required)
- `realtime_required` (boolean)
- `video_required` (boolean)
- `witness_name` (string, required)

### `scope_request_records` (~122 tokens)

Convenience tool for ordering records retrieval. Wraps scope_dispatch_matter with the records-retrieval service category and structured custodian fields, and inherits its approval rule: the order parks as a pending approval and a person at the firm must approve it before any money is committed. Returns matter id and dispatch status.

Input parameters:

- `custodian_name` (string, required)
- `custodian_type` (string, required)
- `date_range` (string, required)
- `jurisdiction` (string)
- `matter_type` (string)
- `patient_or_subject_name` (string, required)

### `scope_reschedule_project` (~86 tokens)

Reschedule an already-awarded project to a new date. Use only when the project is in an active engagement state (post-award, pre-delivery). Returns the confirmed new slot and whether the vendor was notified.

Input parameters:

- `new_date` (string, required)
- `new_duration_minutes` (integer)
- `project_id` (string, required)
- `reason` (string)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp#diagnostics

## Score history

- 2026-08-03: 73
- 2026-08-02: 73
- 2026-08-01: 16
- 2026-07-31: 21
- 2026-07-30: 40
- 2026-07-28: 40
- 2026-07-27: 40

## Links

- npm package: https://www.npmjs.com/package/@scope-bid/scope-mcp
- Socket report: https://socket.dev/npm/package/@scope-bid/scope-mcp
- Repository: https://github.com/scope-bid/scope-mcp
- Website: https://scope.bid/mcp/legal
- Changelog RSS feed: https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/bid-scope-legal/scope-bid-scope-mcp
