Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.cliwant/mcp-sam-gov

NPM · @CLIWANT/MCP-SAM-GOV · SCANNED AUG 8

Keyless MCP: 150 tools for US federal + state/local (SLED) contracting, spending & regulation

+34 this week 54 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 30 of 97 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to cliwant/mcp-sam-gov). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 14 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability0
  • Schema quality not yet verified: the captured schema was too large for us to store in full, so we will not judge it on a partial copy.Unverified
Stability & Change Management0
  • Stability not yet verified: the captured schema was too large for us to store in full, and comparing a partial copy would report our own trimming as a change.Unverified
Tool Coverage0
  • Tool coverage not yet verified: the captured tool definitions were too large for us to store in full, so we will not judge them on a partial copy.Unverified
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 3 categories

Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @cliwant/mcp-sam-gov

# add to Claude Code
claude mcp add cliwant-mcp-sam-gov -- npx -y @cliwant/mcp-sam-gov
# add to Codex CLI
codex mcp add cliwant-mcp-sam-gov -- npx -y @cliwant/mcp-sam-gov
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cliwant-mcp-sam-gov": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@cliwant/mcp-sam-gov"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cliwant-mcp-sam-gov --command npx --arg -y --arg @cliwant/mcp-sam-gov
# ~/.hermes/config.yaml
mcp_servers:
  cliwant-mcp-sam-gov:
    command: "npx"
    args: ["-y", "@cliwant/mcp-sam-gov"]
// mcp.json
{
  "mcpServers": {
    "cliwant-mcp-sam-gov": {
      "command": "npx",
      "args": [
        "-y",
        "@cliwant/mcp-sam-gov"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 8 Aug 26 0
    • Security disclosure: fail → pass functional
  • 7 Aug 26 +3
    • Known CVEs: partial → pass security
    • Dependency health: partial → 0.86 functional
  • 5 Aug 26 +2
    • CVE-2026-69207 no longer affects this package security
    • Known CVEs: fail → partial security
  • 4 Aug 26 −2
    • CVE-2026-69207 affects this package: medium security
    • Known CVEs: partial → fail security
  • 2 Aug 26 +31
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • Known CVEs: unverified → partial security
    • Stability: Stability not yet verified: the captured schema was too large for us to store in full, and comparing a partial copy would report our own trimming as a change. security
    • The attested source repository moved: cliwant/mcp-sam-gov security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • MCP protocol: unverified → pass functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Licence: MIT functional
  • 1 Aug 26 +14
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −18
    • Malware scan: pass → unverified security
  • 27 Jul 26 24

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 8 Aug 2026 · Analysed npm/@cliwant/[email protected]

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo cliwant/mcp-sam-gov
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/cliwant/mcp-sam-gov/.github/workflows/release.yml@refs/tags/v1.12.0
Rekor log index 2231949115
Predicate type https://slsa.dev/provenance/v1
Subject digest sha512:6220bf8cb05325fb97084ba021a7901dd1a7a6f6d0c39960afde27cbcdcd35fa6daa123bae2c0e9a6cba6f42dc1b69280573bfebc2f341b6e70b9938b
Dependencies 97 packages
Packages resolved 97
Stale 30
Tree resolution Complete
MCP tools · 150 exposed · ~69,302 tokens partial

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
api_key_status ~268

No description provided.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

arcgis_feature_query ~997

No description provided.

NameTypeReqDescription
limitnumber
offsetnumber
orderByFieldsstring
outFieldsstring
servicestringyes
wherestring

No output schema declared.

No examples provided.

arcgis_hub_discover_datasets ~637

No description provided.

NameTypeReqDescription
limitnumber
offsetnumber
openDataOnlyboolean
querystringyes

No output schema declared.

No examples provided.

bea_regional_data ~788

No description provided.

NameTypeReqDescription
frequencystring
geoFipsstringyes
lineCodestringyes
tableNamestringyes
yearstring

No output schema declared.

No examples provided.

bls_oews_wages ~1,055

No description provided.

NameTypeReqDescription
areaarray
datatypearray
occupationarray
socarray

No output schema declared.

No examples provided.

bls_qcew ~1,400

No description provided.

NameTypeReqDescription
aggregationLevelstring
areastring
industrystring
limitnumber
modestringyes
offsetnumber
ownershipstring
quarterstringyes
sizeCodestring
yearnumberyes

No output schema declared.

No examples provided.

bls_timeseries ~1,059

No description provided.

NameTypeReqDescription
endYearnumber
seriesarray
seriesIdarray
startYearnumber

No output schema declared.

No examples provided.

bonfire_list_organizations ~311

No description provided.

NameTypeReqDescription
limitnumber
offsetnumber
querystring
statestring

No output schema declared.

No examples provided.

bonfire_search_opportunities ~397

No description provided.

NameTypeReqDescription
limitnumber
offsetnumber
orgstringyes

No output schema declared.

No examples provided.

cbp_border_wait_times ~461

No description provided.

NameTypeReqDescription
borderstring
limitnumber
offsetnumber
portNamestring

No output schema declared.

No examples provided.

census_business_patterns ~710

No description provided.

NameTypeReqDescription
geographystring
limitnumber
naicsstring
statestring
yearstring

No output schema declared.

No examples provided.

census_geocode_address ~674

No description provided.

NameTypeReqDescription
addressstringyes
benchmarkstring
vintagestring

No output schema declared.

No examples provided.

census_geographies_by_coordinates ~646

No description provided.

NameTypeReqDescription
benchmarkstring
latitudenumber
longitudenumber
vintagestring
xnumber
ynumber

No output schema declared.

No examples provided.

cisa_kev_lookup ~605

No description provided.

NameTypeReqDescription
addedSincestring
cveIdstring
dueBeforestring
limitnumber
offsetnumber
productstring
ransomwareOnlyboolean
vendorProjectstring

No output schema declared.

No examples provided.

ckan_discover_datasets ~236

No description provided.

NameTypeReqDescription
hoststringyes
limitnumber
qstringyes

No output schema declared.

No examples provided.

ckan_query ~516

No description provided.

NameTypeReqDescription
filtersstring
hoststringyes
limitnumber
offsetnumber
qstring
resourceIdstringyes
sortstring

No output schema declared.

No examples provided.

clinicaltrials_facet_counts ~724

No description provided.

NameTypeReqDescription
fieldsarrayyes

No output schema declared.

No examples provided.

clinicaltrials_get_study ~246

No description provided.

NameTypeReqDescription
nctIdstringyes

No output schema declared.

No examples provided.

clinicaltrials_search_studies ~1,078

No description provided.

NameTypeReqDescription
conditionstring
funderTypestring
locationstring
overallStatusstring
pageSizenumber
pageTokenstring
query.termstring
sponsorstring

No output schema declared.

No examples provided.

cms_dmepos_suppliers ~624

No description provided.

NameTypeReqDescription
npistring
offsetnumber
sizenumber
statestring

No output schema declared.

No examples provided.

cms_facility_directory ~677

No description provided.

NameTypeReqDescription
facilityNamestring
facilityTypestringyes
offsetnumber
sizenumber
statestring

No output schema declared.

No examples provided.

cms_hospital_compare ~627

No description provided.

NameTypeReqDescription
facilityNamestring
hospitalTypestring
offsetnumber
sizenumber
statestring

No output schema declared.

No examples provided.

cms_medicare_provider_services ~757

No description provided.

NameTypeReqDescription
hcpcsCodestring
npistring
offsetnumber
providerTypestring
sizenumber
statestring

No output schema declared.

No examples provided.

cms_query_dataset ~908

No description provided.

NameTypeReqDescription
conditionsarray
datasetIdstringyes
indexnumber
limitnumber
offsetnumber
propertiesarray
resultsboolean

No output schema declared.

No examples provided.

cms_revoked_providers ~595

No description provided.

NameTypeReqDescription
lastNamestring
npistring
offsetnumber
sizenumber
statestring

No output schema declared.

No examples provided.

cms_search_datasets ~406

No description provided.

NameTypeReqDescription
limitnumber
offsetnumber
qstring

No output schema declared.

No examples provided.

congress_get_bill ~161

No description provided.

NameTypeReqDescription
billNumbernumberyes
billTypestringyes
congressnumberyes

No output schema declared.

No examples provided.

congress_search_bills ~439

No description provided.

NameTypeReqDescription
billTypestring
congressnumber
fromDateTimestring
limitnumber
offsetnumber
querystring
toDateTimestring

No output schema declared.

No examples provided.

courtlistener_search_opinions ~963

No description provided.

NameTypeReqDescription
courtstring
cursorstring
dateFiledAfterstring
dateFiledBeforestring
natureOfSuitstring
orderstring
querystring

No output schema declared.

No examples provided.

cpsc_recalls ~626

No description provided.

NameTypeReqDescription
dateEndstring
dateStartstring
manufacturerstring
productNamestring
recallNumberstring

No output schema declared.

No examples provided.

cve_lookup ~1,129

No description provided.

NameTypeReqDescription
cpeNamestring
cveIdstring
cvssV3Severitystring
kevOnlyboolean
keywordstring
lastModEndDatestring
lastModStartDatestring
pubEndDatestring
pubStartDatestring
resultsPerPagenumber
startIndexnumber

No output schema declared.

No examples provided.

datagov_search_datasets ~610

No description provided.

NameTypeReqDescription
cursorstring
limitnumber
organizationstring
querystring

No output schema declared.

No examples provided.

dol_get_dataset ~766

No description provided.

NameTypeReqDescription
agencystringyes
fieldsarray
filterFieldstring
filterValuestring
limitnumber
offsetnumber
tablestringyes

No output schema declared.

No examples provided.

dol_list_datasets ~483

No description provided.

NameTypeReqDescription
agencystring
limitnumber
offsetnumber
querystring

No output schema declared.

No examples provided.

ecfr_get_section ~403

No description provided.

NameTypeReqDescription
datestring
sectionstringyes
titleNumbernumberyes

No output schema declared.

No examples provided.

ecfr_list_titles ~56

No description provided.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

ecfr_search ~172

No description provided.

NameTypeReqDescription
perPagenumber
querystringyes
titleNumbernumber

No output schema declared.

No examples provided.

echo_facility_report ~190

No description provided.

NameTypeReqDescription
registryIdstringyes

No output schema declared.

No examples provided.

echo_search_facilities ~647

No description provided.

NameTypeReqDescription
facilityNamestring
federalOnlyboolean
limitnumber
majorOnlyboolean
naicsstring
offsetnumber
sicstring
statestringyes

No output schema declared.

No examples provided.

edgar_company_concept ~1,103

No description provided.

NameTypeReqDescription
canonicalOnlyboolean
cikOrTickerstringyes
conceptstringyes
formstring
fynumber
limitnumber
offsetnumber
taxonomystring
unitstring

No output schema declared.

No examples provided.

edgar_company_facts ~369

No description provided.

NameTypeReqDescription
cikOrTickerstringyes
conceptsarray
latestboolean
unitstring

No output schema declared.

No examples provided.

edgar_company_filings ~647

No description provided.

NameTypeReqDescription
cikOrTickerstringyes
formsarray
fullHistoryboolean
limitnumber
maxShardsnumber
offsetnumber

No output schema declared.

No examples provided.

edgar_daily_filing_index ~834

No description provided.

NameTypeReqDescription
cikstring
companyContainsstring
datestringyes
formTypestring
limitnumber
offsetnumber

No output schema declared.

No examples provided.

edgar_filing_index ~835

No description provided.

NameTypeReqDescription
cikstring
companyContainsstring
dateFromstring
dateTostring
formTypestring
limitnumber
offsetnumber
quarternumberyes
yearnumberyes

No output schema declared.

No examples provided.

edgar_full_text_search ~553

No description provided.

NameTypeReqDescription
ciksarray
enddtstring
entityNamestring
formsarray
fromnumber
qstringyes
startdtstring

No output schema declared.

No examples provided.

edgar_lookup_cik ~175

No description provided.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

edgar_xbrl_frames ~780

No description provided.

NameTypeReqDescription
includeStatsboolean
limitnumber
offsetnumber
periodstringyes
tagstringyes
taxonomystring
unitstring

No output schema declared.

No examples provided.

epa_tri_facilities ~574

No description provided.

NameTypeReqDescription
countystring
facilityNamestring
limitnumber
offsetnumber
statestring

No output schema declared.

No examples provided.

fac_get_findings ~658

No description provided.

NameTypeReqDescription
auditYearnumber
auditeeUeistring
limitnumber
offsetnumber
reportIdstring

No output schema declared.

No examples provided.

fac_search_audits ~717

No description provided.

NameTypeReqDescription
auditYearnumber
auditeeStatestring
auditeeUeistring
limitnumber
offsetnumber
totalExpendedMaxnumber
totalExpendedMinnumber

No output schema declared.

No examples provided.