# eCFR (pypi · ecfr-mcp)

Electronic Code of Federal Regulations including FAR, DFARS, and agency supplements. 13 tools.

- Trust score: 78/100 (medium)
- Change this week: +18
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- pypi · `ecfr-mcp`: 78/100 (this document), [markdown](https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp.md), [page](https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp)

## Channel facts

- Registry: `pypi`
- Package: `ecfr-mcp`
- Version: `1.0.10`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it.
  - 1 of 34 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 6 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 58/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 2267 tokens (~174/item across 13 items; 13 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 90/100
  - Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the eCFR MCP server?

eCFR runs locally as a PyPI package, launched with uvx ecfr-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add com-1102tools-ecfr-mcp -- uvx ecfr-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "com-1102tools-ecfr-mcp": {
      "command": "uvx",
      "args": [
        "ecfr-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-1102tools-ecfr-mcp": {
      "command": "uvx",
      "args": [
        "ecfr-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add com-1102tools-ecfr-mcp -- uvx ecfr-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-1102tools-ecfr-mcp": {
      "type": "local",
      "command": [
        "uvx",
        "ecfr-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-1102tools-ecfr-mcp --command uvx --arg ecfr-mcp
```

### Hermes

```yaml
mcp_servers:
  com-1102tools-ecfr-mcp:
    command: "uvx"
    args: ["ecfr-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "com-1102tools-ecfr-mcp": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "ecfr-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-1102tools-ecfr-mcp -t stdio -c uvx -a ecfr-mcp
```

### Other

```json
{
  "mcpServers": {
    "com-1102tools-ecfr-mcp": {
      "command": "uvx",
      "args": [
        "ecfr-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 78, +1)

No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 77, +1)

No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 75, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-09-13 (score 60, −14)

- [security regression] Malware scan: pass → unverified
- [functional] Package version: 1.0.6 → 1.0.10
- [functional] Package version: 1.0.6 → 1.0.9
- [functional] Package version: 1.0.6 → 1.0.8

### 2026-09-11 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (13)

### `get_latest_date` (~142 tokens)

Get the most recent available date for a CFR title.

CRITICAL: eCFR lags 1-2 business days behind the Federal Register.
Using today's date on versioner endpoints causes 404 errors. Call this
first to get the safe date, then pass it to other tools.

Default title 48 = Federal Acquisition Regulations System (FAR, DFARS,
and all agency supplements). Other common titles: 2 (Grants/Agreements),
5 (Administrative Personnel), 29 (Labor), 41 (Public Contracts).

Raises ValueError for titles 1-50 that are reserved (no content).

Input parameters:

- `title_number` (integer)

### `get_cfr_content` (~391 tokens)

Get the full text of a CFR section, subpart, part, or appendix.

This is the primary workhorse for reading regulatory text. Returns
parsed clean text by default (heading, paragraphs, citations, plus
tables and editorial_notes when present). Set raw_xml=True to get the
original XML instead.

Specify the narrowest scope possible to keep responses manageable:
\- section='15.305' for a single FAR section
\- subpart='15.3' for a subpart
\- part='15' for an entire part (can be large)
\- chapter='1' for an entire chapter (often >1 MB, avoid)
\- appendix='Appendix A to Chapter 2' (with chapter='2') for a DFARS appendix

Date auto-resolves to the latest available if not provided. Do NOT use
today's date directly -- eCFR lags 1-2 business days and today often 404s.

Title 48 = FAR/DFARS. Chapter 1 = FAR (Parts 1-99), Chapter 2 = DFARS
(Parts 200-299). Other chapters = agency FAR supplements (GSAR, VAAR,
HSAR, etc.).

For DFARS clauses, use chapter='2' (e.g., section='252.227-7014').

part/subpart/section accept int or string. Common prefix mistakes like
section='FAR 15.305' or '48 CFR 15.305' are stripped automatically, and
trailing paragraph cites like section='15.305(a)(2)' resolve to the base
section '15.305'.

Input parameters:

- `appendix`
- `chapter`
- `date`
- `part`
- `raw_xml` (boolean)
- `section`
- `subpart`
- `title_number` (integer)

### `get_cfr_structure` (~181 tokens)

Get the hierarchical table of contents for a CFR title or subset.

Returns a nested tree of titles, chapters, parts, subparts, and sections
with identifiers, descriptions, and byte sizes.

IMPORTANT: Does NOT support section-level filtering (returns 400).
Use part or subpart, then walk the children to find sections.

Common patterns:
\- chapter='1' for all FAR parts
\- chapter='2' for all DFARS parts
\- part='15' for FAR Part 15 structure
\- subpart='15.3' for just that subpart's sections

part/subpart/chapter/appendix accept int or string.

Input parameters:

- `appendix`
- `chapter`
- `date`
- `part`
- `subchapter`
- `subpart`
- `title_number` (integer)

### `get_version_history` (~130 tokens)

Get the version history of a CFR section, subpart, or part.

Returns a list of content versions with dates, amendment info, and
whether each version was a substantive text change vs editorial.

The 'substantive' field is key: True = the regulatory text actually
changed. False = only editorial/formatting change.

History goes back to January 2017 only. Pre-2017 changes are not tracked.

part/subpart/section accept int or string.

Input parameters:

- `part`
- `section`
- `subpart`
- `title_number` (integer)

### `get_ancestry` (~106 tokens)

Get the breadcrumb hierarchy path for a section, part, or appendix.

Returns ancestors from title down to the target node: title > chapter >
subchapter > part > subpart > section. Useful for understanding where
a section sits in the CFR hierarchy and what regulation it belongs to.

part/section/appendix accept int or string.

Input parameters:

- `appendix`
- `date`
- `part`
- `section`
- `title_number` (integer)

### `search_cfr` (~302 tokens)

Full-text search across the Code of Federal Regulations.

Returns matching sections with excerpts, headings, scores, and hierarchy.

CRITICAL: Set current_only=True (default) to search only in-effect text.
Without it, search returns ALL historical versions including superseded,
so a section amended 5 times appears 5 times.

Search caps at 10,000 total results. Use hierarchy filters (title,
chapter, part) to narrow if you hit the cap.

order controls result ordering: 'relevance' (default), 'newest_first',
'oldest_first', 'hierarchy', or 'citations'.

agency_slugs filters to one or more agencies (single slug string or a
list, e.g. 'defense-acquisition-regulations-system'). Use list_agencies()
to find slugs.

last_modified_after/before use YYYY-MM-DD format and filter by the
date sections were last amended. Useful for finding recent regulatory changes.

per_page accepts 1 to 5000 (default 20); paginate with page for more.

Input parameters:

- `agency_slugs`
- `chapter`
- `current_only` (boolean)
- `last_modified_after`
- `last_modified_before`
- `order`
- `page` (integer)
- `part`
- `per_page` (integer)
- `query` (string, required)
- `section`
- `subpart`
- `title`

### `list_agencies` (~141 tokens)

List all agencies with their CFR title and chapter references.

Returns agency names, slugs, and which CFR titles/chapters they own.
Useful for finding which chapter corresponds to an agency's FAR supplement.

summary_only (default True) strips the `children` and most of
\`cfr_references` to keep the response compact (~20 KB vs ~100 KB).
References owned by child agencies are merged into the parent row, so
chapter lookups like DFARS (chapter 2, on a DoD child agency) still work
in summary mode. Set False for the full raw payload including children.

Input parameters:

- `summary_only` (boolean)

### `get_corrections` (~126 tokens)

Get editorial corrections for a CFR title.

Returns a list of corrections with CFR references, corrective actions,
error dates, and FR citations. Useful for checking whether a section's
current text has been corrected since its last amendment.

limit caps the number of corrections returned (default 50, max 1000).
since_year further filters to corrections with year >= since_year.
Title 48 has ~280 corrections across all years; use since_year to
focus on recent ones.

Input parameters:

- `limit` (integer)
- `since_year`
- `title_number` (integer)

### `lookup_far_clause` (~177 tokens)

Convenience tool: look up the current text of a FAR or DFARS clause.

Pass a section identifier like '15.305', '52.212-4', '2.101', etc.
Default chapter='1' (FAR). Use chapter='2' for DFARS (e.g., '252.227-7014').

Auto-resolves the latest available date. Returns parsed clean text
with heading, paragraphs, and citations.

Common FAR sections: 2.101 (Definitions), 9.104-1 (Responsibility),
15.305 (Proposal Evaluation), 19.502-2 (Small Business Set-Asides),
52.212-4 (Commercial Terms), 52.212-5 (Required Commercial Terms).

Input parameters:

- `chapter`
- `date`
- `section_id` (required)

### `compare_versions` (~172 tokens)

Compare the text of a CFR section at two different dates.

Useful for understanding what changed in a regulatory amendment. Returns
the parsed text at both dates side by side. You can then diff the
paragraphs to identify specific changes.

Dates must be in YYYY-MM-DD format and within the eCFR's tracking range
(January 2017 to present). Both dates must not exceed the title's
up_to_date_as_of value.

This tool always returns the section-level XML parsed -- pass a small
section_id like '15.305', not a whole part. Whole-part comparisons can
exceed 100 KB per side.

Input parameters:

- `chapter`
- `date_after` (string, required)
- `date_before` (string, required)
- `section_id` (required)
- `title_number` (integer)

### `list_sections_in_part` (~101 tokens)

List all sections in a FAR/DFARS part with their headings.

Returns a flat list of sections extracted from the structure tree.
Useful for understanding the scope of a FAR part before drilling into
specific sections.

Default chapter='1' (FAR). Use chapter='2' for DFARS.

part_number accepts int or string.

Input parameters:

- `chapter`
- `date`
- `part_number` (required)
- `title_number` (integer)

### `find_far_definition` (~150 tokens)

Search for a term's definition in FAR 2.101 (master definition section).

FAR 2.101 contains definitions used throughout the Federal Acquisition
Regulation. This tool fetches the full section and searches for paragraphs
containing the term, returning matching paragraphs with surrounding context.

Note: FAR 2.101 is large (~109KB XML). This tool parses the full section
server-side and returns only matching paragraphs.

term must be at least 3 characters. max_matches caps returned matches
(default 20, max 100); common terms like 'offeror' hit many paragraphs.

Input parameters:

- `date`
- `max_matches` (integer)
- `term` (string, required)

### `find_recent_changes` (~148 tokens)

Find CFR sections that have been modified since a given date.

Uses the search API with last_modified_on_or_after filter to find
sections amended after the specified date. Returns section identifiers,
headings, and excerpts, most recently amended first.

since_date must be in YYYY-MM-DD format. Results are capped at 10,000
by the API. Use title/chapter/part filters to narrow if needed.

Common pattern: find FAR changes since a specific date to check for
regulatory updates that might affect ongoing acquisitions.

Input parameters:

- `chapter`
- `part`
- `per_page` (integer)
- `since_date` (string, required)
- `title` (integer)

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp#diagnostics

## Score history

- 2026-09-20: 78
- 2026-09-19: 77
- 2026-09-18: 77
- 2026-09-17: 76
- 2026-09-16: 76
- 2026-09-15: 75
- 2026-09-14: 75
- 2026-09-13: 60
- 2026-09-12: 74
- 2026-09-11: 74
- 2026-09-10: 73
- 2026-09-09: 73
- 2026-09-08: 72
- 2026-09-07: 72
- 2026-09-06: 71
- 2026-09-05: 71
- 2026-09-04: 70
- 2026-09-03: 70
- 2026-09-02: 69
- 2026-09-01: 69
- 2026-08-31: 65
- 2026-08-30: 65
- 2026-08-29: 65
- 2026-08-28: 65
- 2026-08-27: 65
- 2026-08-26: 65
- 2026-08-25: 63
- 2026-08-24: 63

## Common questions

### What is the eCFR MCP server?

eCFR is an MCP server listed in the public MCP registry as com.1102tools/ecfr-mcp. Electronic Code of Federal Regulations including FAR, DFARS, and agency supplements. 13 tools. This page covers its PyPI package (ecfr-mcp).

### Is the eCFR MCP server safe to use?

eCFR scores 78 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the eCFR MCP server expose?

eCFR exposes 13 tools: get_latest_date, get_cfr_content, get_cfr_structure, get_version_history, get_ancestry, and 8 more. Their descriptions and schemas cost roughly 2,267 tokens of context every time the server is loaded.

### Is the eCFR MCP server still maintained?

eCFR is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the eCFR MCP server under?

eCFR declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- PyPI project: https://pypi.org/project/ecfr-mcp/
- Socket report: https://socket.dev/pypi/package/ecfr-mcp
- Repository: https://github.com/1102tools-dev/federal-contracting-mcps
- Website: https://1102tools.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-1102tools-ecfr-mcp/ecfr-mcp
