io.github.cyanheads/sanctions-screening-mcp-server
REMOTE · SANCTIONS-SCREENING.CASEYJHAND.COM · 2 COMPONENTS · SCANNED SEP 28
Screen names against OFAC, EU, UK, UN sanctions lists; resolve entities via GLEIF. Screening aid.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2566 tokens (~320/item across 8 items; 7 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.cyanheads/sanctions-screening-mcp-server server?
io.github.cyanheads/sanctions-screening-mcp-server is a hosted endpoint at https://sanctions-screening.caseyjhand.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · sanctions-screening.caseyjhand.com
claude mcp add --transport http cyanheads-sanctions-screening-mcp-server 'https://sanctions-screening.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-sanctions-screening-mcp-server": {
"url": "https://sanctions-screening.caseyjhand.com/mcp"
}
}
} {
"servers": {
"cyanheads-sanctions-screening-mcp-server": {
"type": "http",
"url": "https://sanctions-screening.caseyjhand.com/mcp"
}
}
} [mcp_servers.cyanheads-sanctions-screening-mcp-server] url = "https://sanctions-screening.caseyjhand.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cyanheads-sanctions-screening-mcp-server": {
"type": "remote",
"url": "https://sanctions-screening.caseyjhand.com/mcp",
"enabled": true
}
}
} openclaw mcp add cyanheads-sanctions-screening-mcp-server --url 'https://sanctions-screening.caseyjhand.com/mcp' --transport streamable-http
mcp_servers:
cyanheads-sanctions-screening-mcp-server:
url: "https://sanctions-screening.caseyjhand.com/mcp" {
"McpServers": {
"cyanheads-sanctions-screening-mcp-server": {
"Transport": "http",
"Url": "https://sanctions-screening.caseyjhand.com/mcp"
}
}
} assistant mcp add cyanheads-sanctions-screening-mcp-server -t streamable-http -u 'https://sanctions-screening.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-sanctions-screening-mcp-server": {
"type": "http",
"url": "https://sanctions-screening.caseyjhand.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 −1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “sanctions_list_sources” rewrote its description, which is the text the model reads security
- Tool “sanctions_resolve_entity” rewrote its description, which is the text the model reads security
- Tool “sanctions_trace_ownership” rewrote its description, which is the text the model reads security
- Tool “sanctions_get_designation” rewrote its description, which is the text the model reads security
- Schema quality: 255 → 320 ▼ functional
- Schema quality: 255 → 292 ▼ functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- Server version: 0.3.0 → 0.4.0 functional
- Server version: 0.2.0 → 0.3.0 functional
- New tool “sanctions_screen_identifier” functional
- “sanctions_resolve_entity” reworded the description of “jurisdiction” cosmetic
- “sanctions_resolve_entity” reworded the description of “status” cosmetic
- “sanctions_trace_ownership” reworded the description of “screenNodes” cosmetic
- “sanctions_get_designation” reworded the description of “entryId” cosmetic
- 24 Sept 26 0
- Server version: 0.1.12 → 0.2.0 functional
- “sanctions_screen_name” reworded the description of “name” cosmetic
- “sanctions_resolve_entity” reworded the description of “name” cosmetic
- 20 Sept 26 0
- Server version: 0.1.11 → 0.1.12 functional
- 9 Sept 26 +1
- Stability: 0.97 → pass security
- 7 Sept 26 −1
- Stability: pass → 0.93 functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- MCP protocol version: 2025-11-25 → 2026-07-28 functional
- Server version: 0.1.10 → 0.1.11 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://sanctions-screening.caseyjhand.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=caseyjhand.com | CN=WE1,O=Google Trust Services,C=US | 4 Sept 2026 | 3 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | a6985204ed51ae050e7738aa6be668e9 |
| SANs: caseyjhand.com, *.caseyjhand.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of sanctions-screening.caseyjhand.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| caseyjhand.com. | present | 2371 | 13 | Verified |
| sanctions-screening.caseyjhand.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://sanctions-screening.caseyjhand.com/mcp | Verified | 200 | |
| http (plaintext) | http://sanctions-screening.caseyjhand.com/mcp | HTTPS enforced | 301 | https://sanctions-screening.caseyjhand.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
sanctions_get_designation sanctions-screening-mcp-server: get designation ~271
Fetch the full record for one sanctions designation by source list + entry ID or the list's published reference number — the drill-in after sanctions_screen_name or sanctions_screen_identifier surfaces a candidate, or the lookup for a reference a notice cites (UN QDe.004, EU EU.27.28, UK OFSI Group ID). Returns all published aliases, identifiers (passport, national ID, tax and registration numbers, SWIFT/BIC codes, digital-currency addresses, vessel call signs, aircraft tail and serial numbers, phone numbers, email addresses, websites), addresses, dates and places of birth at the precision the source published, nationalities, sanctioning program, legal basis, and designation date. The record reflects exactly what the source published; missing fields mean the source omitted them. This is a screening aid — the designation record supports a compliance review, it is not itself a determination.
| Name | Type | Req | Description |
|---|---|---|---|
| entryId | string | yes | The source list's own entry ID (the sourceEntryId from sanctions_screen_name), or the reference number the list publishes for the entry (UN QDe.004, EU EU.27.28, UK OFSI Group ID 14196). Matched trim… |
| source | string | yes | Which source list the entry belongs to. |
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | – | Published addresses. |
| aliases | array | – | All published aliases / name variants. |
| caveat | string | – | Decision-support caveat — this is a screening aid, not a compliance determination. |
| datesOfBirth | array | – | Published dates and places of birth (persons). |
| designationDate | string | – | The source's own designation date as YYYY-MM-DD; absent when unpublished. |
| entityType | string | – | Entity classification as published. |
| error | object | – | Present when the call failed. Absent on success. |
| identifiers | array | – | Published identifiers: identity documents (passport, national ID, tax, registration) and, where the source publishes them, SWIFT/BIC codes, digital-currency addresses, vessel call signs, aircraft tai… |
| legalBasis | string | – | Statutory / regulatory basis, when published. |
| nationalities | array | – | Published nationalities / citizenships. |
| primaryName | string | – | Primary published name. |
| program | string | – | Sanctioning program / regime, when published. |
| referenceNumber | string | – | The list's published reference number (UN, EU, UK OFSI Group ID); absent when the list publishes none for the entry. OFAC publishes none — its entry ID is its published number. |
| remarks | string | – | Free-form remarks published by the source, when present. |
| source | string | – | Source list the entry belongs to. |
| sourceEntryId | string | – | The source list's own entry ID. |
| sourceLabel | string | – | Human-readable name of the source list. |
No examples provided.
sanctions_get_entity sanctions-screening-mcp-server: get entity ~207
Fetch the full GLEIF Level 1 record for one LEI: legal name, other/trading names, legal and headquarters addresses, registration status, jurisdiction, registration authority and ID, and last-update date — plus any sanctions hits screened against the same legal name across all loaded watchlists. The screening cross-reference is a screening AID: a hit is a candidate to verify against the official source, and no hit is not a clearance. screeningStatus says whether that cross-reference actually ran — an empty sanctionsHits under not_ready means the sanctions mirror was unavailable, not that nothing matched. sanctionsScreen says whether the hit list is the whole set: it reports how many potential matches existed before the cap, so a capped cross-reference is distinguishable from a complete one. LEI must be a 20-character GLEIF identifier (18 alphanumerics + 2 check digits).
| Name | Type | Req | Description |
|---|---|---|---|
| lei | string | yes | The 20-character GLEIF Legal Entity Identifier to look up. |
| Name | Type | Req | Description |
|---|---|---|---|
| alternateNames | array | – | Every other and transliterated name with its type, in the order published — the typed view of otherNames plus the ASCII transliterations of a legal name in another script. |
| caveat | string | – | Decision-support caveat — the screening cross-reference is an aid, not a determination. |
| error | object | – | Present when the call failed. Absent on success. |
| headquartersAddress | string | – | Single-line headquarters address, when published. |
| jurisdiction | string | – | Legal jurisdiction (ISO code), when published. |
| lastUpdate | string | – | ISO 8601 last-update timestamp from the LEI record. |
| legalAddress | string | – | Single-line legal address, when published. |
| legalName | string | – | Registered legal name. |
| lei | string | – | The 20-character GLEIF Legal Entity Identifier. |
| otherNames | array | – | Other names published in the LEI record (trading, previous, and alternative-language legal names), as plain strings. |
| registrationAuthorityEntityId | string | – | The entity's ID at its registration authority, when published. |
| registrationAuthorityId | string | – | Registration authority (RA) code, when published. |
| sanctionsHits | array | – | Sanctions screening cross-reference on the entity's legal name. |
| sanctionsScreen | object | – | Disclosure for the cross-reference screen: how many potential matches existed before the cap, and whether sanctionsHits is the complete set. Present only when screeningStatus is 'screened'. |
| screeningStatus | string | – | Whether the cross-reference ran: screened = the legal name was screened against every loaded watchlist; not_ready = the sanctions mirror has never synced, so no screening ran and the empty sanctionsH… |
| status | string | – | Registration status (e.g. ISSUED, LAPSED). |
No examples provided.
sanctions_list_sources sanctions-screening-mcp-server: list sources ~131
List the sanctions watchlists (OFAC SDN + Consolidated, EU, UK, UN) and GLEIF datasets currently loaded in the local mirror, each with its record count, source URL, license, and the mirror's readiness and as-of timestamp — for GLEIF, also whether its reporting exceptions are loaded and how many. Use this for provenance and freshness on any result — results are only as current as the last mirror refresh, and a not-ready mirror means screening cannot run yet. Attribution: UK data is under the Open Government Licence v3.0; all sources are cited here.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| error | object | – | Present when the call failed. Absent on success. |
| leiAsOf | string | – | ISO 8601 timestamp of the last completed GLEIF sync, when available. |
| leiReady | boolean | – | True once the GLEIF (LEI) mirror has completed at least one full sync. |
| reportingExceptionsLoaded | boolean | – | Whether GLEIF reporting exceptions are loaded. When false, sanctions_trace_ownership reads a parent level with no published relationship as unknown. |
| sanctionsAsOf | string | – | ISO 8601 timestamp of the last completed sanctions sync, when available. |
| sanctionsReady | boolean | – | True once the sanctions mirror has completed at least one full sync. |
| sources | array | – | All loaded sources, sanctions lists then the GLEIF dataset. |
No examples provided.
sanctions_resolve_entity sanctions-screening-mcp-server: resolve entity ~541
Resolve a company or organization name (with an optional jurisdiction: a country code, which includes its subdivisions, or an ISO 3166-2 subdivision code) to candidate GLEIF Legal Entity Identifiers (LEIs), ranked. This turns a free-text counterparty name into a stable global identifier that sanctions_get_entity and sanctions_trace_ownership key off. Every name GLEIF publishes takes part: the legal name, previous legal names, trading names, alternative-language legal names, and ASCII transliterations of a legal name in another script — each candidate reports the name it matched on and that name's type, one candidate per LEI. Strict mode (default) matches exact-normalized then all-tokens-present; fuzzy mode (or auto when strict is empty) adds Jaro-Winkler scoring labeled approximate with a raw 0–1 score plus the count of query tokens the matched name covers, which orders candidates that tie on score. Results are paged: totalAvailable and hasMore report candidates beyond the returned page, and nextOffset retrieves them. Returns potential matches to confirm against the GLEIF record — name resolution is a candidate ranking, not an authoritative identification.
| Name | Type | Req | Description |
|---|---|---|---|
| jurisdiction | – | – | Optional legal-jurisdiction filter. A country code ("US") matches that country and every subdivision under it (US-DE, US-CA); a subdivision code ("US-DE") matches exactly. Case-insensitive. Empty str… |
| limit | integer | – | Maximum LEI candidates to return in one page. |
| matchMode | string | – | strict (default): exact then all-tokens-present. fuzzy: also scored Jaro-Winkler. |
| minScore | number | – | Jaro-Winkler floor for fuzzy hits (0–1); defaults to the server's configured floor. |
| name | string | yes | The company / organization name to resolve to an LEI, in any script. It must contain at least one letter or digit, and at most 64 words and 1024 characters. |
| offset | integer | – | Zero-based index of the first LEI candidate to return. Re-call with the returned nextOffset to page through every candidate when hasMore is true; an offset past the end returns an empty page, not an… |
| status | string | – | Registration status filter. issued (default) matches ISSUED; lapsed matches exactly LAPSED; any applies no filter and is the only value that reaches the other states (RETIRED, DUPLICATE, ANNULLED, PE… |
| Name | Type | Req | Description |
|---|---|---|---|
| error | object | – | Present when the call failed. Absent on success. |
| hasMore | boolean | – | True when LEI candidates remain beyond this page — re-call with nextOffset. |
| matchModeUsed | string | – | The match mode actually applied (strict may upgrade to fuzzy). |
| matches | array | – | LEI candidates, ranked by match type, then score, then how much of the query each matched name explains. |
| nextOffset | number | – | The offset to request next. Present only when hasMore is true. |
| normalizedQuery | string | – | The name as the server folded it for matching. |
| notice | string | – | Guidance when no LEI matched and how to broaden, when the requested offset sits past the end of the result set, or when the mirror has not indexed GLEIF's other and transliterated names yet, so only… |
| totalAvailable | number | – | LEI candidates available across all pages, before limit and offset were applied. |
| totalAvailableBasis | string | – | How to read totalAvailable: exact = the complete strict candidate set; lower_bound = a bounded scan produced it (every fuzzy pass, and any strict pass that hit the raw-row scan cap), so more may exis… |
| totalCount | number | – | Number of LEI candidates returned in this page. |
No examples provided.
sanctions_screen_identifier sanctions-screening-mcp-server: screen identifier ~391
Look up an identifier — a vessel IMO number, a SWIFT/BIC code, a digital-currency wallet address, a passport or national ID number, or any other identifier a list publishes — against all loaded sanctions watchlists at once: OFAC SDN + Consolidated, EU, UK, and UN. Exact match after normalization, with no fuzzy or partial matching and no score: spacing, letter case, and the separators - . / are ignored, an IMO number matches with or without its IMO prefix, a SWIFT/BIC code compares on its first eight characters so a branch code matches its institution, and a wallet address folds case only where its encoding is case-insensitive (hex, bech32, cashaddr — never base58). Returns every designation that publishes a matching identifier, one per designation, with the identifiers that matched as published; sanctions_get_designation pulls the full record. This is a screening AID for a human/compliance review, NOT a compliance determination: a hit means "review this candidate against the official source," and an empty result never means "cleared" — an identifier a list prints only in free-text remarks, or bundled with other numbers in one field, does not match.
| Name | Type | Req | Description |
|---|---|---|---|
| sources | array | – | Restrict to specific source lists. Omit to search all loaded lists. |
| type | string | – | Restrict to one identifier category, matched on the label each list publishes, or "any" (default) to search every published identifier, including categories with no name here (MMSI, call signs, tail… |
| value | string | yes | The identifier to look up, as you hold it (e.g. "IMO 7406784", "DCBKKPPY", a wallet address, a passport number). Must contain at least one character other than whitespace and - . / |
| Name | Type | Req | Description |
|---|---|---|---|
| caveat | string | – | Decision-support caveat — this is a screening aid, not a compliance determination. |
| error | object | – | Present when the call failed. Absent on success. |
| hits | array | – | Designations that publish a matching identifier, one per designation, ordered by source list then entry ID. Not paged — the most widely shared published identifiers map to about a dozen designations. |
| notice | string | – | Guidance when no designation matched — what to try next, and what an empty result does NOT mean. |
| totalCount | number | – | Number of designations returned. |
No examples provided.
sanctions_screen_name sanctions-screening-mcp-server: screen name ~469
Screen a name (person, company, vessel, aircraft) against all loaded sanctions watchlists at once — OFAC SDN + Consolidated, EU, UK, and UN — alias- and fuzzy-aware. Returns scored potential matches with the source list, sanctioning program, designation date, and the matched alias. Strict mode (default) matches exact-normalized then all-tokens-present; fuzzy mode (or auto when strict is empty) adds Jaro-Winkler and phonetic matching and labels hits approximate with a raw 0–1 similarity score plus the count of query tokens the candidate covers, which orders candidates that tie on score. Results are paged: totalAvailable and hasMore report matches beyond the returned page, and nextOffset retrieves them. This is a screening AID for a human/compliance review, NOT a compliance determination: a hit means "review this candidate against the official source," and an empty result never means "cleared."
| Name | Type | Req | Description |
|---|---|---|---|
| entityType | string | – | Restrict to one entity class, or "any" (default) to screen across all. |
| limit | integer | – | Maximum number of potential matches to return in one page. |
| matchMode | string | – | strict (default): exact-normalized then all-tokens-present. fuzzy: also scored Jaro-Winkler + phonetic. Strict auto-falls-back to fuzzy when it finds nothing. |
| minScore | number | – | Score floor for fuzzy hits (0–1), applied uniformly to every fuzzy candidate regardless of how it was matched (Jaro-Winkler, token, or phonetic). No hit below this score is returned. Applies to fuzzy… |
| name | string | yes | The name to screen (person, organization, vessel, or aircraft), in any script. It must contain at least one letter or digit, and at most 64 words and 1024 characters. |
| offset | integer | – | Zero-based index of the first potential match to return. Re-call with the returned nextOffset to page through every match when hasMore is true; an offset past the end returns an empty page, not an er… |
| sources | array | – | Restrict to specific source lists. Omit to screen all loaded lists. |
| Name | Type | Req | Description |
|---|---|---|---|
| caveat | string | – | Decision-support caveat — this is a screening aid, not a compliance determination. |
| error | object | – | Present when the call failed. Absent on success. |
| hasMore | boolean | – | True when potential matches remain beyond this page — re-call with nextOffset. |
| hits | array | – | Potential matches, ranked by match type, then score, then how much of the query each candidate explains. |
| matchModeUsed | string | – | The match mode actually applied (strict may auto-upgrade to fuzzy on empty). |
| nextOffset | number | – | The offset to request next. Present only when hasMore is true. |
| normalizedQuery | string | – | The name as the server folded it for matching. |
| notice | string | – | Guidance when no candidate matched — how to broaden, and what an empty result does NOT mean — or when the requested offset sits past the end of the result set. |
| totalAvailable | number | – | Potential matches available across all pages, before limit and offset were applied. |
| totalAvailableBasis | string | – | How to read totalAvailable: exact = the complete strict match set; lower_bound = a bounded scan produced it (every fuzzy pass, and any strict pass that hit the raw-row scan cap), so more may exist. |
| totalCount | number | – | Number of potential matches returned in this page. |
No examples provided.
sanctions_trace_ownership sanctions-screening-mcp-server: trace ownership ~326
Trace the GLEIF Level 2 corporate-ownership graph for an LEI: direct and ultimate parents and/or children, traversed breadth-first to a bounded depth, with relationship type for each edge. Set screenNodes to also screen every entity in the graph against all loaded watchlists — resolving "is anyone in this ownership chain sanctioned." Each per-node screen is a screening AID: hits are candidates to verify, and an empty result for a node is not a clearance of that node. Each node whose parents were walked carries parentStatus for its direct and ultimate parent: a published relationship, a reporting exception with the reasons the entity gave (such as NATURAL_PERSONS or NON_CONSOLIDATING), none, or unknown when reporting exceptions are not loaded. The response says what it could not do: complete/truncated/missingEntityLeis report whether the loaded relationship graph within the depth is fully shown, screeningStatus reports whether the cross-reference actually ran, and each screened node reports whether its own hit list was capped. Requires a valid 20-character LEI (use sanctions_resolve_entity to obtain one).
| Name | Type | Req | Description |
|---|---|---|---|
| depth | integer | – | Maximum traversal depth from the root entity (1–5). |
| direction | string | – | Walk parents (who owns it), children (what it owns), or both (default). |
| lei | string | yes | The 20-character GLEIF LEI at the root of the ownership graph. |
| screenNodes | boolean | – | When true, screen every node's legal name against all watchlists — the ownership-chain cross-reference. |
| Name | Type | Req | Description |
|---|---|---|---|
| caveat | string | – | Decision-support caveat — node screening is an aid, not a determination. |
| complete | boolean | – | True when the loaded Level 2 relationships within the requested depth are all shown (nothing was cut off by depth) AND every node resolved to a GLEIF Level 1 record. It does not say every parent is k… |
| edges | array | – | Directed ownership edges between the nodes. |
| error | object | – | Present when the call failed. Absent on success. |
| flaggedNodeCount | number | – | How many screened nodes had at least one potential watchlist match. |
| missingEntityLeis | array | – | LEIs published in the relationship corpus but absent from the GLEIF Level 1 entity mirror. Their nodes carry the LEI in place of a legal name and no jurisdiction/status — never read that LEI as a leg… |
| nodes | array | – | All entities reached in the traversal, including the root. |
| reportingExceptionsLoaded | boolean | – | Whether GLEIF reporting exceptions are loaded in the mirror. When false, a node's parent level with no published relationship reads unknown rather than exception or none. |
| rootLei | string | – | The LEI the traversal started from. |
| screenedNodeCount | number | – | How many nodes were screened (0 when screenNodes is false). |
| screeningStatus | string | – | Whether the per-node cross-reference ran: screened = every node was screened; not_requested = screenNodes was false; not_ready = screening was requested but the sanctions mirror has never synced, so… |
| truncated | boolean | – | True when further ownership relationships exist beyond the requested depth — re-run with a higher depth to see them. False means the traversal reached the edge of the loaded relationship corpus. |
No examples provided.
What is the io.github.cyanheads/sanctions-screening-mcp-server server?
io.github.cyanheads/sanctions-screening-mcp-server is listed in the public MCP registry as io.github.cyanheads/sanctions-screening-mcp-server. Screen names against OFAC, EU, UK, UN sanctions lists; resolve entities via GLEIF. Screening aid. This page covers its hosted endpoint (https://sanctions-screening.caseyjhand.com/mcp).
Is the io.github.cyanheads/sanctions-screening-mcp-server server safe to use?
io.github.cyanheads/sanctions-screening-mcp-server scores 89 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.cyanheads/sanctions-screening-mcp-server server expose?
io.github.cyanheads/sanctions-screening-mcp-server exposes 7 tools: sanctions_screen_name, sanctions_screen_identifier, sanctions_get_designation, sanctions_list_sources, sanctions_resolve_entity, and 2 more. Their descriptions and schemas cost roughly 2,336 tokens of context every time the server is loaded.
Does the io.github.cyanheads/sanctions-screening-mcp-server server require authentication?
No. We connected to io.github.cyanheads/sanctions-screening-mcp-server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.cyanheads/sanctions-screening-mcp-server server still maintained?
io.github.cyanheads/sanctions-screening-mcp-server is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.