io.github.gander-tools/osm-tagging-schema-mcp
NPM · @GANDER-TOOLS/OSM-TAGGING-SCHEMA-MCP · SCANNED AUG 3
MCP server for querying and validating OpenStreetMap tags
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security70
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects @modelcontextprotocol/sdk 1.23.1, a direct dependency. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (90 of 94), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to gander-tools/osm-tagging-schema-mcp). View diagnostics → Pass
- Clear OSI-approved license (GPL-3.0).Pass
- Actively maintained (last published 84 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability74
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2594 tokens (~288/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · @gander-tools/osm-tagging-schema-mcp
claude mcp add gander-tools-osm-tagging-schema-mcp -- npx -y @gander-tools/osm-tagging-schema-mcp
codex mcp add gander-tools-osm-tagging-schema-mcp -- npx -y @gander-tools/osm-tagging-schema-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"gander-tools-osm-tagging-schema-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@gander-tools/osm-tagging-schema-mcp"
],
"enabled": true
}
}
} openclaw mcp add gander-tools-osm-tagging-schema-mcp --command npx --arg -y --arg @gander-tools/osm-tagging-schema-mcp
mcp_servers:
gander-tools-osm-tagging-schema-mcp:
command: "npx"
args: ["-y", "@gander-tools/osm-tagging-schema-mcp"] {
"mcpServers": {
"gander-tools-osm-tagging-schema-mcp": {
"command": "npx",
"args": [
"-y",
"@gander-tools/osm-tagging-schema-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +33
- CVE-2026-25536 affects this package: high ▼ security
- CVE-2025-66414 affects this package: high ▼ security
- CVE-2026-0621 affects this package: high ▼ security
- Known CVEs: unverified → fail ▼ security
- Provenance: unverified → pass ▲ security
- Install scripts: unverified → pass ▲ security
- The attested source repository moved: gander-tools/osm-tagging-schema-mcp security
- MCP protocol: unverified → fail ▼ functional
- Schema quality: unverified → excellent ▲ functional
- License: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- Maintenance: unverified → pass ▲ functional
- Stability: unverified → 0.23 ▲ functional
- Licence: GPL-3.0 functional
- 1 Aug 26 +15
- Malware scan: unverified → pass ▲ security
- 31 Jul 26 +16
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −42
- Malware scan: pass → unverified ▼ security
- Schema quality: 100 → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Dependency health: unverified → partial ▲ functional
- 27 Jul 26 50
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Analysed npm/@gander-tools/[email protected]
Provenance verified
Ecosystem: npm · Outcome: verified
Reason: verified
- Source repo:
- gander-tools/osm-tagging-schema-mcp
- Certificate issuer:
- https://token.actions.githubusercontent.com
- Certificate SAN:
- https://github.com/gander-tools/osm-tagging-schema-mcp/.github/workflows/release-please.yml@refs/heads/master
- Rekor log index:
- 732627093
- Predicate type:
- https://slsa.dev/provenance/v1
- Subject digest:
- sha512:c80f4eb00e8b4f8b156570e41072453fc63c42bee9c50e0db5da1808e880bc117d0d6cbf03f28eb277a026657255b4eb5ea674ab5ba21b02968e4cafe
- Discovery method:
- attestation_endpoint
Vulnerabilities 3 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-345p-7cg4-v4c7 | CVE-2026-25536 | high | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | yes |
| GHSA-8r9q-7v3j-jr4g | CVE-2026-0621 | high | yes | |
| GHSA-w48q-cv73-mx4w | CVE-2025-66414 | high | yes |
Dependencies 90 packages
90 packages in the resolved dependency tree · 89 deprecated · 29 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
flat_to_json ~301
**INPUT CONVERTER**: Convert OpenStreetMap tags from human-friendly flat text format (one key=value pair per line) into JSON object format required by other MCP tools. This is a preprocessing tool - use it FIRST when users provide tags as text before passing the result to validation, search, or analysis tools. All other tools in this MCP server expect JSON input, so this converter is essential for text-based workflows. The parser is robust and flexible: it handles multiple line ending formats (LF/CRLF/CR), supports comments (lines starting with #), ignores empty lines, trims whitespace, and correctly handles equals signs within values. Returns a validated JSON object with all tags, or an error if any tag is malformed or has an empty value.
| Name | Type | Req | Description |
|---|---|---|---|
| tags | string | yes | OpenStreetMap tags in flat text format with one key=value pair per line. Each line should contain exactly one tag in the format "key=value". Supports comment lines (starting with #) which are ignored… |
No output schema declared.
No examples provided.
get_preset_details ~314
Retrieve comprehensive details for a specific OpenStreetMap preset, including all tags, geometry constraints, and field definitions. A preset represents a complete feature template with its standard tags, allowed geometry types, required fields, and optional fields. Returns the preset's localized name, complete tag set with human-readable names, geometry types (point/line/area/etc.), and expanded field lists. Field lists are automatically expanded from template references (like {@templates/contact} becomes email, phone, website, fax) and preset inheritance (like {building} expands to include all building fields). Use this to understand the complete structure of a feature type, learn what tags and fields are expected for a feature, or build forms/UIs for OSM data entry. Accepts three flexible input formats for maximum convenience.
| Name | Type | Req | Description |
|---|---|---|---|
| presetId | — | yes | Identifier for the preset to retrieve, in one of three formats: 1) Preset ID using slash notation (e.g., 'amenity/restaurant', 'highway/residential', 'natural/tree') - this is the direct preset ident… |
No output schema declared.
No examples provided.
get_tag_values ~235
Retrieve all possible values for a specific OpenStreetMap tag key, with localized human-readable names for both the key and each value. This tool searches through the OSM tagging schema (both predefined field options and preset definitions) to find every documented value that can be used with the specified key. Returns four pieces of information: the normalized key name, localized key display name, a simple array of all values, and a detailed array with localized names for each value. Use this to discover what values are available for a tag (e.g., all amenity types), learn the proper terminology for values, or build UI selection lists. Essential for understanding OSM's controlled vocabularies.
| Name | Type | Req | Description |
|---|---|---|---|
| tagKey | string | yes | The OpenStreetMap tag key to retrieve values for (e.g., 'amenity', 'building', 'highway', 'natural', 'shop'). Supports both simple keys and namespaced keys with colons (e.g., 'addr:street', 'name:en'… |
No output schema declared.
No examples provided.
json_to_flat ~294
**OUTPUT CONVERTER**: Convert OpenStreetMap tags from JSON object format into human-friendly flat text format (one key=value pair per line). This is a postprocessing tool - use it LAST when users want tags displayed as readable text rather than JSON. Since all other tools in this MCP server return JSON format, this converter is essential for creating user-friendly output, generating text files for external tools, or producing easily readable tag lists. The converter validates the input thoroughly: ensures all values are strings (not numbers or other types), rejects empty values, trims whitespace from keys and values, and produces clean one-tag-per-line output with newline separators. Returns plain text with each tag on a separate line, or an error if validation fails.
| Name | Type | Req | Description |
|---|---|---|---|
| tags | — | yes | OpenStreetMap tags in JSON format, provided as either: 1) A JSON string that will be parsed (e.g., '{"amenity":"restaurant","name":"Test Cafe","cuisine":"italian"}') - must be valid JSON with string… |
No output schema declared.
No examples provided.
search_presets ~439
Search for OpenStreetMap presets by keyword or tag combination. OSM presets are predefined feature templates that define common feature types (like 'restaurant', 'park', 'road') with their standard tags, geometry constraints, and recommended fields. This tool searches through preset IDs and their associated tags to find matching features. Supports two search modes: keyword search (searches in preset IDs and all tag keys/values) and tag-based search (exact matching on specific tag key-value pairs using 'key=value' format). Returns comprehensive preset information including localized names, complete tag sets with human-readable names, and allowed geometry types. Use this to discover what feature types exist, find the correct preset for a feature you want to map, or explore related feature categories. Optionally filter results by geometry type or limit result count for performance.
| Name | Type | Req | Description |
|---|---|---|---|
| geometry | string | — | Filter results to only presets that support a specific geometry type (optional). Valid values: 'point' (nodes/POIs), 'vertex' (nodes along ways), 'line' (open ways like roads/rivers), 'area' (closed… |
| keyword | string | yes | Search term for finding presets (case-insensitive). Two formats supported: 1) Simple keyword (e.g., 'restaurant', 'parking', 'school') - searches within preset IDs and all tag keys/values, matching p… |
| limit | number | — | Maximum number of preset results to return (optional, no default limit). Use this to get faster responses when you only need a few results, or to avoid overwhelming output when searching broad terms.… |
No output schema declared.
No examples provided.
search_tags ~227
Search for OpenStreetMap tags by keyword in both tag keys and tag values. Returns two categories of results: keyMatches (when the keyword matches a tag key, returns that key with all possible values) and valueMatches (when the keyword matches a specific tag value, returns the key-value pair). Searches are case-insensitive and match partial strings. Use this to explore available tags or find tags related to a concept.
| Name | Type | Req | Description |
|---|---|---|---|
| keyword | string | yes | Single keyword to search for in tag keys and values (case-insensitive). Should be a standalone word or partial word, not a tag pair. Examples: 'restaurant' (finds amenity=restaurant), 'wheel' (finds… |
| limit | number | — | Maximum total number of results to return across both keyMatches and valueMatches combined (default: 100). Use lower values for faster responses when you only need a few results. |
No output schema declared.
No examples provided.
suggest_improvements ~269
Analyze an OpenStreetMap tag collection and suggest improvements to make it more complete and informative. This tool identifies which OSM presets match your tags, then suggests missing fields that would enhance the feature's documentation. Returns structured suggestions categorized by operation type (add, remove, update) with human-readable explanations. Suggestions include both required fields (core attributes for the matched preset) and optional fields (additional details that would be helpful). Each suggestion includes localized field names and explains why the field would improve the data. Use this for improving incomplete OSM data, learning what additional tags are recommended for a feature type, or ensuring comprehensive tagging before data upload. Accepts input in three flexible formats: JSON object, JSON string, or flat text format (key=value per line).
| Name | Type | Req | Description |
|---|---|---|---|
| tags | — | yes | Collection of existing OpenStreetMap tags to analyze in one of three formats: 1) JSON object (e.g., {"amenity": "restaurant", "name": "Test Cafe"}), 2) JSON string (e.g., '{"amenity":"parking"}'), or… |
No output schema declared.
No examples provided.
validate_tag ~246
Validate a single OpenStreetMap tag key-value pair against the OSM tagging schema. Performs comprehensive validation including: deprecation checking (identifies deprecated tags and suggests modern replacements), schema existence validation (verifies the tag key exists in the schema), option validation (checks if the value is in predefined options for that key), and field type checking (distinguishes between strict fields and combo fields that allow custom values). Returns detailed validation results with localized names and actionable messages. Use this for educational purposes, data quality checks, or validating individual tags before bulk operations.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | The OpenStreetMap tag key to validate (e.g., 'amenity', 'building', 'highway', 'natural'). Tag keys should use the standard OSM format with colons for namespaces (e.g., 'addr:street', 'name:en'). Cas… |
| value | string | yes | The OpenStreetMap tag value to validate against the specified key (e.g., 'restaurant', 'yes', 'residential', 'park'). Values are checked against predefined options if the field has them. Case-sensiti… |
No output schema declared.
No examples provided.
validate_tag_collection ~269
Validate a complete collection of OpenStreetMap tags together, performing comprehensive validation on each tag and providing aggregated statistics. This tool validates each tag individually (using the same validation logic as validate_tag) and then aggregates the results to give you an overall picture of the collection's quality. Returns detailed validation results for each tag (including deprecation warnings, schema validation, and option checking) plus summary statistics (total valid count, deprecated count, error count). Use this for bulk validation of OSM data exports, quality assurance of tag collections before upload, or analyzing the completeness of feature tagging. Accepts input in three flexible formats: JSON object, JSON string, or flat text format (key=value per line).
| Name | Type | Req | Description |
|---|---|---|---|
| tags | — | yes | Collection of OpenStreetMap tags in one of three formats: 1) JSON object (e.g., {"amenity": "restaurant", "name": "Test Cafe", "cuisine": "italian"}), 2) JSON string (e.g., '{"amenity":"parking"}'),… |
No output schema declared.
No examples provided.