# SCORM Packager (HTML → SCORM 2004) (mcpb · scorm-mcp-server-2.3.0.mcpb)

Turn HTML or mobile-learning exports into SCORM 2004/1.2 packages, and validate any SCORM zip.

- Trust score: 57/100 (low)
- Change this week: +4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- mcpb · `scorm-mcp-server-2.3.0.mcpb`: 57/100 (this document), [markdown](https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm.md), [page](https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm)
- npm · `scorm-mcp-server`: 79/100, [markdown](https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/scorm-mcp-server.md), [page](https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/scorm-mcp-server)

## Channel facts

- Registry: `mcpb`
- Package: `https://github.com/giacomomaria81/scorm-mcp-server/releases/download/v2.3.0/scorm-mcp-server-2.3.0.mcpb`
- Version: `2.3.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 23/100
  - Malware scan not yet available for this package.
  - Known CVEs were checked across the 130 of 130 dependencies we could resolve, so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - 42 of 130 dependencies flagged as unhealthy (1 deprecated).
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 25 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 59/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2042 tokens (~680/item across 3 items; 3 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 87/100
  - Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 3 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

- Download bundle: `https://github.com/giacomomaria81/scorm-mcp-server/releases/download/v2.3.0/scorm-mcp-server-2.3.0.mcpb`

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 57, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 56, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 55, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 54, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 53, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 52, +1)

No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 51, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-05 (score 50, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (3)

### `scorm_package` (~1619 tokens)

Package HTML as SCORM (2004 or 1.2)

Convert a self-contained HTML document, a folder, a .zip, a Claude Design (.dc) bundle OR a mobile-learning platform content export (Excel activity templates + media) into a SCORM package (.zip) — SCORM 2004 4th Edition by default, or SCORM 1.2 for legacy LMSs.

Use this to turn a finished learning module (for example HTML produced by Claude Design) into a file that any SCORM-compliant LMS can import. The conversion is faithful: the HTML is preserved, external assets are inlined as data URIs so the package runs 100% offline, and a small runtime is injected to report completion and progress.

MIGRATION FROM MOBILE-LEARNING PLATFORMS: if the input zip/folder contains Excel activity templates (mobile course cards, quiz games...) plus a media folder — the format produced by the platform's content export — the tool rebuilds an interactive HTML course from them (info/transition/flash cards, scored quizzes reporting cmi.score, media embedded, the platform's layout codes rendered) and packages it. No title needed: it is derived from the template file names. Combined with batch mode this migrates a whole course catalogue in one call.

PROGRESS / COMPLETION MODEL (milestones):
The author can mark meaningful steps with data-jalon + optional data-trigger:
  \- <section data-jalon="histoire-produit" data-trigger="view"> ... </section>   (counts when scrolled into view; "view" is the default)
  \- <button  data-jalon="argumentaire" data-trigger="click">J'ai lu</button>      (counts on click)
  \- <video   data-jalon="geste" data-trigger="ended"> ... </video>                (counts when playback ends)
AUTOMATIC FALLBACK: if the HTML declares NO milestone, they are generated automatically from the document structure (sections → articles → h2 → h3, capped at 8, trigger "view"). So plain HTML "just works" with meaningful progress — you do NOT need to ask the author to add attributes first. Explicit data-jalon attributes always take precedence (recommended for click/video steps).
The ru…

Input parameters:

- `auto_milestones` (boolean): When the HTML declares no [data-jalon] milestone, auto-generate 'view' milestones from the document structure (sections, then articles, then headings; max 8). Default: true.
- `base_url` (string): Base URL to resolve relative/root-relative asset references over the network (only needed if the HTML uses relative URLs and no input_path is given).
- `batch` (boolean): Treat input_path as a DIRECTORY containing several courses (each sub-directory, .zip or .html file = one course). Produces one package per course plus a consolidated report. Course titles default to…
- `format` (string): Input format. 'auto' (default) detects Claude Design .dc bundles by signature; override to force a pipeline.
- `html` (string): Raw HTML content to convert (e.g. the output of Claude Design). Provide this OR input_path.
- `identifier` (string): Manifest identifier. Auto-generated from the title if omitted.
- `input_path` (string): Absolute path to an HTML file on disk. Its folder is used to resolve relative assets. Provide this OR html.
- `language` (string): Content language tag (BCP-47), e.g. 'fr-FR', 'en-US', 'it-IT'. Default: 'fr-FR'. Applied as <html lang> when the source declares none.
- `mastery_score` (number): Pass threshold 0..1. Enables score-based success (passed/failed from cmi.score.scaled) and adds sequencing objectives to the manifest. Content reports the score via window.SCORM2004.score(raw,min,max…
- `output_dir` (string): Directory to write the .zip package into. Defaults to $SCORM_OUTPUT_DIR or ~/scorm-packages.
- `scorm_version` (string): SCORM edition of the produced package. '2004' (default, 4th Edition) or '1.2' for legacy LMSs. The injected runtime is adaptive and works with both LMS APIs; this choice controls the manifest and bun…
- `success_on_completion` (boolean): Also report cmi.success_status='passed' when the module completes (equivalent to adding data-scorm-success="on-completion"). Default: false.
- `title` (string): Course / module title, used as the manifest, organization and item title shown in the LMS. Required for HTML inputs; optional for a mobile-learning Excel export, where it is derived from the template…
- `vendor_cdn` (boolean): For Claude Design (.dc) bundles: download CDN libs (React/Babel…) into the package so it runs offline (via window.__resources, no source patch). Default: true.

### `scorm_validate` (~358 tokens)

Validate an existing SCORM package

Check whether an EXISTING SCORM .zip (made by this tool or by ANY other authoring tool) is conformant and will import into an LMS — and if not, explain exactly why.

Use this when an LMS rejects a package, before uploading a package to production, or to audit a batch of courses received from a vendor. The input is never modified.

Checks performed:
  \- the archive is a readable zip with imsmanifest.xml at its ROOT (detects the classic "zipped the folder instead of its contents" mistake and says how to fix it)
  \- the manifest is well-formed XML and the SCORM edition is identified (2004 or 1.2)
  \- an <organization> with a launchable <item> exists, resolving to a scormType="sco" <resource> with an href
  \- the launch file and every <file href> listed in the manifest actually exist in the archive (case-only mismatches are flagged: they work on Windows but fail on the Linux servers most LMSs run on)
  \- the manifest validates against the official ADL XSD schemas (XSDs bundled in the package are used first; missing ones are supplied from the copies embedded in this tool, so packages that ship without schemas can still be validated). Requires xmllint; skipped with a warning otherwise.

Args:
  \- input_path (string, required): path to the .zip to validate.

Returns JSON: { ok, scorm_version, title, entry_href, files_in_zip, checks: [{id, label, ok, detail}], errors, warnings, schema_validation }

Input parameters:

- `input_path` (string, required): Path to the SCORM .zip file to validate.

### `scorm_selftest` (~65 tokens)

SCORM packager self-test

Diagnostic tool with NO arguments: packages a constant built-in HTML and reports version, duration and output path. Distinguishes 'server broken' from 'input problem' in one second. Writes one small file (selftest-scorm2004.zip) into the output directory.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm#diagnostics

## Score history

- 2026-09-20: 57
- 2026-09-19: 56
- 2026-09-18: 56
- 2026-09-17: 55
- 2026-09-16: 55
- 2026-09-15: 54
- 2026-09-14: 54
- 2026-09-13: 53
- 2026-09-12: 53
- 2026-09-11: 53
- 2026-09-10: 52
- 2026-09-09: 52
- 2026-09-08: 51
- 2026-09-07: 51
- 2026-09-06: 50
- 2026-09-05: 50
- 2026-09-04: 49
- 2026-09-03: 49
- 2026-09-02: 48
- 2026-09-01: 45
- 2026-08-31: 45
- 2026-08-30: 45
- 2026-08-29: 45
- 2026-08-28: 45
- 2026-08-27: 45
- 2026-08-26: 45
- 2026-08-25: 43

## Common questions

### What is the SCORM Packager (HTML → SCORM 2004) MCP server?

SCORM Packager (HTML → SCORM 2004) is an MCP server listed in the public MCP registry as io.github.giacomomaria81/scorm-mcp-server. Turn HTML or mobile-learning exports into SCORM 2004/1.2 packages, and validate any SCORM zip. This page covers its MCPB bundle (https://github.com/giacomomaria81/scorm-mcp-server/releases/download/v2.3.0/scorm-mcp-server-2.3.0.mcpb).

### Is the SCORM Packager (HTML → SCORM 2004) MCP server safe to use?

SCORM Packager (HTML → SCORM 2004) scores 57 out of 100 on VerifyMCP. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the SCORM Packager (HTML → SCORM 2004) MCP server expose?

SCORM Packager (HTML → SCORM 2004) exposes 3 tools: scorm_package, scorm_validate, scorm_selftest. Their descriptions and schemas cost roughly 2,042 tokens of context every time the server is loaded.

### What licence is the SCORM Packager (HTML → SCORM 2004) MCP server under?

SCORM Packager (HTML → SCORM 2004) declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- Repository: https://github.com/giacomomaria81/scorm-mcp-server
- Changelog RSS feed: https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm.xml
- Changelog JSON feed: https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm.json
- HTML version of this page: https://verifymcp.io/servers/giacomomaria81-scorm-mcp-server/https-github-com-giacomomaria81-scorm-mcp-server-releases-download-v2-3-0-scorm
