Sam Gov (cliwant) MCP Server

@cliwant/mcp-sam-gov npm v1.12.0 Source verified

Published by cliwant — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.

Most comprehensive keyless MCP server for US federal + state/local (SLED) contracting + spending + regulation: SAM.gov, USAspending, Federal Register, eCFR, Grants.gov, plus SLED procurement bids (OpenGov, Bonfire, ArcGIS, Socrata 53 hosts). 150 tools, no

Trust grade
A
94/100
Last scanned get badge →
Trust
A · 94/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
High
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 94/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−6 capability blast radius (high) — client exposure if the model is manipulated

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 1

critical Completed toxic-flow trifecta across toolsMTC-FLOW-002

This server (without client built-ins) exposes a complete data-exfiltration chain: bls_timeseries → sam_fetch_description → bea_regional_data. Untrusted input is ingested, private data is read, and it can be sent to an external sink via the agent composing the tools (→). Static analysis proves the primitive exists, not that a specific run will occur.

Fix: Remove one leg of the trifecta: isolate untrusted-input tools from secret-reading tools and from egress tools, or require human approval between them.

Location: flow bls_timeseries → sam_fetch_description → bea_regional_data

Tools 148

Each tool and what it can reach — statically extracted from the published source.

  • sam_fetch_descriptioningests untrusted inputreads sensitive data
  • bea_regional_datanetwork egress
  • bls_timeseriesingests untrusted input
  • bonfire_list_organizationsingests untrusted input
  • bonfire_search_opportunitiesingests untrusted input
  • census_business_patternsnetwork egress
  • census_geographies_by_coordinatesingests untrusted input
  • cisa_kev_lookupingests untrusted input
  • clinicaltrials_facet_countsingests untrusted input
  • clinicaltrials_get_studyingests untrusted input
Show 138 more tools ↓
  • clinicaltrials_search_studiesingests untrusted input
  • congress_get_billingests untrusted input
  • courtlistener_search_opinionsnetwork egress
  • cpsc_recallsingests untrusted input
  • dol_get_datasetingests untrusted input
  • dol_list_datasetsingests untrusted input
  • echo_facility_reportingests untrusted input
  • edgar_company_filingsingests untrusted input
  • edgar_daily_filing_indexingests untrusted input
  • edgar_filing_indexingests untrusted input
  • fed_register_get_documentingests untrusted input
  • fred_search_seriesnetwork egress
  • fred_series_observationsingests untrusted input
  • gao_protest_lookupingests untrusted input
  • govinfo_get_packageingests untrusted input
  • grants_get_opportunityingests untrusted input
  • nist_800_53_controlsingests untrusted input
  • nonprofit_financialsingests untrusted input
  • nsf_get_awardingests untrusted input
  • ofac_screen_entityingests untrusted input
  • openfda_device_clearancesnetwork egress
  • openfda_enforcementnetwork egress
  • opengov_search_solicitationsingests untrusted input
  • regulations_get_docketingests untrusted input
  • sam_attachment_urlingests untrusted input
  • sam_fetch_attachment_textingests untrusted input
  • sam_get_opportunityingests untrusted input
  • sam_lookup_notice_fieldsingests untrusted input
  • usas_get_award_detailingests untrusted input
  • api_key_statusno sensitive capability
  • arcgis_feature_queryno sensitive capability
  • arcgis_hub_discover_datasetsno sensitive capability
  • bls_oews_wagesno sensitive capability
  • cbp_border_wait_timesno sensitive capability
  • census_geocode_addressno sensitive capability
  • ckan_discover_datasetsno sensitive capability
  • ckan_queryno sensitive capability
  • cms_dmepos_suppliersno sensitive capability
  • cms_facility_directoryno sensitive capability
  • cms_hospital_compareno sensitive capability
  • cms_medicare_provider_servicesno sensitive capability
  • cms_query_datasetno sensitive capability
  • cms_revoked_providersno sensitive capability
  • cms_search_datasetsno sensitive capability
  • congress_search_billsno sensitive capability
  • cve_lookupno sensitive capability
  • datagov_search_datasetsno sensitive capability
  • ecfr_get_sectionno sensitive capability
  • ecfr_list_titlesno sensitive capability
  • ecfr_searchno sensitive capability
  • echo_search_facilitiesno sensitive capability
  • edgar_company_conceptno sensitive capability
  • edgar_company_factsno sensitive capability
  • edgar_full_text_searchno sensitive capability
  • edgar_lookup_cikno sensitive capability
  • edgar_xbrl_framesno sensitive capability
  • epa_tri_facilitiesno sensitive capability
  • fac_get_findingsno sensitive capability
  • fac_search_auditsno sensitive capability
  • far_clause_lookupno sensitive capability
  • far_compliance_matrixno sensitive capability
  • far_searchno sensitive capability
  • fdic_bank_failuresno sensitive capability
  • fdic_branch_depositsno sensitive capability
  • fdic_institution_financialsno sensitive capability
  • fdic_institution_historyno sensitive capability
  • fdic_risk_ratiosno sensitive capability
  • fdic_search_institutionsno sensitive capability
  • fed_register_list_agenciesno sensitive capability
  • fed_register_public_inspectionno sensitive capability
  • fed_register_search_documentsno sensitive capability
  • feedbackno sensitive capability
  • fema_disaster_declarationsno sensitive capability
  • fema_search_hazard_mitigationno sensitive capability
  • fema_search_public_assistanceno sensitive capability
  • fpds_search_awardsno sensitive capability
  • govinfo_list_collectionsno sensitive capability
  • govinfo_search_packagesno sensitive capability
  • grants_searchno sensitive capability
  • gsa_benchmark_labor_ratesno sensitive capability
  • gsa_perdiem_ratesno sensitive capability
  • hts_lookupno sensitive capability
  • lda_search_filingsno sensitive capability
  • nhtsa_complaintsno sensitive capability
  • nhtsa_recallsno sensitive capability
  • nih_reporter_search_projectsno sensitive capability
  • nonprofit_searchno sensitive capability
  • nppes_lookup_providerno sensitive capability
  • nsf_search_awardsno sensitive capability
  • nws_active_alertsno sensitive capability
  • openfda_drug_approvalsno sensitive capability
  • opengov_list_governmentsno sensitive capability
  • regulations_search_commentsno sensitive capability
  • regulations_search_docketsno sensitive capability
  • regulations_search_documentsno sensitive capability
  • sam_check_exclusionsno sensitive capability
  • sam_get_wage_ratesno sensitive capability
  • sam_integrity_lookupno sensitive capability
  • sam_lookup_organizationno sensitive capability
  • sam_search_opportunitiesno sensitive capability
  • sam_search_shapingno sensitive capability
  • sam_search_wage_determinationsno sensitive capability
  • sba_size_standardno sensitive capability
  • search_gov_domainsno sensitive capability
  • socrata_discover_datasetsno sensitive capability
  • socrata_queryno sensitive capability
  • treasury_avg_interest_ratesno sensitive capability
  • treasury_debt_to_pennyno sensitive capability
  • treasury_monthly_statementno sensitive capability
  • treasury_query_datasetno sensitive capability
  • usas_analyze_incumbentno sensitive capability
  • usas_autocomplete_naicsno sensitive capability
  • usas_autocomplete_recipientno sensitive capability
  • usas_disaster_spendingno sensitive capability
  • usas_get_agency_awards_summaryno sensitive capability
  • usas_get_agency_budget_functionno sensitive capability
  • usas_get_agency_profileno sensitive capability
  • usas_get_recipient_profileno sensitive capability
  • usas_glossaryno sensitive capability
  • usas_list_disaster_codesno sensitive capability
  • usas_list_toptier_agenciesno sensitive capability
  • usas_lookup_agencyno sensitive capability
  • usas_naics_hierarchyno sensitive capability
  • usas_search_agency_spendingno sensitive capability
  • usas_search_awardsno sensitive capability
  • usas_search_awards_by_recipientno sensitive capability
  • usas_search_cfda_spendingno sensitive capability
  • usas_search_expiring_contractsno sensitive capability
  • usas_search_federal_account_spendingno sensitive capability
  • usas_search_individual_awardsno sensitive capability
  • usas_search_psc_spendingno sensitive capability
  • usas_search_recipientsno sensitive capability
  • usas_search_recompetesno sensitive capability
  • usas_search_state_spendingno sensitive capability
  • usas_search_subagency_spendingno sensitive capability
  • usas_search_subawardsno sensitive capability
  • usas_search_teaming_partnersno sensitive capability
  • usas_spending_over_timeno sensitive capability

Toxic flows 1

Cross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).

What this scan could not see

Versions 2

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v1.12.0 latest A 94/100 1 1.13.0 2026-09-07
v1.11.0 A 94/100 1 1.9.0 2026-07-24

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 94/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/cliwant-mcp-sam-gov/badge.svg)](https://mcptrustchecker.com/registry/cliwant-mcp-sam-gov)
HTML
<a href="https://mcptrustchecker.com/registry/cliwant-mcp-sam-gov"><img src="https://mcptrustchecker.com/registry/cliwant-mcp-sam-gov/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/cliwant-mcp-sam-gov/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @cliwant/mcp-sam-gov --online

Use the free API → How scoring works

Other implementations of Sam Gov 2

Independent packages implementing the same tool, scanned with the same engine. Compare all 3 side by side →

More in Data Science & ML