usaspending-gov-mcp
PyPI
v1.0.5
Published by 1102tools-dev — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP server for USASpending.gov federal contract and award data
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/test_tool_profiles.py:19`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: "] = profile return subprocess.run( [ sys.executable, "-c", (
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/test_tool_profiles.py
Each tool and what it can reach — statically extracted from the published source.
get_award_detailingests untrusted inputautocomplete_awarding_agencyno sensitive capabilityautocomplete_cfdano sensitive capabilityautocomplete_funding_agencyno sensitive capabilityautocomplete_glossaryno sensitive capabilityautocomplete_naicsno sensitive capabilityautocomplete_pscno sensitive capabilityautocomplete_recipientno sensitive capabilityawards_last_updatedno sensitive capabilityget_agency_awardsno sensitive capabilityget_agency_budgetary_resourcesno sensitive capabilityget_agency_federal_accountsno sensitive capabilityget_agency_object_classesno sensitive capabilityget_agency_obligations_by_award_categoryno sensitive capabilityget_agency_overviewno sensitive capabilityget_agency_program_activitiesno sensitive capabilityget_agency_sub_agenciesno sensitive capabilityget_award_countno sensitive capabilityget_award_federal_account_countno sensitive capabilityget_award_fundingno sensitive capabilityget_award_funding_rollupno sensitive capabilityget_award_subaward_countno sensitive capabilityget_award_transaction_countno sensitive capabilityget_award_types_referenceno sensitive capabilityget_def_codes_referenceno sensitive capabilityget_federal_account_detailno sensitive capabilityget_federal_account_fy_snapshotno sensitive capabilityget_federal_account_object_classesno sensitive capabilityget_federal_account_program_activitiesno sensitive capabilityget_glossaryno sensitive capabilityget_idv_activityno sensitive capabilityget_idv_amountsno sensitive capabilityget_idv_childrenno sensitive capabilityget_idv_fundingno sensitive capabilityget_idv_funding_rollupno sensitive capabilityget_naics_detailsno sensitive capabilityget_psc_filter_treeno sensitive capabilityget_recipient_childrenno sensitive capabilityget_recipient_profileno sensitive capabilityget_state_profileno sensitive capabilityget_submission_periodsno sensitive capabilityget_transactionsno sensitive capabilitylist_federal_accountsno sensitive capabilitylist_statesno sensitive capabilitylist_toptier_agenciesno sensitive capabilitylookup_piidno sensitive capabilitynew_awards_over_timeno sensitive capabilitysearch_awardsno sensitive capabilitysearch_recipientsno sensitive capabilitysearch_subawardsno sensitive capabilityspending_by_categoryno sensitive capabilityspending_by_geographyno sensitive capabilityspending_by_subaward_groupedno sensitive capabilityspending_by_transactionno sensitive capabilityspending_over_timeno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.5 latest |
A 96/100 | 1 | 1.13.0 | 2026-08-25 |
v1.0.4 |
A 96/100 | 1 | 1.12.1 | 2026-08-23 |
v1.0.3 |
A 96/100 | 0 | 1.12.1 | 2026-08-22 |
v1.0.2 |
A 96/100 | 0 | 1.12.1 | 2026-08-18 |
v1.0.0 |
A 96/100 | 0 | 1.12.1 | 2026-08-16 |
v0.3.2 |
A 96/100 | 0 | 1.12.1 | 2026-07-27 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan usaspending-gov-mcp --online --registry pypi
A Model Context Protocol server implementation for AdGuard Home that enables AI agents to query and manage DNS records, filtering rules and more
Identity oracle and trust layer for autonomous AI agents. Bidirectional KYA and trust scoring.
MCP server with Airtable integration
A free one-minute reset for people, delivered by AI, with no account or personal data.
Access SEC filings efficiently, save time and tokens, and get cited answers.
A smart [MCP](https://modelcontextprotocol.io) server for [AniList](https://anilist.co) that gets your anime/manga taste - not just API calls.