
Csf
- compligent/mcp-platform
io.github.compl-i-agent/csf is a MCP server that applies NIST CSF 2.0 through 35 tools and 12 prompts for agent-driven cybersecurity framework work.
About
io.github.compl-i-agent/csf is an MCP server that exposes the NIST Cybersecurity Framework 2.0 to AI coding agents through 35 tools and 12 prompts. developers and teams use it when they need structured language for identify, protect, detect, respond, and govern—without hiring a consultant for every roadmap review. Install the stdio server via npm, register it in Claude Code, Cursor, or Windsurf, and let the agent walk controls, gaps, and priorities against your actual stack. It fits SaaS and API products that must show reasonable security posture to customers, investors, or enterprise buyers. The server is versioned (2.4.6) and documented on the Compl-i-agent CSF site; treat outputs as guidance you validate with your own risk tolerance and legal counsel, not as certification.
- 35 MCP tools aligned to NIST Cybersecurity Framework 2.0
- 12 guided prompts for assessments and control conversations
- stdio npm package @compligent-mcp/csf (v2.4.6)
- Professional CSF-oriented workflow for builders and small teams
- Pairs with agent-driven compliance gap analysis
Csf by the numbers
- Data as of Jul 7, 2026 (Skillselion catalog sync)
claude mcp add csf -- npx -y @compligent-mcp/csfAdd your badge
Show developers this MCP server is listed on Skillselion. Paste this into your README.
| Package | @compligent-mcp/csf |
|---|---|
| Transport | STDIO |
| Auth | None |
| Repository | compligent/mcp-platform ↗ |
What it does
Map product and infra controls to NIST CSF 2.0 and run structured security assessments from your coding agent.
Who is it for?
Best when you're preparing for SOC2-curious buyers, security questionnaires, or internal hardening sprints and want CSF vocabulary in the IDE.
Skip if: Skip if you need automated pentesting, live vuln scanning, or certified compliance attestation without human review.
What you get
Your agent can reference CSF 2.0 structures, run framework-aligned prompts, and produce control-oriented notes you can turn into a backlog and customer-facing security narrative.
- CSF-aligned control and gap discussion notes
- Prompt-driven assessment outputs for security backlog items
- Repeatable agent access to 35 framework tools
By the numbers
- 35 MCP tools
- 12 prompts
- Server version 2.4.6
Recommended MCP Servers
How it compares
NIST CSF framework MCP server, not a single passive security skill or a generic OWASP cheat sheet.
FAQ
Who is io.github.compl-i-agent/csf for?
Developers and small teams shipping SaaS or APIs who want NIST CSF 2.0 structure inside Claude Code, Cursor, or similar agents.
When should I use io.github.compl-i-agent/csf?
Use it during security hardening, pre-launch reviews, customer security questionnaires, or when scoping what controls you actually need.
How do I add io.github.compl-i-agent/csf to my agent?
Install @compligent-mcp/csf from npm, add a stdio MCP entry pointing at the package, restart the agent, and invoke tools from the CSF catalog.