Cra Readiness Audit runs on your own machine — the client starts it, so there is no endpoint to ping. 333 installs a week from npm. Last commit 22 Sep 2026.
Flags the lines in your repo that break the EU Cyber Resilience Act - default passwords, disabled TL
Today is the operative word: we check Cra Readiness Audit every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add cra-readiness-audit -- npx -y @readystack/cra-readiness-audit
{
"mcpServers": {
"cra-readiness-audit": {
"args": [
"-y",
"@readystack/cra-readiness-audit"
],
"command": "npx"
}
}
}
[mcp_servers.cra-readiness-audit]
command = "npx"
args = ["-y", "@readystack/cra-readiness-audit"]
{
"mcpServers": {
"cra-readiness-audit": {
"args": [
"-y",
"@readystack/cra-readiness-audit"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"cra-readiness-audit": {
"args": [
"-y",
"@readystack/cra-readiness-audit"
],
"command": "npx"
}
}
}
Reads your SECURITY.md against the EU Cyber Resilience Act reporting clock that started on 11 Septem
Reads security headers and CSP line by line in your config file and names the lines that silently do
Finds the coverage gates in your repo that can never fail a build
Flags the EN 301 549 clause each line breaks, and separates what is in force today from what arrives
Reads the open-weight model IDs in your code and names the licence clause that binds you - 22 rules
Finds the credential in your release workflow that expires before your next release
Marks the lines in your test suite that current pytest no longer runs — and the config keys it silen
Names every schedule line in the file you have open that fires at the wrong hour, twice, or never at
Answers built from our own checks of this server.