Fedramp Oscal Ssp Lint runs on your own machine — the client starts it, so there is no endpoint to ping. 425 installs a week from npm. Last commit 22 Sep 2026.
16 checks on a system-security-plan JSON, in your editor, before a validator returns the package
Today is the operative word: we check Fedramp Oscal Ssp Lint every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add fedramp-oscal-ssp-lint -- npx -y @readystack/fedramp-oscal-ssp-lint
{
"mcpServers": {
"fedramp-oscal-ssp-lint": {
"args": [
"-y",
"@readystack/fedramp-oscal-ssp-lint"
],
"command": "npx"
}
}
}
[mcp_servers.fedramp-oscal-ssp-lint]
command = "npx"
args = ["-y", "@readystack/fedramp-oscal-ssp-lint"]
{
"mcpServers": {
"fedramp-oscal-ssp-lint": {
"args": [
"-y",
"@readystack/fedramp-oscal-ssp-lint"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"fedramp-oscal-ssp-lint": {
"args": [
"-y",
"@readystack/fedramp-oscal-ssp-lint"
],
"command": "npx"
}
}
}
Sixteen statutory checks on the signup page AB 2863 rewrote, in your editor and in the browser
API monitoring from your editor. Checks the JSON your endpoints return, not just the status code.
15 checks for the apiVersions kubectl no longer serves, on the manifest open in your editor
Find the package.json lines that stop vsce before you run the release build
MCP security trust layer: scan packages, inspect repos, check exposure, monitor changes.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
Finds the Gov-Client and Gov-Vendor header mistakes HMRC rejects, in your editor, offline, before yo
Answers built from our own checks of this server.