finos-mcp-aigf
A read-only MCP server for the FINOS AI Governance Framework: its risks and controls with their public AIR-* ids, risk-to-control mapping, crosswalks to NIST SP 800-53, ISO 42001, the EU AI Act and OWASP, and full-text search with citable aigf:// resources.
Not affiliated with or endorsed by FINOS. This is an independent, community package. On PyPI the finos- prefix is also used by official FINOS packages such as finos-cdm; this is not one of them.
Run it
Requires Python 3.12+.
uvx --python 3.12 finos-mcp-aigf # stdio
uvx --python 3.12 finos-mcp-aigf --transport streamable-http --port 8000
Claude Code: claude mcp add finos-aigf -- uvx --python 3.12 finos-mcp-aigf. Claude Desktop:
{"mcpServers": {"finos-aigf": {"command": "uvx", "args": ["--python", "3.12", "finos-mcp-aigf"]}}}
Tools
get_risk,get_control,list_risks,list_controls: acceptAIR-SEC-010,ri-10,10or a title.map_risks_to_controls: controls ranked by how many of the given risks they cover.map_control_to_external,find_by_external_reference,list_reference_frameworks: crosswalks in both directions.search_framework: BM25 search; installfinos-mcp-aigf[semantic]for hybrid search (downloads a ~15 MB model on first use).search_status,server_info.
Full argument reference: https://vardhjain.github.io/finos-mcp/tools/.
Safety
Read-only by construction: every tool is registered with readOnlyHint: true and the server refuses to serve tools otherwise. Content is vendored into the package with recorded upstream commit hashes, so the server makes no network calls at runtime. Every call is rate-limited, input-capped, audited as one JSON line, and fails with a structured error the agent can act on. Details: finos-mcp-core.
Docs: https://vardhjain.github.io/finos-mcp/ · Source: https://github.com/vardhjain/finos-mcp · Changelog: https://github.com/vardhjain/finos-mcp/blob/main/CHANGELOG.md
Licence
Code is Apache-2.0. The vendored AI Governance Framework content is CC-BY-4.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file finos_mcp_aigf-0.1.2.tar.gz.
File metadata
- Download URL: finos_mcp_aigf-0.1.2.tar.gz
- Upload date:
- Size: 193.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8926b2516712284d233974a5763b0959f781ffbfc794ce21d1082a801fdc7f12
|
|
| MD5 |
5e66284bfd97590ccd95e8c3a8ca5614
|
|
| BLAKE2b-256 |
730c3729487f4d55c6db89e3f731d9f8bfd2af588629d6336a485b8452a72c75
|
Provenance
The following attestation bundles were made for finos_mcp_aigf-0.1.2.tar.gz:
Publisher:
release.yml on vardhjain/finos-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
finos_mcp_aigf-0.1.2.tar.gz -
Subject digest:
8926b2516712284d233974a5763b0959f781ffbfc794ce21d1082a801fdc7f12 - Sigstore transparency entry: 2790404329
- Sigstore integration time:
-
Permalink:
vardhjain/finos-mcp@2fb343e7c76d1132442b0ef339c57871853cfdda -
Branch / Tag:
refs/tags/v0.1.2 - Owner: https://github.com/vardhjain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@2fb343e7c76d1132442b0ef339c57871853cfdda -
Trigger Event:
push
-
Statement type:
File details
Details for the file finos_mcp_aigf-0.1.2-py3-none-any.whl.
File metadata
- Download URL: finos_mcp_aigf-0.1.2-py3-none-any.whl
- Upload date:
- Size: 245.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
aeb4eab0d156df5199a947c2afcd09d883f3ed201d773753c06805e83d986557
|
|
| MD5 |
820b62e64a638f53e349c480577d7cdc
|
|
| BLAKE2b-256 |
ce0d76e3b9ddf39d8eb6713caf35c38f05feb402c5efdaff6b64749907721882
|
Provenance
The following attestation bundles were made for finos_mcp_aigf-0.1.2-py3-none-any.whl:
Publisher:
release.yml on vardhjain/finos-mcp
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
finos_mcp_aigf-0.1.2-py3-none-any.whl -
Subject digest:
aeb4eab0d156df5199a947c2afcd09d883f3ed201d773753c06805e83d986557 - Sigstore transparency entry: 2790404373
- Sigstore integration time:
-
Permalink:
vardhjain/finos-mcp@2fb343e7c76d1132442b0ef339c57871853cfdda -
Branch / Tag:
refs/tags/v0.1.2 - Owner: https://github.com/vardhjain
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@2fb343e7c76d1132442b0ef339c57871853cfdda -
Trigger Event:
push
-
Statement type: