Back to Browse

STIG MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server mapping MITRE ATT&CK® -> NIST 800-53r5 -> DISA STIG fix/check steps

About

MCP server mapping MITRE ATT&CK® -> NIST 800-53r5 -> DISA STIG fix/check steps

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). 1 code issue detected. No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

4 files analyzed · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Directory holding the knowledge base and downloaded sourcesOptional

Environment variable: STIG_MCP_DATA

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jeneric-stig-mcp": {
      "env": {
        "STIG_MCP_DATA": "your-stig-mcp-data-here"
      },
      "args": [
        "stig-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

stig-mcp

Local MCP server that maps MITRE ATT&CK® techniques (and actors) to the NIST 800-53r5 controls that mitigate them, with the DISA STIG fix and check steps for the systems under consideration, severity-ordered.

Prerequisite

stig-mcp is published on PyPI and runs through uvx, which comes with uv. Install uv, then check that uvx --version runs in a new terminal. Restart VS Code or Claude Code after installing uv so it sees the new PATH.

Quick start

VS Code (GitHub Copilot)

  1. Click this badge. VS Code opens and offers to install stig-mcp; choose Install.

    Install in VS Code

  2. Open Copilot Chat and set the mode dropdown to Agent. MCP tools are not available in Ask or Edit mode.

  3. Ask: Install the stig-mcp knowledge base. This is a one-time download of about 6 MB. Allow the tool when VS Code asks.

If that doesn't work, see troubleshooting or setting up VS Code by hand.

Claude Code

  1. Inside a Claude Code session (2.1.275 or later), run:

    /plugin install stig-mcp --marketplace jeneric/STIG-MCP
    
  2. Ask: Install the stig-mcp knowledge base. This is a one-time download of about 6 MB. Allow the tool when Claude Code asks.

If that doesn't work, see troubleshooting or setting up Claude Code by hand.

Example prompts

With the knowledge base installed, try:

  1. What DISA STIG steps mitigate T1078 on Windows 11?
  2. Which ATT&CK techniques does APT29 use?
  3. Which STIG benchmarks apply to RHEL 9?

More example prompts are in the user guide, with how to get more out of it and how to make sure the agent answers from the server.

Other MCP clients

Use this only if you are not using VS Code or Claude Code. Any client that launches a local (stdio) MCP server works with this configuration, shown in the common mcpServers shape:

{
  "mcpServers": {
    "stig-mcp": {
      "command": "uvx",
      "args": ["stig-mcp"],
      "env": { "UV_SYSTEM_CERTS": "true", "UV_NATIVE_TLS": "true" }
    }
  }
}

The two environment variables let uv download stig-mcp behind a TLS-inspecting proxy. They are harmless on most other hosts; that section names the one exception. Then ask the agent to install the stig-mcp knowledge base, as in the quick start.

docs/install.md has the details:

What this server fetches

  • The MCP server contacts nothing unless check_sources or install_knowledge_base is called. Then it sends HTTPS GET requests to api.github.com (this repository's release listing) and github.com (/jeneric/STIG-MCP/releases/download/...), which redirects to release-assets.githubusercontent.com or objects.githubusercontent.com. Any other URL, a redirect included, is refused. Nothing is uploaded, and there is no telemetry. install_knowledge_base given a file path and its SHA-256 requests nothing at all.
  • stig-mcp-install-kb contacts the same hosts, and nothing at all with --file.
  • stig-mcp-fetch, used only to build the knowledge base yourself, downloads from raw.githubusercontent.com and api.github.com (MITRE ATT&CK, the CTID mapping, the NIST 800-53 catalog) and from dl.dod.cyber.mil (DISA).

PRIVACY.md states what each of these requests sends and what is stored locally.

Documentation

  • docs/install.md: installation details for every client, where the data lives, and troubleshooting.
  • docs/user-guide.md: for a person talking to an LLM that has this server wired in.
  • docs/operations.md: for whoever installs, builds and maintains the knowledge base.
  • SECURITY.md: reporting a vulnerability, and what is in scope.
  • CONTRIBUTING.md: working from a source checkout, running the tests, and the project's conventions.
  • RELEASING.md: for the maintainer, publishing the package to PyPI and the MCP Registry.
  • PRIVACY.md: what the server and the fetch tool contact, and what is stored locally.

Third-party content

The knowledge base aggregates MITRE ATT&CK, CTID mapping, DISA STIG, DISA CCI list, and NIST OSCAL content. See NOTICE for attribution and licensing obligations and licenses/apache-2.0.txt for the Apache 2.0 license text that notice requires.

Development

Developed with the assistance of Claude Code (Anthropic). All changes were reviewed and tested by the maintainer.

Reviews

No reviews yet

Be the first to review this server!