Back to Browse

My Eli MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Laws of Malaysia Online: fetch and cite Malaysian principal Acts.

About

MCP server for Laws of Malaysia Online: fetch and cite Malaysian principal Acts.

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-designed, read-only MCP server for fetching Malaysian legislation from a public government portal. The codebase demonstrates strong security practices: no authentication required (appropriate for public data), proper input validation, structured error handling, comprehensive audit logging, and strict read-only access patterns. Permissions are appropriate for the stated purpose—network access to a specific government domain and local caching. Minor code quality observations (broad exception handling in one spot, path traversal handling that is overly defensive) do not materially impact security. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-matematicsolutions-my-eli-mcp": {
      "args": [
        "my-eli-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

my-eli-mcp

An MCP server for Laws of Malaysia Online (lom.agc.gov.my), the Attorney-General's Chambers' official portal for Malaysian federal legislation. It fetches and cites principal Acts, with a verifiable citation on every response.

Part of the MateMatic eu-legal-mcp production line, extended into Asia alongside jp-eli-mcp and sg-eli-mcp. Same citation contract (a stable identifier + a human-readable citation + a source URL), adapted for a jurisdiction with no ELI, no confirmed search API, and a source that publishes only PDF.

Scope. This MVP covers principal Acts only, addressed by their numeric act coordinate (e.g. 883). No free-text search API was found on this portal during discovery; amendments and subsidiary legislation (P.U. (A)/(B) notices) are not yet covered. Every response carries a dataset_note.

Licence. lom.agc.gov.my legislation is official public information published by the Attorney-General's Chambers of Malaysia. This connector relays it with attribution and a source_url.

The tools

ToolWhat it does
my_get_actMetadata for a principal Act by its numeric act coordinate.
my_get_textThe full text of an Act, extracted from the official PDF.
my_coverageDeclare what this connector covers, when each family was captured, and - explicitly - what it does NOT cover. Every gap carries a fallback.

Every response carries the contract: eli_uri (Malaysia has no ELI - this is the durable lom.agc.gov.my act page URL, e.g. https://lom.agc.gov.my/act-detail.php?language=BI&act=883, see eli_note), human_readable_citation (derived from the official PDF's own filename, since the portal carries no separate title metadata), and source_url.

Install

Not yet on PyPI - install from source until the first release ships:

git clone https://github.com/matematicsolutions/my-eli-mcp
cd my-eli-mcp
pip install -e .

Once released, this will be uvx my-eli-mcp.

Configuration via env:

  • MY_ELI_BASE_URL - default https://lom.agc.gov.my
  • MY_ELI_CACHE_DIR - default ~/.matematic/cache/my-eli
  • MY_ELI_AUDIT_DIR - default ~/.matematic/audit

No API key. lom.agc.gov.my is keyless.

Configure (Claude Code / any MCP client)

{
  "mcpServers": {
    "my-eli-mcp": { "command": "my-eli-mcp" }
  }
}

Windows 11 with Smart App Control

Smart App Control blocks unsigned executables, which covers uvx.exe, pip.exe and the my-eli-mcp.exe launcher that pip writes at install time. The python.exe and py.exe from the python.org installer are signed by the Python Software Foundation, so running the module through the interpreter works:

python -m pip install my-eli-mcp
python -m my_eli_mcp

pip.exe is blocked for the same reason, so install with python -m pip, not pip install. If python is not on PATH, use the Windows launcher: py -3 -m my_eli_mcp.

{ "mcpServers": { "my-eli-mcp": { "command": "python", "args": ["-m", "my_eli_mcp"] } } }

Do not turn Smart App Control off to work around this - it cannot be re-enabled without reinstalling Windows.

Governance

  • Public data only - read-only against lom.agc.gov.my; no client data leaves the machine.
  • Audit log - every tool call appends one JSON line to ~/.matematic/audit/my-eli-mcp.jsonl.
  • Vendor-neutral - talks only to lom.agc.gov.my; no LLM provider, no telemetry.
  • Verifiable citations - every response is independently checkable via source_url.

See CONSTITUTION.md and DISCOVERY.md.

Tests

pip install -e ".[dev]"
pytest tests/test_instructions_drift.py -v   # offline
pytest tests/test_smoke.py -v                # hits live lom.agc.gov.my

Licence

Apache-2.0. © Matematic Solutions / Wieslaw Mazur.

Reviews

No reviews yet

Be the first to review this server!