Compliance Trestle MCP
MCP server to easily use compliance-trestle (OSCAL tool) from Claude, Roo, or any MCP-compliant client. Its 9 documented tools cover trestle, author, profile, task. It runs locally over stdio via the published package.
People who work with trestle, author and profile and want it reachable from Claude, Cursor, VS Code, or another MCP client. The project is written in Python.
VERIFIED ACTIVE
LAST COMMIT 2026-08-25 · ★ 2 · #100 OF 208 MAINTAINED DOCUMENTATION · VERIFIED 2026-09-18
Apache-2.0 · Python servers · how we verify → /methodology
01 · Install Compliance Trestle MCP
Claude Code
claude mcp add oscal-compass-compliance-trestle-mcp -- uvx compliance-trestle-mcp Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"oscal-compass-compliance-trestle-mcp": {
"command": "uvx",
"args": [
"compliance-trestle-mcp"
]
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as local process (stdio) - runs on your machine with your user's permissions
license Apache-2.0 - declared in the repository
pypi package compliance-trestle-mcp - check the name against the project README before installing (PyPI has no namespace ownership)
registry namespace io.github.oscal-compass is GitHub-verified and matches the repo owner
03 · What Compliance Trestle MCP can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
What you can build
With this server connected, an agent can generate markdown controls from a catalog, generate markdown for profiles, resolve profile to catalog, and convert a CSV mapping file into an OSCAL component definition.
Capability map
Tools grouped from the project's README - what Compliance Trestle MCP lets an agent do.
Trestle
5 tools - e.g. Initialize a trestle workspace; Import OSCAL models (Catalog/Profile/etc.) from a file or URL; Convert a CSV mapping file into an OSCAL component definition
trestle_init · trestle_import · trestle_task_csv_to_oscal_cd · trestle_task_xlsx_to_oscal_poam · trestle_validate
auth & access
4 tools - e.g. Generate markdown controls from a catalog; Generate markdown for profiles; Resolve profile to catalog
trestle_author_catalog_generate · trestle_author_profile_generate · trestle_author_profile_resolve · trestle_author_profile_assemble
Latest releases
v0.2.1 · 2026-08-25
add disclaimer · POA&M support - add trestle_validate and trestle_task_xlsx_to_oscal_poam · add release/publish/validate workflows and single-source the version · New Contributors · @degenaro made their first…
04 · Who maintains Compliance Trestle MCP
compliance-trestle-mcp is maintained by oscal-compass. It's the only MCP server we track from this author; the repo dates to Feb 2026.
05 · Facts
- category
- documentation - ranked #100 of 208 actively-maintained documentation servers as of 2026-09-18.
- release cadence
- 1 release in the last 90 days (latest 2026-08-25)
- registry
- io.github.oscal-compass/compliance-trestle-mcp (active, first published 2026-02-26)
- packages
- pypi:compliance-trestle-mcp
06 · Compliance Trestle MCP FAQ
Is Compliance Trestle MCP still maintained?
Yes - as of 2026-09-18, its last commit was 2026-08-25 and it shipped 1 release in the last 90 days. We re-verify nightly.
What can Compliance Trestle MCP do?
With this server connected, an agent can generate markdown controls from a catalog, generate markdown for profiles, resolve profile to catalog, and convert a CSV mapping file into an OSCAL component definition.
How do I install Compliance Trestle MCP?
Run `uvx compliance-trestle-mcp`. You can also paste the ready-made client config above.
Does Compliance Trestle MCP run locally?
Yes - it's a stdio server: it runs on your machine (via uvx) with your user's permissions. Your data stays local unless the server itself calls external APIs.
07 · Alternatives to Compliance Trestle MCP
Alternatives to Compliance Trestle MCP
Maintained documentation servers if Compliance Trestle MCP isn't the fit.
- Context7 Up-to-date code docs for any prompt ★ 62,152 · 2026-09-18
- Agent Skills Search Server Search and discover Agent Skills from the skills.sh registry. Powered by HAPI MCP server. ★ 25,432 · 2026-08-09
- Repowise Codebase intelligence for AI coding agents - graph, git history, docs, decisions, code health. ★ 6,686 · 2026-09-17
- GitLab MCP GitLab MCP server for projects, merge requests, issues, pipelines, wiki, releases, and more. ★ 1,984 · 2026-09-16
- Microsoft Learn MCP Official Microsoft Learn MCP Server – real-time, trusted docs & code samples for AI and LLMs. ★ 1,892 · 2026-09-10
- Pg Aiguide Comprehensive PostgreSQL documentation and best practices, including ecosystem tools ★ 1,843 · 2026-09-16
Pairs well with
Servers that cover what Compliance Trestle MCP doesn't - only shown when the pairing reason fits the companion.
More documentation MCP servers · TriliumNext (trilium-MCP) · GitLab Docs · ableton-mind - Ableton Live MCP server · Rebuild Dossier · Limps
More Python MCP servers · As A Judge · Ouestcharlie Woof · Cloak MCP · Watch Skill · Global Agent Memory · see all