Atlas / MCP servers / jamesanz / US Legal

US LegalSAFE

mcp/jamesanz/us-legal

An MCP server that provides comprehensive US legislation.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
18 17r · 1w · 0d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Comprehensive US legal data in your AI workflow. Search Congress bills, Federal Register documents, court opinions, and committees. No API keys required (optional for enhanced access).

An MCP (Model Context Protocol) server that brings authoritative US legal information into AI coding environments like Cursor and Claude Desktop.

Why Use US Legal MCP?

  • 🆓 No API Keys Required – Works out of the box (optional keys for enhanced access)
  • 🎯 Jev High-Confidence Filter – Optional TypeSafe Jev scoring drops poor matches
  • 📜 Comprehensive Sources – Congress, Federal Register, CourtListener
  • ⚡ Easy Setup – One-click install in Cursor or simple manual setup
  • 🔍 Multi-Source Search – Search across all legal sources simultaneously
  • 📊 Real-time Data – Recent bills, regulations, and court opinions

Quick Start

Ready to explore US legal data? Install in seconds:

Install in Cursor (Recommended):

🔗 Install in Cursor

Or install manually:

npm install -g us-legal-mcp
# Or from source:
git clone https://github.com/JamesANZ/legal-mcp.git
cd legal-mcp && npm install && npm run build

Features

📜 Congress.gov

  • `search-congress-bills` – Search bills and resolutions
  • `get-recent-bills` – Get recently introduced legislation
  • `get-congress-committees` – List Congressional committees

📋 Federal Register

  • `search-federal-register` – Search regulations and executive orders
  • `get-recent-regulations` – Get recently published documents

⚖️ CourtListener

  • `search-court-opinions` – Search court opinions (federal and state)
  • `get-recent-court-opinions` – Get recent court decisions

🎯 Jev Relevance Filter (optional)

When TYPESAFE_API_KEY (or JEV_API_KEY) is set in the

Read from source at commit f55f3f0906f0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add us-legal-mcp --env CONGRESS_API_KEY=${CONGRESS_API_KEY} --env COURT_LISTENER_API_KEY=${COURT_LISTENER_API_KEY} --env GOVINFO_API_KEY=${GOVINFO_API_KEY} --env JEV_API_KEY=${JEV_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "us-legal-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CONGRESS_API_KEY": "${CONGRESS_API_KEY}",
        "COURT_LISTENER_API_KEY": "${COURT_LISTENER_API_KEY}",
        "GOVINFO_API_KEY": "${GOVINFO_API_KEY}",
        "JEV_API_KEY": "${JEV_API_KEY}"
      }
    }
  }
}
03

Exposed tools (18)

17 read · 1 write · 0 destructive.

ToolRiskDescription
get_bill_actionsreadChronological actions (newest first) for a specific bill from Congress.gov. Identify via billId or congress+type+number.
get_bill_detailsreadFetch live bill metadata from the Congress.gov API (sponsors, latest action, policy area, linked endpoints). Identify the bill by billId (e.g.
get_bill_textreadList available text versions (Introduced, Engrossed, Enrolled, etc.) with PDF/HTML/XML download links for a bill.
get_clarity_act_inforeadCurated reference for the Digital Asset Market CLARITY Act (H.R.3633, 119th Cong.). Returns status, timeline, sponsor, key provisions, agency jurisdiction (SEC/CFTC), and source links. For live bill actions use get_bill_actions with billId
get_congress_committeesreadGet list of Congressional committees
get_curated_actreadReturn a curated reference record for a major US digital-asset act by slug.
get_genius_act_inforeadCurated reference for the GENIUS Act (Guiding and Establishing National Innovation for U.S. Stablecoins Act, S.1582, 119th Cong., Pub. L. 119-27). Returns status, timeline, sponsors, key provisions, agency jurisdiction, and source links. For live bill actions use get_bill_actions with billId
get_public_law_textreadFetch a Public Law package from GovInfo (summary + optional truncated plain text). Example: congress=119, lawNumber=27 returns the GENIUS Act.
get_recent_billsreadGet the most recently introduced bills in Congress
get_recent_court_opinionsreadGet the most recently published court opinions from CourtListener
get_recent_regulationsreadGet the most recently published Federal Register documents
get_recent_regulator_newsreadRecent press releases / news items from a US financial regulator (OCC, SEC, CFTC, Federal Reserve, Treasury, FinCEN) or all of them.
search_all_legalreadComprehensive search across all US legal sources (Congress, Federal Register, Court Opinions). When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
search_congress_billswriteSearch for bills and resolutions in Congress.gov. When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
search_court_opinionsreadSearch for court opinions and decisions from CourtListener (federal and state courts). When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
search_digital_asset_regulationreadAggregate search across Congress bills, Federal Register, and all regulator news feeds. Scoped to digital-asset / crypto / stablecoin topics. When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
search_federal_registerreadSearch for documents in the Federal Register (regulations, executive orders, etc.). When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
search_regulator_newsreadKeyword search across regulator press-release feeds (OCC, SEC, CFTC, Fed, Treasury, FinCEN). Useful for stablecoin/CBDC/digital-asset monitoring. When TYPESAFE_API_KEY is set, only high-confidence Jev matches are returned.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:270
lnbc1pjhhsqepp5mjgwnvg0z53shm22hfe9us289lnaqkwv8rn2s0rtekg5vvj56xnqdqqcqzzsxqyz5vqsp5gu6vh9hyp94c7t3tkpqrp2r059t4vrw7ps78a4n0a2u52678c7yq9qyyssq7zcferywka50wcy75skjfrdrk930cuyx24rg55cwfuzxs49rc9c53mpz
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, fast-xml-parser, zod, @types/node, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f55f3f0906f0full audit observations/trust-audit/mcp-server/jamesanz__us-legal.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f55f3f0906f0SAFEB89first audit
06

Questions

What is the US Legal MCP server?

An MCP server that provides comprehensive US legislation.

What tools does US Legal expose?

18 in total: 17 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is US Legal safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does US Legal need?

It reads CONGRESS_API_KEY, COURT_LISTENER_API_KEY, GOVINFO_API_KEY, JEV_API_KEY, REGULATIONS_GOV_API_KEY and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does US Legal run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as us-legal-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (f55f3f0906f0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement