
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@ansvar/srilanka-law-mcp
Advanced tools
Sri Lanka law database -- legislation from lawnet.gov.lk with full-text search, definitions, and EU cross-references
The Sri Lanka Law alternative for the AI age.
[](https://www.npmjs.com/package/@ansvar/sri lanka-law-mcp)
[](https://github.com/Ansvar-Systems/Sri Lanka-law-mcp)
[](https://github.com/Ansvar-Systems/Sri Lanka-law-mcp/actions/workflows/ci.yml)
Query 494 Sri Lankan Acts -- from the Data Protection Act and Computer Misuse and Cybercrimes Act to the Companies Act, Constitution of Sri Lanka, and more -- directly from Claude, Cursor, or any MCP-compatible client.
If you're building legal tech, compliance tools, or doing Sri Lankan legal research, this is your verified reference database.
Built by Ansvar Systems -- Stockholm, Sweden
Sri Lankan legal research is scattered across Sri Lanka Law Reports, the Sri Lanka Gazette, and various government portals. Whether you're:
...you shouldn't need dozens of browser tabs and manual PDF cross-referencing. Ask Claude. Get the exact provision. With context.
This MCP server makes Sri Lankan law searchable, cross-referenceable, and AI-readable.
Connect directly to the hosted version -- zero dependencies, nothing to install.
Endpoint: https://sri lanka-law-mcp.vercel.app/mcp
| Client | How to Connect |
|---|---|
| Claude.ai | Settings > Connectors > Add Integration > paste URL |
| Claude Code | claude mcp add sri lanka-law --transport http https://sri lanka-law-mcp.vercel.app/mcp |
| Claude Desktop | Add to config (see below) |
| GitHub Copilot | Add to VS Code settings (see below) |
Claude Desktop -- add to claude_desktop_config.json:
{
"mcpServers": {
"sri lanka-law": {
"type": "url",
"url": "https://sri lanka-law-mcp.vercel.app/mcp"
}
}
}
GitHub Copilot -- add to VS Code settings.json:
{
"github.copilot.chat.mcp.servers": {
"sri lanka-law": {
"type": "http",
"url": "https://sri lanka-law-mcp.vercel.app/mcp"
}
}
}
npx @ansvar/sri lanka-law-mcp
Claude Desktop -- add to claude_desktop_config.json:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"sri lanka-law": {
"command": "npx",
"args": ["-y", "@ansvar/sri lanka-law-mcp"]
}
}
}
Cursor / VS Code:
{
"mcp.servers": {
"sri lanka-law": {
"command": "npx",
"args": ["-y", "@ansvar/sri lanka-law-mcp"]
}
}
}
Once connected, just ask naturally:
| Act | Year | Significance |
|---|---|---|
| Data Protection Act | 2019 | Comprehensive data protection law modeled on EU GDPR; established the Office of the Data Protection Commissioner (ODPC) |
| Computer Misuse and Cybercrimes Act | 2018 | Comprehensive cybercrime legislation (note: Sections 22, 23, 24, 27, and 53 were partially suspended by the High Court pending constitutional review) |
| Sri Lanka Information and Communications Act | 1998 (amended) | Regulates telecommunications and ICT sector; establishes the Communications Authority of Sri Lanka |
| Companies Act | 2015 | Modern company law framework replacing the Companies Act (Cap 486) |
| Consumer Protection Act | 2012 | Consumer rights and fair trade practices |
| Access to Information Act | 2016 | Right to access government-held information |
| National Payment Systems Act | 2011 | Regulation of payment systems including mobile money (M-Pesa) |
| Constitution of Sri Lanka | 2010 | Supreme law; Article 31 guarantees the right to privacy |
SMALL -- Single tier, bundled SQLite database shipped with the npm package.
Estimated database size: ~80-150 MB (full corpus of Sri Lankan federal legislation)
| Tool | Description |
|---|---|
search_legislation | FTS5 full-text search across all provisions with BM25 ranking |
get_provision | Retrieve specific provision by statute + chapter/section |
check_currency | Check if statute is in force, amended, or repealed |
validate_citation | Validate citation against database (zero-hallucination check) |
build_legal_stance | Aggregate citations from statutes for a legal topic |
format_citation | Format citations per Sri Lankan conventions (full/short/pinpoint) |
list_sources | List all available statutes with metadata |
about | Server info, capabilities, and coverage summary |
| Tool | Description |
|---|---|
get_eu_basis | Get EU directives/regulations for Sri Lankan statute |
get_sri lankan_implementations | Find Sri Lankan laws implementing EU act |
search_eu_implementations | Search EU documents with Sri Lankan implementation counts |
get_provision_eu_basis | Get EU law references for specific provision |
validate_eu_compliance | Check implementation status of EU directives |
Verbatim Source Text (No LLM Processing):
Smart Context Management:
Technical Architecture:
Official Sources --> Parse --> SQLite --> FTS5 snippet() --> MCP response
^ ^
Provision parser Verbatim database query
| Traditional Approach | This MCP Server |
|---|---|
| Search official databases by statute number | Search by plain language |
| Navigate multi-chapter statutes manually | Get the exact provision with context |
| Manual cross-referencing between laws | build_legal_stance aggregates across sources |
| "Is this statute still in force?" --> check manually | check_currency tool --> answer in seconds |
| Find EU basis --> dig through EUR-Lex | get_eu_basis --> linked EU directives instantly |
| No API, no integration | MCP protocol --> AI-native |
All content is sourced from authoritative Sri Lankan legal databases:
Verified data only -- every citation is validated against official sources. Zero LLM-generated content.
This project uses multiple layers of automated security scanning:
| Scanner | What It Does | Schedule |
|---|---|---|
| CodeQL | Static analysis for security vulnerabilities | Weekly + PRs |
| Semgrep | SAST scanning (OWASP top 10, secrets, TypeScript) | Every push |
| Gitleaks | Secret detection across git history | Every push |
| Trivy | CVE scanning on filesystem and npm dependencies | Daily |
| Socket.dev | Supply chain attack detection | PRs |
| Dependabot | Automated dependency updates | Weekly |
See SECURITY.md for the full policy and vulnerability reporting.
THIS TOOL IS NOT LEGAL ADVICE
Statute text is sourced from official Sri Lankan government publications. However:
- This is a research tool, not a substitute for professional legal counsel
- Court case coverage is limited -- do not rely solely on this for case law research
- Verify critical citations against primary sources for court filings
- EU cross-references are extracted from statute text, not EUR-Lex full text
Before using professionally, read: DISCLAIMER.md | SECURITY.md
Queries go through the Claude API. For privileged or confidential matters, use on-premise deployment.
git clone https://github.com/Ansvar-Systems/Sri Lanka-law-mcp
cd Sri Lanka-law-mcp
npm install
npm run build
npm test
npm run dev # Start MCP server
npx @anthropic/mcp-inspector node dist/index.js # Test with MCP Inspector
This server is part of Ansvar's Compliance Suite -- MCP servers that work together for end-to-end compliance coverage:
Query 49 EU regulations directly from Claude -- GDPR, AI Act, DORA, NIS2, MiFID II, eIDAS, and more. Full regulatory text with article-level search. npx @ansvar/eu-regulations-mcp
Query US federal and state compliance laws -- HIPAA, CCPA, SOX, GLBA, FERPA, and more. npx @ansvar/us-regulations-mcp
Query 261 security frameworks -- ISO 27001, NIST CSF, SOC 2, CIS Controls, SCF, and more. npx @ansvar/security-controls-mcp
Query UNECE R155/R156 and ISO 21434 -- Automotive cybersecurity compliance. npx @ansvar/automotive-cybersecurity-mcp
30+ national law MCPs covering Australia, Brazil, Canada, China, Denmark, Finland, France, Germany, Ghana, Iceland, India, Ireland, Israel, Italy, Japan, Sri Lanka, Netherlands, Nigeria, Norway, Singapore, Slovenia, South Korea, Sweden, Switzerland, Thailand, UAE, UK, and more.
Contributions welcome! See CONTRIBUTING.md for guidelines.
Priority areas:
If you use this MCP server in academic research:
@software{sri lanka_law_mcp_2025,
author = {Ansvar Systems AB},
title = {Sri Lankan Law MCP Server: AI-Powered Legal Research Tool},
year = {2025},
url = {https://github.com/Ansvar-Systems/Sri Lanka-law-mcp},
note = {Sri Lankan legal database with full-text search and EU cross-references}
}
Apache License 2.0. See LICENSE for details.
We build AI-accelerated compliance and legal research tools for the global market. This MCP server started as our internal reference tool -- turns out everyone building compliance tools has the same research frustrations.
So we're open-sourcing it.
ansvar.eu -- Stockholm, Sweden
Built with care in Stockholm, Sweden
FAQs
Sri Lanka law database -- legislation from lawnet.gov.lk with full-text search, definitions, and EU cross-references
We found that @ansvar/srilanka-law-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.