
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@conformy/mcp-server
Advanced tools
EU AI Act & NIS2 compliance — classify AI systems, check NIS2 obligations, and draft compliance documentation
EU AI Act & NIS2 compliance from your AI assistant. Classify AI systems by risk level, check NIS2 cybersecurity obligations, and draft structured compliance documentation — without leaving your editor or chat.
Documents created via MCP are synced with conformy.io — view, edit, and export from either place.
Add to claude_desktop_config.json:
{
"mcpServers": {
"conformy": {
"command": "npx",
"args": ["-y", "@conformy/mcp-server"]
}
}
}
Classification and reference tools work without an API key. For document generation, add your key:
{
"mcpServers": {
"conformy": {
"command": "npx",
"args": ["-y", "@conformy/mcp-server"],
"env": {
"CONFORMY_API_KEY": "your-api-key"
}
}
}
}
Get an API key: Sign up at conformy.io, buy credits, then create a key in your dashboard under API Keys.
{
"mcpServers": {
"conformy": {
"command": "npx",
"args": ["-y", "@conformy/mcp-server"],
"env": {
"CONFORMY_API_URL": "http://localhost:5202"
}
}
}
}
| Tool | What it does |
|---|---|
classify_ai_system | Classify an AI system by risk level (prohibited / high / limited / minimal) with Annex III mapping |
check_deadline | EU AI Act enforcement timeline — days remaining until each deadline |
get_requirements | Required compliance documents by risk level and role (provider / deployer) |
list_annex_iii_categories | All 8 Annex III high-risk categories |
| Tool | What it does |
|---|---|
get_document_template | Full question template for a document type — start here to see what info is needed |
create_document | Create a new compliance document with answers, optionally start AI generation |
list_documents | List all your documents |
get_document | Get a document with all answers and generated sections |
update_document_answers | Update specific answers on an existing document (only send what changed) |
generate_document | Start AI generation — only regenerates sections whose answers changed (smart diffing) |
get_generation_status | Poll generation progress |
generate_document_section | Generate a single section independently |
export_document | Export to PDF or DOCX, saved to ~/Downloads |
| Tool | What it does |
|---|---|
classify_nis2_entity | Classify an organization as essential, important, or not in scope based on sector and size |
list_nis2_sectors | All Annex I (highly critical) and Annex II (other critical) sectors |
check_nis2_obligations | Article 21 risk measures, Article 23 incident reporting, supervision details |
| Tool | What it does |
|---|---|
check_credits | Check your remaining document generation credits |
Document generation uses prepaid credits. 1 credit = 1 AI-generated section.
| Action | Cost |
|---|---|
| Full Annex IV document (9 sections) | 9 credits |
| Edit one answer + regenerate | 1 credit (only changed section) |
| Classification, templates, exports | Free |
Credits work across both the MCP server and conformy.io.
Buy credits at conformy.io/sv/pricing (SEK) or conformy.io/en/pricing (EUR).
Classify an AI system:
"Classify our facial recognition system used for employee access control"
Check NIS2 scope:
"Is our energy company subject to NIS2? We have 300 employees and €80M turnover"
Draft a document:
"Get the Annex IV template, then create a document for our medical imaging AI"
Continue work:
"List my documents and show me the latest Annex IV — I want to update section 3"
Export:
"Export my Annex IV document as PDF"
| Variable | Default | Description |
|---|---|---|
CONFORMY_API_URL | https://api.conformy.io | API base URL |
CONFORMY_API_KEY | — | API key for document generation and account features |
MIT
FAQs
EU AI Act & NIS2 compliance — classify AI systems, check NIS2 obligations, and draft compliance documentation
The npm package @conformy/mcp-server receives a total of 44 weekly downloads. As such, @conformy/mcp-server popularity was classified as not popular.
We found that @conformy/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.