🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@mima-ai/governance-mcp

Package Overview
Dependencies
Maintainers
1
Versions
14
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@mima-ai/governance-mcp

MCP server — AI governance evidence for EU AI Act, SOC 2, ISO 42001, and NIST AI RMF

latest
Source
npmnpm
Version
0.1.13
Version published
Maintainers
1
Created
Source

@mima-ai/governance-mcp

MCP server for AI governance — push compliance evidence to Mima from any agent, any stack, 4 lines of config.

One tool call maps to EU AI Act, ISO 42001, SOC 2, and NIST AI RMF simultaneously. Your readiness score updates automatically.

Install

npx @mima-ai/governance-mcp

Or add to your MCP config:

{
  "mcpServers": {
    "mima-governance": {
      "command": "npx",
      "args": ["-y", "@mima-ai/governance-mcp"],
      "env": {
        "MIMA_API_KEY": "mima_ext_...",
        "MIMA_WORKSPACE_ID": "ws-..."
      }
    }
  }
}

10 tools

ToolWhat it does
get_postureOverall readiness score + per-framework breakdown
list_systemsAll AI systems — registered vs unregistered
list_evidenceEvidence records filtered by system and time
dry_run_attestPreview which controls an attestation would earn
attestWrite a GRC evidence record
register_systemRegister an AI system under EU AI Act Art. 9
acknowledge_policyRecord a policy acknowledgment
derive_controlsRecommended evidence types for a system description
check_gatesGate pass/fail status with exit codes
suggest_gatesPrioritised gate recommendations

Usage — Claude Code

Add to ~/.claude/settings.json:

{
  "mcpServers": {
    "mima-governance": {
      "command": "npx",
      "args": ["-y", "@mima-ai/governance-mcp"],
      "env": {
        "MIMA_API_KEY": "mima_ext_...",
        "MIMA_WORKSPACE_ID": "ws-..."
      }
    }
  }
}

Then ask Claude: "Check our compliance posture" or "Register this AI system and suggest which controls we need."

Usage — Cursor / Windsurf

Add to .cursor/mcp.json or .windsurf/mcp.json in your project root:

{
  "mcpServers": {
    "mima-governance": {
      "command": "npx",
      "args": ["-y", "@mima-ai/governance-mcp"],
      "env": {
        "MIMA_API_KEY": "mima_ext_...",
        "MIMA_WORKSPACE_ID": "ws-..."
      }
    }
  }
}

Dry-run support

All write tools support dry-run — preview what controls you'd earn before committing:

dry_run_attest({ record_type: "ai_risk_assessment", system_name: "loan-scorer" })
// → { mapped_controls: ["EUAIA_ART9", "ISO42001_6_1", "NIST_AIRF_MAP_1"] }

Four frameworks, one call

FrameworkWhat it covers
EU AI ActArt. 9–15 risk management, oversight, accuracy obligations
ISO 42001AI management system controls — A.6.x risk, A.9.x performance
SOC 2CC3.x–CC8.x risk, change, and incident management
NIST AI RMFGOVERN, MAP, MEASURE, MANAGE functions

Get an API key

mima.works → sign up → copy your key from the dashboard.

Python SDK

For app-code attestation (decorators, batch pushes, pre-approval gates):

pip install mima-governance

Docs

docs.mima.works

Keywords

mcp

FAQs

Package last updated on 04 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts