
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
Official ACF® Model Context Protocol server — Agentic Commerce Framework governance copilot for AI assistants.
Official ACF® Model Context Protocol server. Agentic Commerce Framework® — first open governance standard for autonomous AI agents.
ACF Standard · Compliance · Teaching toolkit
acf-mcp exposes the ACF® doctrine — 4 principles, 4 autonomy levels, 6 maturity dimensions, the DDAO role, 17 methodological cards, 5 expert regulatory guides (AI Act, GDPR, DORA, NIS2, ISO 42001), the white paper and the glossary — as native MCP Resources, Tools and Prompts so any MCP client (Claude Desktop, Cursor, Windsurf, Continue…) can reason on top of it.
It also ships 7 deterministic REASON tools (built on a versioned knowledge base — no internal LLM call) that take a user case and return a structured ACF® governance assessment:
acf.advisor — generic case → structured advice (autonomy + risk + principles + fiches + first actions)acf.classify-agent — killer tool: 10-field qualified-enum input → preliminary qualification (ACF level + criticality + AI Act role + GDPR status + obligations by lifecycle + DDAO controls + sign-off requirements)acf.assess-autonomy — N0-N3 recommendation with go/no-go + gating + kill switch designacf.identify-governance-gaps — 6-dimension maturity score + prioritised remediationacf.map-ai-act-obligations — full obligation set structured by lifecycle phase (pre-go-live / continuous / on-incident) with Digital Omnibus deferralsacf.assign-ddao-controls — level × risk → recommended + ACF-canonical controlsacf.evaluate-agent-mandate — 8-check audit of an existing mandateEvery REASON output is signed: doctrine_version, doctrine_hash, doctrine_archive_url, regulatory_snapshot, generated_at. Every REASON output is positioned as preliminary qualification, not legal advice — requires_human_review: true is constant in V1.0.
# Claude Desktop, Cursor, Windsurf:
npx -y acf-mcp
Add to Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"acf": {
"type": "stdio",
"command": "npx",
"args": ["-y", "acf-mcp"]
}
}
}
No API key — V1.0 is open access (cf. Position stratégique in the spec).
acf-mcp is a local stdio server — there is no hosted HTTP endpoint to configure; it runs on the client via npx (above). Find it through:
acf-mcpio.github.acfstandard/acf-mcpacf-mcpV1.0 ships FR + EN translated. The 11 other locales (es, de, pt, it, nl, ru, ar, tr, ja, zh, ko) are infrastructure-supported but fallback to EN with _meta.is_fallback: true signalled. Full translation comes in V1.3 with native juristic review per jurisdiction.
Every REASON output embeds:
doctrine_version — e.g. "ACF framework v1.0 / rules 2026-06"doctrine_hash — sha256 of the active content + rules at call timedoctrine_archive_url — permanent archive of the doctrine version usedregulatory_snapshot — corpus that was reasoned againstgenerated_at — ISO 8601 timestampAn audit can reconstruct the exact analysis produced at instant T by loading the archive URL.
MIT. See LICENSE.
Dorange, V. (2026). Agentic Commerce Framework® (ACF®). ACF Standard.
https://acfstandard.com
Issues + PRs welcome on https://github.com/acfstandard/acf-mcp. Developer documentation: https://acfstandard.io. Doctrine modifications go through the maintainer review process.
FAQs
Official ACF® Model Context Protocol server — Agentic Commerce Framework governance copilot for AI assistants.
The npm package acf-mcp receives a total of 0 weekly downloads. As such, acf-mcp popularity was classified as not popular.
We found that acf-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.