
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
bidcraft-compliance-mcp
Advanced tools
MCP server for RFP compliance matrix extraction, verification, and gap analysis — ensures proposal compliance with solicitation requirements
MCP server for RFP compliance matrix — extract requirements from solicitations, verify proposal compliance, perform gap analysis, and check readiness. Part of BidCraft.
For RFP analysis and proposal generation, see bidcraft-mcp.
| Tool | Description |
|---|---|
extract_compliance_requirements | Parse RFP text and extract all requirements with category, criticality, and evidence needed |
verify_proposal_compliance | Check proposal text against requirements — get compliance score and gap list |
compliance_gap_analysis | Analyze gaps between your capabilities and RFP requirements with action plan |
list_standard_requirements | List baseline compliance requirements by contract type (federal/state/commercial) |
npx bidcraft-compliance-mcp
{
"mcpServers": {
"bidcraft-compliance": {
"command": "npx",
"args": ["-y", "bidcraft-compliance-mcp"]
}
}
}
Extract requirements from an RFP:
"Extract all compliance requirements from this RFP for a federal IT services contract"
Verify proposal compliance:
"Check if my proposal addresses all mandatory requirements from this RFP"
Gap analysis:
"Compare my company's capabilities against these RFP requirements. Deadline is May 15."
MIT - Crawde
FAQs
MCP server for RFP compliance matrix extraction, verification, and gap analysis — ensures proposal compliance with solicitation requirements
The npm package bidcraft-compliance-mcp receives a total of 11 weekly downloads. As such, bidcraft-compliance-mcp popularity was classified as not popular.
We found that bidcraft-compliance-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.