
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
bidcraft-evaluate-mcp
Advanced tools
MCP server for bid/no-bid evaluation — scores RFP opportunities on win probability, strategic fit, resource requirements, competitive positioning, and risk factors to make data-driven pursuit decisions
Bid/no-bid evaluation engine for RFP opportunities. Scores opportunities on 8 dimensions — strategic fit, customer relationship, technical capability, past performance, price competitiveness, resource availability, competitive landscape, and risk profile — to make data-driven pursuit decisions.
Score an RFP/bid opportunity across 8 weighted dimensions and get a clear BID / NO_BID / CONDITIONAL_BID recommendation with confidence level, risk factors, and mitigation strategies.
Rank multiple bid opportunities by expected value, ROI, strategic importance, and urgency. Outputs a prioritized pipeline with pursue/defer/conflict recommendations within your capacity constraints.
Assess your competitive strengths and vulnerabilities against known competitors criterion-by-criterion. Generates ghost strategies and identifies where to emphasize differentiators.
Calculate the full cost of pursuing an opportunity — labor, review cycles, graphics, travel, subcontractor coordination, and materials. Includes ROI analysis and break-even win rate.
Create a structured capture plan with milestone timeline, team assignments, win themes, discriminators, competitive ghost strategies, risk register, and pre-submission checklist.
npx bidcraft-evaluate-mcp
Add to claude_desktop_config.json:
{
"mcpServers": {
"bidcraft-evaluate": {
"command": "npx",
"args": ["-y", "bidcraft-evaluate-mcp"]
}
}
}
Evaluate a bid opportunity:
Use evaluate_opportunity with opportunity_name "DOD Cyber Program", customer "US Army", contract_value 5000000, contract_type "firm_fixed_price", customer_relationship "existing_customer", pct_requirements_met 85, has_key_personnel true, win_probability 45
Compare pipeline opportunities:
Use compare_opportunities with 3-5 opportunities including contract_value, win_probability, strategic_value, and bid_cost for each
Analyze competitive position:
Use analyze_competitive_position with evaluation_criteria, your_scores, and competitor scores to see where you lead and where you're vulnerable
| Dimension | Weight | What It Measures |
|---|---|---|
| Strategic Fit | 15% | Alignment with strategy, market growth, new market entry |
| Customer Relationship | 15% | Incumbent status, existing rapport, access |
| Technical Capability | 20% | Requirements coverage, key personnel, solution maturity |
| Past Performance | 10% | Relevant experience, ratings, references |
| Price Competitiveness | 15% | Price vs market rate, margin adequacy, contract type risk |
| Resource Availability | 10% | Staff availability, hiring needs |
| Competitive Landscape | 10% | Number of competitors, incumbent advantage |
| Risk Profile | 5% | Contract risk, regulatory, protest likelihood |
This MCP server is part of BidCraft — AI-powered RFP proposal generation and bid management platform.
MIT
FAQs
MCP server for bid/no-bid evaluation — scores RFP opportunities on win probability, strategic fit, resource requirements, competitive positioning, and risk factors to make data-driven pursuit decisions
We found that bidcraft-evaluate-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.