🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

contract-ops-mcp

Package Overview
Dependencies
Maintainers
1
Versions
10
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

contract-ops-mcp

One MCP server for the whole contract-ops CLI suite — connect once, drive all nine local-first CLIs (extract, draft, lint, compare, convert, review, vault) as agent tools. Signing stays human-gated.

latest
Source
npmnpm
Version
0.3.0
Version published
Weekly downloads
110
-28.1%
Maintainers
1
Weekly downloads
 
Created
Source

contract-ops-mcp

One MCP server for the whole contract-ops CLI suite — wire it up once and an agent (Claude, Cursor, Codex, …) gets all nine local-first CLIs as tools: extract, draft, lint, compare, convert, review, and the template + signed-contract vaults. Signing stays human-gated.

Run this

// e.g. Claude Desktop / Cursor MCP config
{
  "mcpServers": {
    "contract-ops": { "command": "npx", "args": ["-y", "contract-ops-mcp"] }
  }
}

The CLIs themselves must be installed (the server shells out to them). Fastest way to get all nine:

curl -fsSL https://cli.drbaher.com/install.sh | sh     # local
# …or run the server + CLIs in one container: ghcr.io/drbaher/contract-ops

Call suite_status any time to see which CLIs are present and how to install any that aren't.

Tools

Curated, ergonomic tools (typed inputs, JSON out) for the common operations, plus two escape hatches for the long tail:

ToolWhat it does
extract_contractAny contract (.md/.txt/.html/.docx/.pdf) → structured JSON (parties, dates, clauses, …)
lint_contractInternal-consistency findings (placeholders, broken refs, defined-term/numbering/date defects)
compare_versionsClause-aware drift between two versions (exit 0 clean · 2 substantive · 3 cosmetic · 4 moved)
fill_templateFill a template's placeholders with typed params (deterministic)
convert_to_pdfDOCX → PDF (needs a PDF backend, e.g. LibreOffice)
review_ndaScore an NDA against a house playbook, with evidence
template_vault_find / template_vault_getSearch / resolve versioned templates (read-only)
contract_vault_query / contract_vault_due / contract_vault_riskQuery the signed-contract register; project renewal/notice deadlines; renewal-exposure (read-only)
verify_signature / verify_receipt / audit_showVerify a signed PDF / a receipt bundle / walk the audit log (read-only)
catalog(cli)Return any CLI's full --catalog json — discover the long tail
run(cli, args)Escape hatch: run any suite CLI with raw args (no shell)
suite_statusWhich CLIs are installed (+ versions) and how to install the rest

The curated set and catalog/run are discovery-driven — they ride the suite's uniform --catalog json contract, so they stay in sync as the CLIs evolve.

Safety

  • Signing is human-gated. Only sign-cli's read/verify operations are exposed (verify_signature, verify_receipt, audit_show) — never request-create or sign. This is enforced: the run/catalog escape hatches reject any sign subcommand outside a read-only allowlist, so request-create/send/sign/approve can't be reached here. Those stay behind sign-cli's own MCP server with its per-signer approval tokens, so this server can't become an unguarded signing path.
  • Filesystem lockdown. File-path arguments to the curated tools are confined to CONTRACT_OPS_MCP_BASE_DIR (default: the working directory). Set it to widen the sandbox.
  • No shell. CLIs are invoked with execFile (no shell interpolation).

License

MIT. Part of the contract-ops CLI suite. See AGENTS.md for the agent contract.

Keywords

contract-ops

FAQs

Package last updated on 15 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts