
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
summitflow-mcp
Advanced tools
Grant management MCP server — deadline planning, business-day math, grant budgets with correct indirect base, volunteer and in-kind valuation. No API key.
Grant management tools for AI agents. Plan backward from a funder deadline, count business days around federal holidays, build a grant budget with indirect on the correct base, and value volunteer and in-kind contributions.
No API key. No account. No network calls. Every tool is a pure function.
Web versions of these tools live at summitflow.co/tools.
Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"summitflow": {
"command": "uvx",
"args": ["summitflow-mcp"]
}
}
}
Or pip install summitflow-mcp. No environment variables required.
| Tool | What it does |
|---|---|
grant_deadline_plan | Works backward from a deadline to start-drafting, internal-review and packet-complete dates |
grant_lead_times | The lead times behind that plan, with the reasoning for each |
business_days_between | Business days between two dates, skipping weekends and US federal holidays |
add_business_days | Add or subtract business days from a date |
federal_holidays | US federal holidays for a year, with observed dates |
grant_budget | Full budget with fringe and indirect calculated on MTDC or TDC |
volunteer_time_value | Volunteer hours valued at the published national rate |
in_kind_value | Totals donated goods and services at fair market value |
summitflow_resources | Free templates, guides and calculators on the web |
Indirect goes on the right base. grant_budget defaults to Modified Total
Direct Cost, which excludes equipment and the portion of each contract above the
first $25,000. Applying your rate to total direct costs instead is the most
common budget error and it inflates the ask in a way reviewers notice. The tool
reports which base it used and what it excluded.
Observed holiday dates, not nominal ones. A federal holiday falling on a Saturday closes offices the Friday before. For a deadline calculation that is the difference between submitting on time and submitting late, so all the date math uses observed dates.
The volunteer rate is cited, not invented. volunteer_time_value defaults
to Independent Sector's published national value of volunteer time (2025), and
says so in its output, because a match figure you cannot source is a figure you
cannot defend. Skilled volunteers doing professional work should be valued at
the rate for that work instead.
Deadlines are not plans. grant_deadline_plan returns three earlier dates
because those are the ones that go on a calendar with a person's name attached.
The deadline itself should be uneventful.
git clone https://github.com/RyanKramer/summitflow-mcp
cd summitflow-mcp
pip install -e .
summitflow-mcp
Built by SummitFlow — the grant deadline safety net for small nonprofits. Free templates, guides and calculators.
MIT licensed.
FAQs
Grant management MCP server — deadline planning, business-day math, grant budgets with correct indirect base, volunteer and in-kind valuation. No API key.
We found that summitflow-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.