Access US federal award, recipient, agency, and spending analytics data from USAspending.gov.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 9 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The usaspending-mcp-server MCP server exposes 18 tools, focused primarily on general-purpose capabilities. Its published description reads: "Access US federal award, recipient, agency, and spending analytics data from USAspending.gov". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates usaspending-mcp-server F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check usaspending-mcp-server's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add usaspending-mcp-server to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://usaspending.caseyjhand.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
List all top-tier federal agencies with toptier codes, agency slugs, budget authority amounts, and obligation totals for the current fiscal year. Use this as the entry point for agency navigation — to
Look up valid code values for filter fields by searching free-text descriptions. Use the type parameter to select the lookup table: naics (NAICS industry codes), psc (product/service codes), cfda (CFD
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: usaspending_list_agencies
A tool description tries to alter the model’s use of another tool.
ired inputs for usaspending_get_agency and agency-based filters on spending analysis tRecommendationDescriptions must describe only their own tool.
tool: usaspending_search_awards
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: usaspending_get_award
A tool description tries to alter the model’s use of another tool.
_id values from usaspending_search_awards as input. Recipient hashes can be passed to usaRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_award_transactions
A tool description tries to alter the model’s use of another tool.
d IDs come from usaspending_search_awards (generated_internal_id field).RecommendationDescriptions must describe only their own tool.
tool: usaspending_get_award_subawards
A tool description tries to alter the model’s use of another tool.
baward_count on usaspending_get_award first to confirm subawards exist before callingRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_award_federal_accounts
A tool description tries to alter the model’s use of another tool.
award_id — from usaspending_search_awards (generated_internal_id field) or usaspending_geRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_idv_awards
A tool description tries to alter the model’s use of another tool.
obtainable from usaspending_search_awards (generated_internal_id field) or from usaspendiRecommendationDescriptions must describe only their own tool.
tool: usaspending_search_recipients
A tool description tries to alter the model’s use of another tool.
an be passed to usaspending_get_recipient for full profiles. Recipient level: P = parentRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_recipient
A tool description tries to alter the model’s use of another tool.
h_recipients or usaspending_get_award. Optionally scope the totals to a specific fiscRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_agency
A tool description tries to alter the model’s use of another tool.
both appear in usaspending_list_agencies results and award search results.RecommendationDescriptions must describe only their own tool.
tool: usaspending_spending_by_geography
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: usaspending_spending_by_category
A tool description tries to alter the model’s use of another tool.
ards filters or usaspending_autocomplete_filters lookups.RecommendationDescriptions must describe only their own tool.
tool: usaspending_spending_over_time
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: usaspending_disaster_spending
A tool description tries to alter the model’s use of another tool.
codes appear in usaspending_get_award account_obligations_by_defc and usaspending_getRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_federal_account
A tool description tries to alter the model’s use of another tool.
utput field) or usaspending_get_award_federal_accounts (its federal_account field), and are formattedRecommendationDescriptions must describe only their own tool.
tool: usaspending_get_federal_account_breakdown
A tool description tries to alter the model’s use of another tool.
output field), usaspending_get_award_federal_accounts (its federal_account field), or usaspending_getRecommendationDescriptions must describe only their own tool.
tool: usaspending_search_federal_accounts
A tool description tries to alter the model’s use of another tool.
get detail. Use usaspending_list_agencies to look up agency_identifier codes (3-digit strRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
m. - Start with usaspending_list_agencies or usaspending_autocomplete_filters to discoverRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: usaspending_autocomplete_filters
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_search_awards
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_search_recipients
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_spending_by_geography
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_spending_by_category
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_spending_over_time
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_disaster_spending
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: usaspending_search_federal_accounts
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Search federal awards by keyword, recipient, agency, award type, NAICS code, location, or date range. Returns ranked award summaries including recipient names, amounts, awarding agencies, and generate
Fetch full details of a federal award by its generated unique award ID. Returns contract or assistance award data including recipient info, agency hierarchy, period of performance, place of performanc
List individual transactions (contract modifications, grant amendments) on a federal award. Each transaction represents a change event — obligation modifications, performance period extensions, scope
List subaward contracts or grants under a prime federal award. Reveals the sub-contractor or sub-grantee layer — the organizations that actually perform the work. Each row shows the subaward number, a
List the Treasury federal accounts that funded an award, with the amount obligated from each and the funding agency behind it. This is the award → appropriation link: each row returns federal_account
List child contracts and task/delivery orders placed under an IDV (Indefinite Delivery Vehicle) award. Each row includes the generated_unique_award_id to chain into usaspending_get_award for full deta
Search for organizations or individuals receiving federal funds by name, UEI (Unique Entity Identifier), or DUNS. Returns recipient hash IDs, UEI/DUNS identifiers, total award amounts, and hierarchy l
Fetch a recipient's full profile including address, business type codes, parent organization, alternate names, and total transaction and loan amounts. Recipient IDs are UUID hashes with a level suffix
Fetch an agency's fiscal-year overview including mission, budgetary resources, obligation and outlay totals (for the most recent fiscal year), sub-agency count, and DEF codes for disaster/emergency fu
Aggregate federal spending by state, county, or congressional district. Useful for per-capita analysis, regional comparisons, and mapping federal investment patterns. Geographic filters accept FIPS co
Aggregate federal spending grouped by a specific dimension: NAICS industry code, PSC product/service code, awarding agency, funding agency, CFDA assistance program, or recipient. Returns top items wit
Fetch aggregated federal obligation amounts grouped by fiscal year, fiscal quarter, or fiscal month. All grouping is relative to the US government fiscal year (Oct–Sep), so fiscal month 1 is October,
Fetch disaster and emergency supplemental spending (COVID-19, hurricanes, infrastructure law, etc.) broken down by agency, CFDA assistance program, recipient, or geography. Use the dimension parameter
Fetch a federal account's budget data: total obligations, gross outlays, and budgetary resources, plus the per-Treasury-Account-Symbol (TAS) component breakdown in children. Federal accounts connect a
Fetch a federal account's obligations broken down by program activity (what the money funds) or object class (what it buys — personnel, supplies, contracts). Use the dimension parameter to select the
List and keyword-search federal accounts by agency identifier or title keyword. Returns account numbers, names, managing agencies, and budgetary resources. Use account_number from results as input to