
CSOAI
Initializing...
Free forever · No credit card

CSOAI
Initializing...
EU AI Act · DORA · NIS2 · CRA · UK AI Bill · Korea AI Basic Act · OASF · EUDI Wallet · MITRE ATT&CK · SBOM · A2A patterns · BFT Council · x402 · Stripe ACP · Care membrane — 14 governance MCPs + 20 A2A MCPs · MIT-licensed, self-hostable via uvx in 10 seconds.
One email when a new MCP lands in the Registry, plus a monthly EU AI Act / DORA / NIS2 enforcement digest. Unsubscribe anytime.
We never share your email. By subscribing you agree to receive monthly MEOK updates. Operated by CSOAI LTD (UK Companies House 16939677).
EU AI Act, DORA, NIS2, CRA, UK AI Bill — purpose-built MCPs for regulated AI deployments.
410 articles from EUR-Lex via FTS5 search, Annex III high-risk classifier, Article 50 transparency, Article 73 incident reporting, 42-point audit, penalty calculator.
uvx eu-ai-act-compliance-mcp
First international standard for AI impact assessment (May 2025). 6 lifecycle phases × 7 impact categories. Cross-walks to EU AI Act Articles + ISO 42001 clauses. Companion to ISO 42001 AIMS.
uvx iso-42005-impact-mcp
Republic of Korea AI Basic Act — in force 22 January 2026. High-impact AI classification, mandatory GenAI labelling, MSIT obligations. Cross-walks to EU AI Act + Japan AI Promotion Act.
uvx korea-ai-basic-act-mcp
EU Digital Operational Resilience Act 5-pillar audit, Article 28 Register of Information, TLPT readiness, incident classification.
uvx dora-compliance-mcp
NIS2 Directive Article 21 risk-management measures, Article 23 incident classification, Article 20 accountability for essential/important entities.
uvx nis2-compliance-mcp
EU CRA Annex I classifier, SBOM generation, vulnerability handling, conformity assessment. Sept 2027 cliff.
uvx cra-compliance-mcp
CycloneDX ML-BOM 1.6 + SPDX 3.0 AI profile, EU AI Act Annex IV mapping, NIST AI RMF alignment.
uvx ai-bom-mcp
Unified incident classification across EU AI Act Art 73, DORA Art 19, NIS2 Art 23, GDPR Art 33, ISO/IEC 42001 — one incident triggers all regime clocks.
uvx ai-incident-reporting-mcp
Article 73 5-clock broadcaster: one incident → simultaneous signed reports to EU AI Act Art 73 + DORA Art 19 + NIS2 Art 23 + GDPR Art 33 + ISO 42001 cl 10.1. Single incident_id drives all 5 regimes from the same detection timestamp. Companion to ai-incident-reporting-mcp.
uvx agent-incident-relay-mcp
Wbni-2 (NL NIS2) registration packet generator. Classifies Annex I essential / Annex II important + size, generates NCSC-NL portal payload + Article 21 attestation. DEADLINE 30 June 2026. Post-deadline: €100K-€10M + director liability.
uvx meok-nis2-nl-register-mcp
EU Cyber Resilience Act Article 14 actively-exploited-vulnerability notifier. 24h/72h/14d three-clock tracker. Generates ENISA + national-CSIRT payload (DE BSI / FR ANSSI / NL NCSC-NL / 7 more). DEADLINE 11 September 2026 — every EU software vendor needs this.
uvx meok-cra-art14-reporter-mcp
C2PA 2.2 (May 2025) Durable Content Credentials — soft + hard binding (Digimarc-compatible). Survives compression, crop, screenshot, adversarial removal. First-mover before Adobe ships official tooling. 3 perceptual methods (Digimarc soft / robust pHash / video pdf-hash).
uvx meok-c2pa-durable-mcp
Auto-generates Fundamental Rights Impact Assessment per Article 27(1) 9 mandatory elements. Triggers for public bodies, private operators of public services, creditworthiness + life/health-insurance pricers. Cross-walks to EDPB DPIA template. £1,500/mo enterprise wedge (consultants charge £20K-£100K manually).
uvx meok-eu-ai-act-art-26-fria-mcp
Provider-side Instructions for Use generator per Article 13(3) — 7 mandatory elements: identity + characteristics + pre-determined changes + Art 14 human oversight + compute lifecycle + log mechanisms + other-relevant. Crosswalks to deployer FRIA. Pairs with meok-eu-ai-act-art-26-fria-mcp.
uvx meok-eu-ai-act-art-13-ifu-mcp
Risk Management System generator per Article 9 — 4-step iteration (identify / estimate / post-market / mitigate) + 12 risk categories + signed Annex IV bundle. Completes the provider-side triple with Art 13 IFU + AI-BOM. Every high-risk AI provider needs an RMS before market placement.
uvx meok-eu-aia-art-9-rms-mcp
EU CDSM Directive Article 4(3) Text + Data Mining opt-out. Issues + scans HTTP/HTML/robots.txt/C2PA reservation signals across 20+ AI agents (GPTBot/ClaudeBot/Google-Extended/etc.). Liability shield: signs each training-run scan with audit-defensible attestation. First-mover — nobody else has shipped this.
uvx meok-w3c-tdm-rights-mcp
Map DORA obligations to NIS2 Article 21-23 measures for dual-compliance scoring. EU banks, insurers, CASPs, CTPPs.
uvx dora-nis2-crosswalk-mcp
Demographic analysis, fairness metrics, mitigation strategies, EU AI Act Article 10 compliance. Signed Article 10 certificates.
uvx bias-detection-mcp
EU AI Act Article 50 watermarking. C2PA manifest generation, AI content detection, signed conformity attestations. Aug 2026 cliff.
uvx watermarking-authenticity-mcp
Dedicated EU AI Act Article 50(2) GenAI watermarking MCP. Visible label + invisible payload + perceptual anchor per the GPAI Code of Practice. 5 modalities (image / text / audio / video / code). C2PA manifest envelope. 2 Aug 2026 cliff.
uvx agent-content-watermark-mcp
EU AI Act Code of Practice 2nd draft (Jan 2026) introduced the EU icon + label spec for AI-generated content. 8 emitters: C2PA 2.2 assertion · HTML meta + link tags · image ICC private tag · audio ID3v2 frames · video keyframe uuid box. First-mover — nobody else ships this.
uvx meok-eu-aigc-icon-mcp
UK AI White Paper 5 principles, AI (Regulation) Bill audit, Algorithmic Transparency Recording Standard, ICO/FCA/MHRA/CMA/Ofcom/HSE guidance.
uvx uk-ai-bill-compliance-mcp
Identity, trust, audit, rate-limiting, handoff, policy enforcement — the substrate for multi-agent systems.
5-voter Byzantine Fault Tolerant council halts agentic loops when 3-of-5 voters agree no real progress is happening. Detects: repetition · identical errors · goal drift · rapid-fire spinning · no artefact growth. The anti-loop guardrail every agent fleet needs. Saves £1-£3 per agent run on free tier; £100-£1,000/mo on Substrate.
uvx bft-progress-council-mcp
Hard per-session spend cap with signed budget-exhausted attestations. 13 pre-loaded model rates. Twin of BFT Progress Council — spend axis vs stall axis. Pays for itself first time it halts an over-spending agent.
uvx agent-token-budget-mcp
Multi-tenant LLM cost attribution for chargeback billing. Splits one agent's spend across many tenants with signed per-tenant chargeback summaries. Companion to agent-token-budget.
uvx agent-cost-allocator-mcp
Coinbase HTTP 402 + on-chain settlement. Agents pay per-call without a Stripe account. USDC on Base/Polygon/Solana + Lightning. Pure HTTP. The plumbing for the agent economy.
uvx agent-x402-paywall-mcp
Bridges Stripe ACP + Google AP2 + Coinbase x402 — the only MCP that covers all 3 live agent-payment protocols. PSD2 + MiCA + 6AMLD + FinCEN BSA overlays. Explicitly addresses the IBM ACP / Stripe ACP name collision.
uvx agent-commerce-protocol-mcp
Bridges Cisco Outshift OASF + AGNTCY Directory under Linux Foundation. Converts MCP server.json and A2A agent-cards into OASF manifests so MEOK agents appear in the enterprise-procurement directory layer. OCI-based schema, capability taxonomy across 7 categories.
uvx oasf-agent-directory-mcp
EU Digital Identity Wallet bridge for AI agents (eIDAS 2.0). Covers ISO/IEC 18013-5 mDoc, W3C Verifiable Credentials 2.0, OID4VC + OID4VP, EUDI ARF v1.7. Selective disclosure (GDPR Art 5 minimisation). The wallet-based agent-identity bridge for 2026 EU deployments.
uvx eudi-wallet-mcp
Step-debugger for agentic loops. Records every action (input, output, model, tokens, ms, cost) so you can replay deterministically. Branch from any step. Search + export + HMAC-sign for audit. Pairs with BFT Progress Council + Audit Logger.
uvx agent-replay-debugger-mcp
Stripe Agentic Commerce Protocol bridge — ChatGPT shopping checkout intents + AP2 mandate crosswalk + PSD2 SCA + signed receipts. 60+ ACP launch partners catalogued (Shopify / Etsy / Instacart / DoorDash / Uber Eats / Expedia / etc.).
uvx meok-stripe-acp-checkout-mcp
Signed on-chain settlement receipts for agentic payments. 7 chains (Base / Polygon / Solana / Lightning / Arbitrum / Optimism / Ethereum). MiCA Article 60 + 64 crosswalk. Stripe ACP intent linkage. Closes the agentic-payment chain — only thing that gives MiCA-defensible proof for x402 / on-chain settlements.
uvx meok-coinbase-x402-receipt-mcp
Linux Foundation AAIF agent identity bridge — publishes /.well-known/agent-card with DID + capabilities + endpoints + trust attestations. Bridges A2A and Cisco OASF manifests to AAIF. First-mover for the AAIF identity spec.
uvx meok-aaif-agent-card-mcp
Google AP2 v0.2.0 — signed user-side spend mandate for agentic commerce. 7 scopes (merchant / category / subscription / negotiation / search / data / A2A). PSD2 SCA crosswalk (passkey strong, SMS weak, Art 13 low-value exemption). MiCA + 6AMLD overlays.
uvx meok-ap2-mandate-mcp
1-line USDC paywall for any FastMCP tool. One decorator turns any tool into a pay-per-call endpoint settled in USDC on Base / Polygon / Solana or BTC on Lightning. The minimal wrapper that Coinbase + Cloudflare + Vercel never shipped.
uvx meok-x402-wrap-mcp
The WAF for AI agents — scans prompts, RAG docs, tool args, A2A payloads for OWASP LLM01 prompt injection BEFORE they reach a downstream agent.
uvx agent-prompt-injection-firewall-mcp
GDPR Chapter V transfer-basis runtime guard for A2A. Adequacy decisions, SCCs, BCRs, EU AI Act Article 10 data governance.
uvx agent-data-residency-mcp
Verifiable agent-to-agent task handoff with signed provenance chain. Non-repudiable A2A delegation.
uvx agent-handoff-certified-mcp
Per-agent-pair IAM for A2A. Define policies, gate every call via evaluate_call. EU AI Act Art 14 + ISO 42001 Annex A.7 evidence.
uvx agent-policy-enforcement-mcp
Hash-chained HMAC-signed audit log MCP for A2A calls. EU AI Act Art 12 + DORA Art 17 + ISO 42001 clause 9 auditor-ready evidence.
uvx agent-audit-logger-mcp
Fleet-wide shared rate limiter for A2A + multi-MCP deployments. Sliding window + concurrency grants + signed enforcement attestations.
uvx agent-rate-limiter-mcp
Connects A2A protocol traffic to governance/audit infrastructure. Bridges agent-to-agent calls into compliance evidence chains.
uvx a2a-governance-bridge-mcp
Agent-to-agent payment rails with PSD2 + EU MiCA-compliant transfer attestation.
uvx agent-commerce-payments-mcp
Capability-scoped delegation between agents. Time-bounded, audit-logged, revocable.
uvx agent-delegation-mcp
Cryptographic agent identity with W3C DID + verifiable credentials. Trust scores per agent endpoint.
uvx agent-identity-trust-mcp
Auction + bidding protocol primitives for multi-agent coordination. Signed negotiation transcripts.
uvx agent-negotiation-mcp
Workflow orchestration over A2A — sequence, branch, retry across heterogeneous agents.
uvx agent-orchestrator-mcp
The mesh substrate UNDER A2A / ACP / AP2 / x402. Mint a libp2p PeerID (Ed25519), compose / parse multiaddrs, sign + verify Agent Records, derive deterministic GossipSub topics. The same stack IPFS / Ethereum / Filecoin / Polkadot use — now wired for agents. Lets agents discover + reach each other without a central registry.
uvx meok-libp2p-agent-mesh-mcp
Read-only blockchain query bridge for crypto-AI agents. Built-in registry of 10 Cosmos mainnets (Cosmos Hub, Osmosis, Celestia, dYdX, Neutron, Injective, Sei, Akash, Stride, Kava) + custom RPC. ABCI 1.0 + ABCI++ vote extensions (CometBFT 0.38). HMAC-signed query results. No signing, no private keys — safe by construction. Pairs with libp2p mesh + AAIF identity + AP2 payments.
uvx meok-abci-bridge-mcp
AI gateway, ops, self-audit, and the Care Membrane safety scoring.
Civilian open-source geospatial awareness — wraps ESA Copernicus Sentinel-1/2/3/5p + OpenStreetMap + Overture Maps + Ordnance Survey UK + INSPIRE EU + DEFRA behind one MCP. Care Membrane ethics gate refuses high-risk targeting/surveillance queries.
uvx gods-eye-geospatial-mcp
Unified gateway for multi-LLM routing — Claude, GPT, Gemini, Llama, local — with cost + latency observability.
uvx ai-gateway-mcp
Continuous internal compliance audit — reads policy + checks every agent action against rule set.
uvx ai-self-audit-mcp
AI runtime observability — token usage, cost, latency, error rates, drift detection.
uvx ai-ops-mcp
6-dimension Noddings care score + sovereignty + dignity scoring on every response. Portable safety eval.
uvx care-membrane-mcp
Artificial Intelligence and Data Act (Canada) compliance audit + Annex disclosure tools.
uvx canada-aida-ai-mcp
SBOM, MITRE ATT&CK + ATLAS, Sigstore, SLSA — supply-chain integrity for AI.
SBOM generation in CycloneDX 1.6 + SPDX 2.3. Required by EO 14028, NIS2, CRA. Signed attestations.
uvx sbom-cyclonedx-mcp
Haulage, skip hire, construction ISO 19650 — UK trade-specific compliance.
UK Operator Licence, tachograph, drivers' hours, DVSA roadside checks for 3.5T+ goods vehicles.
uvx haulage-uk-compliance-mcp
UK Waste Carrier Registration, EA waste codes, hazardous waste consignment notes for skip hire + waste transport.
uvx skip-hire-ai-mcp
ISO 19650 / UK BIM Level 2 compliance. EIR, BEP, MIDP, TIDP, CDE structure validation.
uvx construction-iso-19650-mcp
API docs, testers, changelog automation, accessibility audits — the boring-but-essential layer.
Audits any MCP server.json against the official Model Context Protocol spec (2025-12-11). Linting for required fields, semver, slug pattern, recommended fields, naming conventions. HMAC-signed conformity reports — meta-viral for every MCP author.
uvx mcp-spec-compliance-mcp
Automated security red-team for any MCP server. Maps OWASP LLM Top 10 (2025) + 5 MCP-specific risks (tool spoofing, privilege exposure, plain-HTTP resources, ungated destructive verbs) to a 0-100 hardening score with HMAC-signed reports. Every MCP author wants this before publishing — every consumer wants it before loading.
uvx meok-mcp-hardening-mcp
Drop-in test harness for any MCP server. Golden-file diff, schema-drift detection (breaking-change flag), tool-name + description + JSON-Schema validation, idempotency check, pytest template generator, HMAC-signed test report with Shields.io grade badge. Thousands of MCPs ship zero tests — this is the pre-publish gate every author has been missing.
uvx meok-mcp-test-mcp
Validates the cross-vendor coding-agent spec (AGENTS.md — Cursor / Claude Code / Cline / Windsurf / Aider / OpenAI Codex, stewarded by AAIF). Required-section gate, security smells (hardcoded secrets / dangerous instructions), consistency with package.json + pyproject.toml + Makefile. Generates passing templates for 6 project types.
uvx meok-agents-md-lint-mcp
One MCP that routes to the whole MEOK fleet. Holds 62 MEOK MCPs (plus your own registered ones) behind a single namespaced endpoint — solves the Claude Code / Cursor tool-count ceiling. Bundle subsets by category, HMAC-sign multi-MCP call chains.
uvx agent-mcp-router-mcp
Generate signed .well-known MCP server cards in all 3 SEP shapes (1649 + 1960 + 2127). Claude Desktop 2.1 + Cursor 2026.4 auto-discover MCPs via these. The gap is ~2,000 MCPs on the registry don't have cards. Drop into any static-file host.
uvx meok-mcp-cardgen-mcp
OpenAPI 3.1 + AsyncAPI 3.0 spec → human-readable docs with example payloads.
uvx api-docs-generator-ai-mcp
Generate test suites for any OpenAPI spec — happy path + edge cases + load tests.
uvx api-tester-ai-mcp
Keep-a-Changelog generator from git history + PR descriptions. Semver-aware.
uvx changelog-ai-mcp
Generate GitHub Actions / GitLab CI / Jenkins pipelines from a project description.
uvx ci-cd-generator-ai-mcp
WCAG 2.2 AA audit + remediation suggestions for any web page or component.
uvx accessibility-ai-mcp
Backup policy + RPO/RTO calculator + restore-test scheduler.
uvx backup-ai-mcp
EVM contract analysis, gas optimisation, Solidity audit primitives.
uvx blockchain-ai-mcp
Verify on-chain attestations, signatures, and proof-of-existence claims.
uvx blockchain-verification-mcp
Sector-specific MCPs from agriculture to accounting.
Farm-robotics command + telemetry for spray, harvest, weed-control robots.
uvx agriculture-robotics-mcp
ADS-B + Mode S aircraft tracking, NOTAM lookup, conflict detection.
uvx airspace-monitor-mcp
Double-entry bookkeeping primitives, VAT/Sales tax computation, P&L generation.
uvx accounting-ai-mcp
Brand-voice-constrained ad copy generation for Google + Meta + LinkedIn.
uvx ad-copy-ai-mcp
Text-to-ASCII rendering for CLI banners, READMEs, retro art.
uvx ascii-art-ai-mcp
Household + small-business budgeting with category breakdowns and trend forecasting.
uvx budget-planner-ai-mcp
Smart scheduling across multiple calendars, conflict resolution, prep-time blocks.
uvx calendar-ai-mcp
SaaS churn prediction from usage + billing + support signals.
uvx churn-predictor-ai-mcp
Self-host MIT for free. £29/mo Starter adds HMAC-signed attestations. £149/mo Pro adds 24h SLA. £999/mo Defence adds SLA + multi-BU separation + reseller white-label.
Built solo in Lincolnshire, UK · CSOAI LTD trading as MEOK AI Labs · UK Companies House 16939677 · Apache 2.0 / MIT · hello@meok.ai