@ariada-org/mcp-server
v0.1.0
Published
Model Context Protocol (MCP) server exposing the ariada OSS accessibility scanner pipeline as discoverable tools for AI coding assistants. Open source under EUPL-1.2.
Maintainers
Readme
@ariada-org/mcp-server
Model Context Protocol (MCP) server that exposes the ariada open-source accessibility scanner as discoverable tools for AI coding assistants (Claude Code, Cursor, Continue, Zed).
Install
npm install -g @ariada-org/mcp-serverQuick start
Configure the server in your AI assistant. Example for Claude Desktop:
{
"mcpServers": {
"ariada": {
"command": "npx",
"args": ["@ariada-org/mcp-server", "--transport", "stdio"],
},
},
}Example for Cursor (.cursor/mcp.json):
{
"mcpServers": {
"ariada": {
"command": "npx",
"args": ["@ariada-org/mcp-server"],
},
},
}Once configured, the assistant can introspect and call four tools, list one prompt template, and read a resource catalogue.
Tools
| Tool | Purpose |
| -------------------------- | --------------------------------------------------------------------------------------------- |
| ariada.scan | Run a single-URL accessibility scan and return a structured report |
| ariada.list-rules | List the rule catalogue (filterable by pack, WCAG, or EN 301 549) |
| ariada.explain-violation | Return canonical explanatory text for a violation ID — never fabricates |
| ariada.suggest-fix | Return a remediation pattern; returns no-known-pattern when the corpus has no canonical fix |
Programmatic use
import { AriadaMcpServer } from "@ariada-org/mcp-server";
const server = new AriadaMcpServer();
const tools = server.listTools();
const out = await server.callTool("ariada.list-rules", { pack: "checkout" });Security
The server applies an SSRF guard before any scan: private-network addresses (RFC 1918, loopback, link-local), IPv6 ULA / link-local, and non-HTTP schemes (file://, data://, javascript://) are refused with structured JSON-RPC errors. Pass --allow-private only when scanning a known local development URL.
The server emits no telemetry and makes no network calls except to the scan target URL.
See SECURITY.md for reporting and supported-version policy.
Transports
| Transport | Status | Notes |
| --------- | ------------------ | -------------------------------------------- |
| stdio | enabled by default | NDJSON-framed JSON-RPC 2.0 over stdin/stdout |
| http | scaffolded | Not enabled in this release |
CLI
ariada-mcp-server --help
ariada-mcp-server --version
ariada-mcp-server --transport stdio
ariada-mcp-server --transport stdio --allow-privateLicense
Source code is licensed under EUPL-1.2 (European Union Public Licence, version 1.2). See LICENSE. Per-file licensing is declared via SPDX headers and REUSE.toml.
Maintainer
Maintained by Alexander Brichkin (Agonist Development AB, Sweden, org.nr 559452-5726).
