The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Air Blackbox MCP listing page.
EU AI Act compliance scanning for Claude Desktop, Claude Code, Cursor, and any MCP-compatible client.
Unlike other compliance scanners that only report problems, AIR Blackbox also remediates - generating working code fixes, trust layer integrations, GDPR compliance checks, bias analysis, and full compliance reports. Under the hood, the scanning feeds into air-trust, a cryptographic audit chain (HMAC-SHA256) with Ed25519 signed handoffs that ensures compliance data integrity.
| Tier | Tool | What it does | Requires SDK |
|---|---|---|---|
| Scanning | scan_code | Scan Python code string for all 6 EU AI Act articles | No |
| Scanning | scan_file | Read and scan a single Python file | No |
| Scanning | scan_project | Recursively scan all .py files in a directory | No |
| Analysis | analyze_with_model | Deep analysis via local fine-tuned model (Ollama) | No |
| Analysis | check_injection | Detect prompt injection attacks (15 patterns) | No |
| Analysis | classify_risk | Classify tools by EU AI Act risk level | No |
| Remediation | add_trust_layer | Generate trust layer integration code | No |
| Remediation | suggest_fix | Get article-specific fix recommendations | No |
| Documentation | explain_article | Technical explanation of EU AI Act articles | No |
| Documentation | generate_compliance_report | Full markdown compliance report | No |
| GDPR | scan_gdpr | GDPR-specific compliance scan | Yes |
| Bias | scan_bias | Bias and fairness analysis | Yes |
| Validation | validate_action | Validate agent actions before execution (Article 14) | Yes |
| History | compliance_history | View past scans, trends, and compliance scores | Yes |
LangChain, CrewAI, AutoGen, OpenAI, Haystack, LlamaIndex, Semantic Kernel, Google ADK, Claude Agent SDK, and generic RAG pipelines.
Works standalone with just the lightweight built-in scanner.
Installs the full air-blackbox SDK (>=1.13,<2) for advanced compliance
features. The floor is the version this package is tested against, and the
major cap means a 2.x SDK cannot silently change your findings.
This package supports both MCP SDK generations — mcp>=1.0, no upper bound.
mcp 2.0 removed mcp.server.fastmcp and replaced FastMCP with MCPServer.
Rather than pin away from it, the server detects which generation is installed
and binds to the right class, so it runs on 1.x and 2.x alike:
| installed | server class |
|---|---|
mcp 1.x | FastMCP |
mcp 2.x | MCPServer |
Both paths are covered by tests that launch python -m air_blackbox_mcp as a
real subprocess and drive it over stdio — the same way Claude Desktop and
Cursor do — and the full suite runs green on both.
If you are on 0.2.3, upgrade. That version declared an unpinned
mcp>=1.0.0, so once mcp 2.0 shipped, every fresh install produced a server
that died on import:
0.2.4 fixed it by capping at mcp<2; 0.3.0 removes the cap entirely, so this
server no longer conflicts with anything built for mcp 2.x sharing the same
environment.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json:
Restart Claude Desktop. The 14 tools will appear automatically.
Add to .cursor/mcp.json in your project:
Or add to .claude/mcp.json for Claude Code.
In Claude Desktop, Claude Code, or Cursor, just ask:
send_email"The full air-blackbox SDK unlocks 4 additional tools:
GDPR Scanning (scan_gdpr)
Bias Analysis (scan_bias)
Action Validation (validate_action)
Compliance History (compliance_history)
For AI-powered analysis beyond regex patterns:
Other MCP compliance tools only scan. AIR Blackbox:
Which engine runs is fixed per tool, not a runtime fallback. Earlier versions of this README described a "try the SDK first, fall back to built-in" pattern. That was never what the code did, and it mattered: a reader could not tell whether two reports came from the same rules. The actual behavior:
| Tools | Engine | If the SDK is missing |
|---|---|---|
Tiers 1–4 (scan_code, scan_file, scan_project, check_injection, classify_risk, …) | Always the built-in rule-based scanner | No effect — these never use the SDK |
Tier 5 (scan_gdpr, scan_bias, validate_action, compliance_history) | Always the full air-blackbox SDK | Explicit error telling you to install [full] |
So a given tool produces results from the same engine on every install, and there is no silent switch between engines.
Because a compliance finding is only comparable to another if you know what
produced it, every machine-readable result carries a provenance block:
engine — builtin-rules or air-blackbox-sdk, whichever actually ran.ruleset_version — a content hash of the active rules, not a hand-maintained
string. Change a regex and it changes by itself; a version someone must
remember to bump is one that eventually misreports which rules ran.sdk_version — the SDK that produced this result, so it is null for
built-in results even when the SDK is installed alongside. Reporting a
version that contributed nothing would imply its rules ran.Two reports with the same engine + ruleset_version were produced by
byte-identical rules and can be diffed directly. Different values mean the
rules moved, and the diff needs that context to be meaningful.
Errors carry provenance too — knowing which version produced an error is as useful as knowing which version produced a finding.
Install [full] to unlock the Tier 5 SDK tools; the base install works
standalone.
This MCP server is part of the AIR Blackbox ecosystem: