Lobbywatch Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Lobbywatch Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that connects AI models to Lobbywatch.ch, the largest lobby database of the Swiss Federal Parliament — conflicts of interest, lobby groups, access badges, and transparency scores.
Part of the [Swiss Public Data MCP Portfolio](https://github.com/malkreide) — connecting AI models to Swiss public data sources.
"Welche Mitglieder der WBK-N haben Interessenbindungen zu Bildungsverlagen oder privaten Bildungsträgern, und wie ist ihre Transparenz-Bewertung?"
Which members of the National Council's Education Commission have declared conflicts of interest with educational publishers or private education providers, and how does their compensation transparency score compare?
→ More use cases by audience →
Lobbywatch.ch maintains the largest public database on Swiss federal parliamentarians and their connections to lobby organisations: 245 parliamentarians, ~7'800 interessenbindungen (declared mandates), 139 lobby groups, 368 access-badge holders, updated weekly, licensed CC BY-SA 4.0.
lobbywatch-mcp exposes this data to Large Language Models via the Model Context Protocol. It is designed to be used alongside parlament-mcp (the official Swiss Parliament's Curia Vista data): the pair makes it possible to ask what a parliamentarian did officially and who they are connected to — in a single conversation.
dataIF REST API is used only where it returns reliable data (lobby groups, search).stdio for Claude Desktop, streamable-http / sse for cloud deployments. ┌─────────────────────────────┐
LLM client │ LobbywatchClient │
(Claude Desktop, │ │
Inspector, …) │ ┌───────────────────┐ │
│ │ │ Dump cache │ │ cms.lobbywatch.ch
│ MCP │ │ (24 h TTL, │ │ ┌──────────────────┐
▼ stdio / │ │ ~80 MB resident)├─────┼─────►│ weekly JSON │
┌─────────┐ HTTP │ └───────────────────┘ │ │ export (~17 MB) │
│ FastMCP │◄────►│ │ └──────────────────┘
│ server │ │ ┌───────────────────┐ │ ┌──────────────────┐
└─────────┘ │ │ dataIF REST ├─────┼─────►│ /interface/v1/ │
│ │ (live fallback) │ │ │ json/… │
│ └───────────────────┘ │ └──────────────────┘
└─────────────────────────────┘Outbound HTTP runs through a single httpx.AsyncClient with follow_redirects=False, an SSRF guard that blocks RFC1918 / link-local / metadata IPs, and an httpx event hook that re-resolves on every request. The dump path is the primary source of truth for parliamentarian queries; dataIF is only used for lobby group lookups and the search endpoint.
From PyPI (after first release):
pip install lobbywatch-mcpFrom source:
git clone https://github.com/malkreide/lobbywatch-mcp.git
cd lobbywatch-mcp
pip install -e ".[dev]"lobbywatch-mcpThis starts the server in stdio mode. For HTTP:
LOBBYWATCH_MCP_TRANSPORT=http LOBBYWATCH_MCP_PORT=8000 lobbywatch-mcpA hardened multi-stage Dockerfile ships with the repo (non-root, read-only-rootfs compatible). See docs/deployment.md and deploy/docker-compose.example.yml for resource limits, sticky-LB guidance and egress hardening.
docker build -t lobbywatch-mcp:0.2.0 .
docker run --rm -p 127.0.0.1:8000:8000 lobbywatch-mcp:0.2.0Add to your claude_desktop_config.json:
{
"mcpServers": {
"lobbywatch": {
"command": "uvx",
"args": ["lobbywatch-mcp"]
}
}
}A full example is provided in claude_desktop_config.json.
Once connected, try prompts such as:
All tool names use the lobbywatch_ namespace prefix (since 0.2.0) to avoid collisions with sibling portfolio servers.
| Tool | Purpose | Source |
|---|---|---|
lobbywatch_get_parlamentarier(name_or_id) | Full profile + all conflicts of interest | Dump |
lobbywatch_list_interessenbindungen(name_or_id, nur_hauptberuflich, nur_aktiv) | Filtered mandate list | Dump |
lobbywatch_search_parlamentarier_nach_branche(branche_query, kommission, limit) | Cross-filter by industry and commission | Dump |
lobbywatch_get_lobbygruppe(name_or_id) | Lobby group with connected MPs and organisations | Live dataIF |
lobbywatch_get_ranking(kriterium, kommission, partei, limit) | Top-N by criterion | Dump |
lobbywatch_get_transparenzquote(kommission) | Distribution of compensation transparency labels | Dump |
lobbywatch_refresh_dump() / lobbywatch_dump_status() | Cache control | Dump |
All behaviour is controlled via environment variables:
| Variable | Default | Purpose |
|---|---|---|
LOBBYWATCH_MCP_TRANSPORT | stdio | Transport (stdio, http, sse) |
LOBBYWATCH_MCP_HOST | 127.0.0.1 | HTTP bind host (set to 0.0.0.0 only behind an auth gateway) |
LOBBYWATCH_MCP_PORT | 8000 | HTTP bind port |
LOBBYWATCH_MCP_CACHE_DIR | ~/.cache/lobbywatch-mcp | Dump cache location |
LOBBYWATCH_MCP_CACHE_TTL | 86400 (24h) | Cache time-to-live in seconds |
LOBBYWATCH_MCP_HTTP_TIMEOUT | 60 | HTTP timeout in seconds |
LOBBYWATCH_MCP_CORS_ORIGINS | _(unset)_ | Comma-separated origin allow-list for HTTP/SSE; when set, exposes Mcp-Session-Id to browsers |
LOBBYWATCH_MCP_LOG_FORMAT | text | text (stdlib formatter) or json (structured via structlog) |
LOBBYWATCH_MCP_LOG_LEVEL | INFO | DEBUG / INFO / WARNING / ERROR |
LOBBYWATCH_MCP_OTEL_ENABLED | 0 | Set to 1 to enable OpenTelemetry tracing (requires pip install 'lobbywatch-mcp[obs]') |
LOBBYWATCH_MCP_OTEL_ENDPOINT | _(unset)_ | OTLP/HTTP collector endpoint (e.g. http://localhost:4318/v1/traces) |
lobbywatch-mcp/
├── src/lobbywatch_mcp/
│ ├── __init__.py
│ ├── __main__.py # CLI + transport selection
│ ├── config.py # URLs, cache paths, attribution
│ ├── client.py # Dump download + dataIF client
│ ├── models.py # Pydantic v2 response envelopes
│ └── server.py # FastMCP tool registrations
├── tests/
│ ├── conftest.py # Fixture parliamentarians
│ ├── test_client.py # Respx-mocked unit tests
│ ├── test_server.py # Tool integration tests
│ └── test_live.py # @pytest.mark.live — excluded from CI
├── .github/workflows/
│ ├── ci.yml # Test matrix + ruff
│ └── publish.yml # PyPI OIDC Trusted Publisher
├── claude_desktop_config.json
├── pyproject.toml
└── ...The code is released under the MIT License.
The data served through this MCP is © Lobbywatch.ch and licensed under CC BY-SA 4.0. Every response envelope includes the attribution string. Downstream users must:
/table/parlamentarier/... dataIF REST endpoint currently returns empty result sets. The server works around this by using the weekly JSON dump instead.zutrittsberechtigungen (access badges) are not populated in the "essential" dump variant used here. A future release will add a dedicated tool using the non-essential dump.See CONTRIBUTING.md.
See SECURITY.md for the security posture, accepted-risk decisions, and how to report a vulnerability.
See CHANGELOG.md.
MIT License — see LICENSE. Data CC BY-SA 4.0 — see LICENSE § Data notice.
malkreide · GitHub
Part of the [Swiss Public Data MCP Portfolio](https://github.com/malkreide).
<!-- mcp-name: io.github.malkreide/lobbywatch-mcp -->
<!-- BEGIN GENERATED: install -->
Run via uv's uvx — no clone or manual install needed. Add to your MCP client config (mcpServers for Claude Desktop, Cursor and Windsurf; use a top-level servers key for VS Code in .vscode/mcp.json):
{
"mcpServers": {
"lobbywatch-mcp": {
"command": "uvx",
"args": [
"lobbywatch-mcp"
]
}
}
}<!-- END GENERATED: install -->
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.