williamlaverty · MCP server
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ rulings, plus deduction, depreciation, BAS and audit-risk tool
Not claimed by its maker. Is this yours? Prove it and answer the findings
Published because it was found. A finding is information about where the limits are, not a verdict that the software is unsafe.
Receipt history: every signed receipt for every version of this listing, and what changed between them.
Your AI agent, fluent in Australian tax. MCP server with cited answers from 34,500+ ATO documents, the income tax and GST Acts and 4,900+ rulings, plus deduction, depreciation, BAS and audit-risk tools that know your tax profile.
Static scanned
Paste this into your client's MCP configuration.
{
"mcpServers": {
"ato-mcp": {
"command": "npx",
"args": [
"-y",
"ato-mcp@2.2.1"
]
}
}
}Or run it directly.
npx -y ato-mcp@2.2.1Pinned to 2.2.1, which is the version the findings above were found in. Drop the version to take whatever is newest, and the report on this page stops describing what you installed.
1,463 installs last month · build provenance signed · no published advisories · version current · checked 2026-10-05
Built from source, attested
npm publishes a signed statement that this exact package was built from the repository below, at this commit. It is verifiable without taking our word for it.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/ato-mcp)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
Model Context Protocol server for Vanta's security compliance platform
Maintenance
MaintainedA release on 15 Sep 2026 (2.2.1), 8 days before this check on 23 Sep 2026. Anything later would only be more recent.
Read from the npm registry, read by the weekly version refresh.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured