Reported issues for sanctions-screening-mcp-server
Pod holds 17 of 30 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to sanctions-screening-mcp-server.
Most discussed
bug(matching): fuzzy hard-cap results are not page-retrievable
Server version
0.1.10
mcp-ts-core version
^0.11.5
Runtime
Bun
Runtime version
Bun 1.3.14
Transport
HTTP (Streamable HTTP)
OS
macOS 26.1
Description
sanctions_screen_name and sanctions_resolve_entity truncate a fuzzy pass to SANCTIONS_FUZZY_MAX_RESULTS (default 50) before pagination is applied, so totalAvailable can never exceed the cap and hasMore reports false on a page that is not the end of the match set. No input retrieves the remainder…
Read the thread · 2026-07-05 · open · 5 comments
bug(mirror): GLEIF delta refresh skips gaps and deletions, then reports fresh
Server version
0.3.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
HTTP (Streamable HTTP)
OS
Linux
Description
Related: #5
mirror:refresh applies only GLEIF's LastDay deltas, then advanceLeiFreshnessIfReady() stamps leiAsOf to now. After a gap longer than a day, the gap's changes are skipped and sanctions_list_sources reports the mirror current.
Inside the window, Level 2 deltas carry only changed relationships…
Read the thread · 2026-09-25 · closed · 1 comment
bug(ingest): source download timeout aborts transfers longer than two minutes
Server version
0.2.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
stdio
Description
Related: #43
The streaming source downloads pass a 120 s timeout to fetchWithTimeout meant to bound only the wait for response headers (HEADERS_TIMEOUT_MS in sanctions-ingest.ts, STREAM_HEADERS_TIMEOUT_MS in gleif-ingest.ts). Since mcp-ts-core 0.11.3 that timeout bounds the whole exchange, body included (cyanheads/mcp-ts-core#341). A…
Read the thread · 2026-09-25 · closed · 1 comment
bug(ingest): OFAC standard-format path infers dates and identifiers
Server version
0.2.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
HTTP (Streamable HTTP)
OS
macOS 27.0
Description
Related: #39, #40
When OFAC_SDN_URL / OFAC_CONSOLIDATED_URL point at OFAC's standard-format files (SDN.XML, CONSOLIDATED.XML) instead of the advanced ones, parseOfacStandard() fills two fields by inference. The default configuration uses the advanced files and is unaffected.
- Every
idList/id…
Read the thread · 2026-09-25 · closed · 1 comment
bug(ingest): UK phone numbers, emails, and websites are dropped
Server version
0.2.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
HTTP (Streamable HTTP)
OS
macOS 27.0
Description
Related: #40, #41
parseUkDesignation() never reads the UK list's Designation/PhoneNumbers/PhoneNumber, Designation/EmailAddresses/EmailAddress, or Designation/Websites/Website, so none reach identifiers. In UK-Sanctions-List.xml as fetched 2026-09-21 that is 1,074 phone numbers in 680 records, 719…
Read the thread · 2026-09-25 · closed · 1 comment
bug(designation resource): entry IDs arrive percent-encoded
Server version
0.2.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
stdio
Description
Related: cyanheads/mcp-ts-core#490
sanctions://designation/{source}/{entryId} hands its handler the template variable still percent-encoded, so a URI a client encoded per RFC 3986 misses a designation that exists. Entry IDs with reserved characters (UN reference numbers such as QDe.004 once they resolve, EU and UN IDs containing .) are the…
Read the thread · 2026-09-25 · closed · 1 comment
bug(mirror): scheduled refresh has no time bound
Server version
0.2.0
mcp-ts-core version
^0.13.6
Runtime
Bun
Runtime version
Bun 1.4.0
Transport
HTTP (Streamable HTTP)
OS
macOS 27.0
Description
Related: #32
scheduleRefresh() in src/index.ts calls designations.runSync({ mode: 'refresh' }) with no signal, so the scheduled refresh has no time bound. A source download's 120 s timeout is meant to bound only the wait for response headers (#47), which leaves the body drain bounded only by the…
Read the thread · 2026-09-25 · closed · 1 comment
feat(get_designation): surface and accept published list reference numbers
Use case
Official notices and the lists' own cross-references cite a designation by its published reference number, not by the internal ID sourceEntryId uses. The remarks on un 111923 (AIMAN MUHAMMED RABI AL-ZAWAHIRI) read "Leader of Al-Qaida (QDe.004)", but un entries are keyed by DATAID (Al-Qaida is 113458) and REFERENCE_NUMBER is dropped at ingest; the EU's euReferenceNumber is dropped the same way. A caller holding QDe.004 has no way to fetch the record, and…
Read the thread · 2026-09-25 · closed · 1 comment
Most recent
bug(screen_name): a strict hit on one list suppresses fuzzy results on the others
Server version
0.4.0
mcp-ts-core version
^0.13.7
Runtime
Bun
Runtime version
Bun 1.4.2
Transport
HTTP (Streamable HTTP)
OS
Linux (Docker)
Description
Strict mode auto-falls back to fuzzy only when strict returns nothing across every source (screenName(), wantFuzzy). A strict hit on one list suppresses fuzzy results from all the others, even for records a direct fuzzy screen ranks first.
Steps to reproduce
sanctions_screen_name`{ "name":…
Read the thread · 2026-09-25 · open · 0 comments
bug(trace_ownership): ultimate-parent edges flatten ownership depth
Server version
0.4.0
mcp-ts-core version
^0.13.7
Runtime
Bun
Runtime version
Bun 1.4.2
Transport
HTTP (Streamable HTTP)
OS
Linux (Docker)
Description
traverse() treats IS_ULTIMATELY_CONSOLIDATED_BY as an adjacency edge. Every entity whose ultimate parent is the root is reported at depth 1 (or at depth 1 as a parent), which flattens real multi-level chains.
Related: #38, #27
Steps to reproduce
sanctions_trace_ownership`{ "lei":…
Read the thread · 2026-09-25 · open · 0 comments
feat(screen_name): match across scripts via transliteration
Use case
sanctions_screen_name never matches a non-Latin query against Latin-only list entries, or the reverse. Names in native script, and GLEIF legal names used as the cross-reference input, miss most designations.
Related: #37
"Совкомфлот" → eu 167101 only (it carries a Cyrillic aka); ofac_sdn 34741 and uk missed
"Роснефть" → eu Роснефть-Аэро only; ofac_sdn/ofac_consolidated 17022 missed
Proposed behavior
- Screen a non-Latin query in both its native and its…
Read the thread · 2026-09-25 · open · 0 comments
feat(get_entity): cross-reference the LEI and registration number as identifiers
Use case
sanctions_get_entity and sanctions_trace_ownership (screenNodes: true) cross-reference an LEI by name only. Lists that publish the LEI or the registry number as an identifier get no exact-identifier check, even though sanctions_screen_identifier already answers that lookup.
Related: #37
Repro: sanctions_get_entity { "lei": "253400DYLWR5A6YAWJ69" } (PAO Sovcomflot) returns sanctionsHits: [], but:
screen_identifier "253400DYLWR5A6YAWJ69" → ofac_sdn 34741…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/56) · 2026-09-25 · open · 0 comments
### bug(screen_name): legal-form and country tokens count toward fuzzy coverage
### Server version
0.4.0
### mcp-ts-core version
^0.13.7
### Runtime
Bun
### Runtime version
Bun 1.4.2
### Transport
HTTP (Streamable HTTP)
### OS
Linux (Docker)
### Description
Fuzzy coverage counts legal-form tokens (`ltd`, `co`, `company`, `limited`, …) and bare country tokens (`uk`) as query tokens. They add junk candidates to the numerator and inflate the denominator of the ≥50% coverage gate in `admitFuzzy()`, so a query whose one distinctive word matches exactly is rejected.…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/55) · 2026-09-25 · open · 0 comments
### bug(screen_name): fuzzy candidate pool fills in insertion order, dropping later-list matches
### Server version
0.4.0
### mcp-ts-core version
^0.13.7
### Runtime
Bun
### Runtime version
Bun 1.4.2
### Transport
HTTP (Streamable HTTP)
### OS
Linux (Docker)
### Description
`runFuzzy()` seeds its candidate pool with one blocking query per strategy, each `LIMIT perStrategyLimit(cap)` (200) with no `ORDER BY`. Rows arrive in rowid order, so the earliest-ingested source fills the budget and a strong match from a later list never enters the pool. Ranking happens only over what was…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/54) · 2026-09-25 · open · 0 comments
### bug(resolve_entity): fuzzy scoring cost grows with query word count
### Server version
0.3.0
### mcp-ts-core version
^0.13.6
### Runtime
Bun
### Runtime version
Bun 1.4.0
### Transport
HTTP (Streamable HTTP)
### OS
macOS 27.0
### Description
Related: #33, #9
`runLeiFuzzy()` pools up to the per-prefix row limit (200) for every distinct query-word prefix, then scores every pooled row synchronously on the request thread. At the 64-word input bound, a name of common words pools about 12,800 rows. Scoring them takes about 1.3 s whatever the blocking…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/51) · 2026-09-25 · open · 0 comments
### bug(screen_name): fuzzy blocking scans the name table per query word
### Server version
0.3.0
### mcp-ts-core version
^0.13.6
### Runtime
Bun
### Runtime version
Bun 1.4.0
### Transport
HTTP (Streamable HTTP)
### OS
macOS 27.0
### Description
Related: #33
`runFuzzy()` in `src/services/screening/screening-service.ts` blocks designation candidates with one `n.normalized LIKE '%<prefix>%' … LIMIT n` per distinct token prefix over the `name` table. A leading-`%` `LIKE` can't use an index, so any prefix with fewer than `n` matches reads every `name`…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/50) · 2026-09-25 · open · 0 comments
### feat(screening): exact lookup by IMO, SWIFT/BIC, wallet, or document number
### Use case
Maritime, payment, and crypto screening start from an identifier, not a name: a vessel's IMO number, a bank's SWIFT/BIC in a wire, a wallet address, a passport number. The mirror stores these in each designation's `identifiers`, but only names are searchable. Passed as a name, an identifier misses: `ofac_sdn` `4243` (EBANO) publishes `IMO 7406784`, yet `sanctions_screen_name` returns 0 hits for `"7406784"` and 20 unrelated fuzzy candidates for `"IMO 7406784"`.
Depends on: #40…
[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/41) · 2026-09-25 · closed · 1 comment
The remaining reports are on [the project's issue tracker](https://github.com/cyanheads/sanctions-screening-mcp-server/issues).