Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for sanctions-screening-mcp-server

Pod holds 17 of 30 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to sanctions-screening-mcp-server.

Most discussed

bug(matching): fuzzy hard-cap results are not page-retrievable

Server version

0.1.10

mcp-ts-core version

^0.11.5

Runtime

Bun

Runtime version

Bun 1.3.14

Transport

HTTP (Streamable HTTP)

OS

macOS 26.1

Description

sanctions_screen_name and sanctions_resolve_entity truncate a fuzzy pass to SANCTIONS_FUZZY_MAX_RESULTS (default 50) before pagination is applied, so totalAvailable can never exceed the cap and hasMore reports false on a page that is not the end of the match set. No input retrieves the remainder…

Read the thread · 2026-07-05 · open · 5 comments

bug(mirror): GLEIF delta refresh skips gaps and deletions, then reports fresh

Server version

0.3.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

HTTP (Streamable HTTP)

OS

Linux

Description

Related: #5

mirror:refresh applies only GLEIF's LastDay deltas, then advanceLeiFreshnessIfReady() stamps leiAsOf to now. After a gap longer than a day, the gap's changes are skipped and sanctions_list_sources reports the mirror current.

Inside the window, Level 2 deltas carry only changed relationships…

Read the thread · 2026-09-25 · closed · 1 comment

bug(ingest): source download timeout aborts transfers longer than two minutes

Server version

0.2.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

stdio

Description

Related: #43

The streaming source downloads pass a 120 s timeout to fetchWithTimeout meant to bound only the wait for response headers (HEADERS_TIMEOUT_MS in sanctions-ingest.ts, STREAM_HEADERS_TIMEOUT_MS in gleif-ingest.ts). Since mcp-ts-core 0.11.3 that timeout bounds the whole exchange, body included (cyanheads/mcp-ts-core#341). A…

Read the thread · 2026-09-25 · closed · 1 comment

bug(ingest): OFAC standard-format path infers dates and identifiers

Server version

0.2.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

HTTP (Streamable HTTP)

OS

macOS 27.0

Description

Related: #39, #40

When OFAC_SDN_URL / OFAC_CONSOLIDATED_URL point at OFAC's standard-format files (SDN.XML, CONSOLIDATED.XML) instead of the advanced ones, parseOfacStandard() fills two fields by inference. The default configuration uses the advanced files and is unaffected.

Read the thread · 2026-09-25 · closed · 1 comment

bug(ingest): UK phone numbers, emails, and websites are dropped

Server version

0.2.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

HTTP (Streamable HTTP)

OS

macOS 27.0

Description

Related: #40, #41

parseUkDesignation() never reads the UK list's Designation/PhoneNumbers/PhoneNumber, Designation/EmailAddresses/EmailAddress, or Designation/Websites/Website, so none reach identifiers. In UK-Sanctions-List.xml as fetched 2026-09-21 that is 1,074 phone numbers in 680 records, 719…

Read the thread · 2026-09-25 · closed · 1 comment

bug(designation resource): entry IDs arrive percent-encoded

Server version

0.2.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

stdio

Description

Related: cyanheads/mcp-ts-core#490

sanctions://designation/{source}/{entryId} hands its handler the template variable still percent-encoded, so a URI a client encoded per RFC 3986 misses a designation that exists. Entry IDs with reserved characters (UN reference numbers such as QDe.004 once they resolve, EU and UN IDs containing .) are the…

Read the thread · 2026-09-25 · closed · 1 comment

bug(mirror): scheduled refresh has no time bound

Server version

0.2.0

mcp-ts-core version

^0.13.6

Runtime

Bun

Runtime version

Bun 1.4.0

Transport

HTTP (Streamable HTTP)

OS

macOS 27.0

Description

Related: #32

scheduleRefresh() in src/index.ts calls designations.runSync({ mode: 'refresh' }) with no signal, so the scheduled refresh has no time bound. A source download's 120 s timeout is meant to bound only the wait for response headers (#47), which leaves the body drain bounded only by the…

Read the thread · 2026-09-25 · closed · 1 comment

feat(get_designation): surface and accept published list reference numbers

Use case

Official notices and the lists' own cross-references cite a designation by its published reference number, not by the internal ID sourceEntryId uses. The remarks on un 111923 (AIMAN MUHAMMED RABI AL-ZAWAHIRI) read "Leader of Al-Qaida (QDe.004)", but un entries are keyed by DATAID (Al-Qaida is 113458) and REFERENCE_NUMBER is dropped at ingest; the EU's euReferenceNumber is dropped the same way. A caller holding QDe.004 has no way to fetch the record, and…

Read the thread · 2026-09-25 · closed · 1 comment

Most recent

bug(screen_name): a strict hit on one list suppresses fuzzy results on the others

Server version

0.4.0

mcp-ts-core version

^0.13.7

Runtime

Bun

Runtime version

Bun 1.4.2

Transport

HTTP (Streamable HTTP)

OS

Linux (Docker)

Description

Strict mode auto-falls back to fuzzy only when strict returns nothing across every source (screenName(), wantFuzzy). A strict hit on one list suppresses fuzzy results from all the others, even for records a direct fuzzy screen ranks first.

Steps to reproduce

  1. sanctions_screen_name `{ "name":…

Read the thread · 2026-09-25 · open · 0 comments

bug(trace_ownership): ultimate-parent edges flatten ownership depth

Server version

0.4.0

mcp-ts-core version

^0.13.7

Runtime

Bun

Runtime version

Bun 1.4.2

Transport

HTTP (Streamable HTTP)

OS

Linux (Docker)

Description

traverse() treats IS_ULTIMATELY_CONSOLIDATED_BY as an adjacency edge. Every entity whose ultimate parent is the root is reported at depth 1 (or at depth 1 as a parent), which flattens real multi-level chains.

Related: #38, #27

Steps to reproduce

  1. sanctions_trace_ownership `{ "lei":…

Read the thread · 2026-09-25 · open · 0 comments

feat(screen_name): match across scripts via transliteration

Use case

sanctions_screen_name never matches a non-Latin query against Latin-only list entries, or the reverse. Names in native script, and GLEIF legal names used as the cross-reference input, miss most designations.

Related: #37

"Совкомфлот" → eu 167101 only (it carries a Cyrillic aka); ofac_sdn 34741 and uk missed
"Роснефть"   → eu Роснефть-Аэро only; ofac_sdn/ofac_consolidated 17022 missed

Proposed behavior

Read the thread · 2026-09-25 · open · 0 comments

feat(get_entity): cross-reference the LEI and registration number as identifiers

Use case

sanctions_get_entity and sanctions_trace_ownership (screenNodes: true) cross-reference an LEI by name only. Lists that publish the LEI or the registry number as an identifier get no exact-identifier check, even though sanctions_screen_identifier already answers that lookup.

Related: #37

Repro: sanctions_get_entity { "lei": "253400DYLWR5A6YAWJ69" } (PAO Sovcomflot) returns sanctionsHits: [], but:

screen_identifier "253400DYLWR5A6YAWJ69" → ofac_sdn 34741…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/56) · 2026-09-25 · open · 0 comments

### bug(screen_name): legal-form and country tokens count toward fuzzy coverage

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

Fuzzy coverage counts legal-form tokens (`ltd`, `co`, `company`, `limited`, …) and bare country tokens (`uk`) as query tokens. They add junk candidates to the numerator and inflate the denominator of the ≥50% coverage gate in `admitFuzzy()`, so a query whose one distinctive word matches exactly is rejected.…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/55) · 2026-09-25 · open · 0 comments

### bug(screen_name): fuzzy candidate pool fills in insertion order, dropping later-list matches

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

`runFuzzy()` seeds its candidate pool with one blocking query per strategy, each `LIMIT perStrategyLimit(cap)` (200) with no `ORDER BY`. Rows arrive in rowid order, so the earliest-ingested source fills the budget and a strong match from a later list never enters the pool. Ranking happens only over what was…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/54) · 2026-09-25 · open · 0 comments

### bug(resolve_entity): fuzzy scoring cost grows with query word count

### Server version

0.3.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #33, #9

`runLeiFuzzy()` pools up to the per-prefix row limit (200) for every distinct query-word prefix, then scores every pooled row synchronously on the request thread. At the 64-word input bound, a name of common words pools about 12,800 rows. Scoring them takes about 1.3 s whatever the blocking…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/51) · 2026-09-25 · open · 0 comments

### bug(screen_name): fuzzy blocking scans the name table per query word

### Server version

0.3.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #33

`runFuzzy()` in `src/services/screening/screening-service.ts` blocks designation candidates with one `n.normalized LIKE '%<prefix>%' … LIMIT n` per distinct token prefix over the `name` table. A leading-`%` `LIKE` can't use an index, so any prefix with fewer than `n` matches reads every `name`…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/50) · 2026-09-25 · open · 0 comments

### feat(screening): exact lookup by IMO, SWIFT/BIC, wallet, or document number

### Use case

Maritime, payment, and crypto screening start from an identifier, not a name: a vessel's IMO number, a bank's SWIFT/BIC in a wire, a wallet address, a passport number. The mirror stores these in each designation's `identifiers`, but only names are searchable. Passed as a name, an identifier misses: `ofac_sdn` `4243` (EBANO) publishes `IMO 7406784`, yet `sanctions_screen_name` returns 0 hits for `"7406784"` and 20 unrelated fuzzy candidates for `"IMO 7406784"`.

Depends on: #40…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/41) · 2026-09-25 · closed · 1 comment

The remaining reports are on [the project's issue tracker](https://github.com/cyanheads/sanctions-screening-mcp-server/issues).