# Reported issues for sanctions-screening-mcp-server

Pod holds 17 of 30 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [sanctions-screening-mcp-server](/mcp/sanctions-screening-mcp-server).

## Most discussed

### bug(matching): fuzzy hard-cap results are not page-retrievable

### Server version

0.1.10

### mcp-ts-core version

^0.11.5

### Runtime

Bun

### Runtime version

Bun 1.3.14

### Transport

HTTP (Streamable HTTP)

### OS

macOS 26.1

### Description

`sanctions_screen_name` and `sanctions_resolve_entity` truncate a fuzzy pass to `SANCTIONS_FUZZY_MAX_RESULTS` (default 50) *before* pagination is applied, so `totalAvailable` can never exceed the cap and `hasMore` reports `false` on a page that is not the end of the match set. No input retrieves the remainder…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/9) · 2026-07-05 · open · 5 comments

### bug(mirror): GLEIF delta refresh skips gaps and deletions, then reports fresh

### Server version

0.3.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

Linux

### Description

Related: #5

`mirror:refresh` applies only GLEIF's `LastDay` deltas, then `advanceLeiFreshnessIfReady()` stamps `leiAsOf` to now. After a gap longer than a day, the gap's changes are skipped and `sanctions_list_sources` reports the mirror current.

Inside the window, Level 2 deltas carry only changed relationships…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/49) · 2026-09-25 · closed · 1 comment

### bug(ingest): source download timeout aborts transfers longer than two minutes

### Server version

0.2.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

stdio

### Description

Related: #43

The streaming source downloads pass a 120 s timeout to `fetchWithTimeout` meant to bound only the wait for response headers (`HEADERS_TIMEOUT_MS` in `sanctions-ingest.ts`, `STREAM_HEADERS_TIMEOUT_MS` in `gleif-ingest.ts`). Since mcp-ts-core 0.11.3 that timeout bounds the whole exchange, body included (cyanheads/mcp-ts-core#341). A…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/47) · 2026-09-25 · closed · 1 comment

### bug(ingest): OFAC standard-format path infers dates and identifiers

### Server version

0.2.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #39, #40

When `OFAC_SDN_URL` / `OFAC_CONSOLIDATED_URL` point at OFAC's standard-format files (`SDN.XML`, `CONSOLIDATED.XML`) instead of the advanced ones, `parseOfacStandard()` fills two fields by inference. The default configuration uses the advanced files and is unaffected.

- Every `idList/id`…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/46) · 2026-09-25 · closed · 1 comment

### bug(ingest): UK phone numbers, emails, and websites are dropped

### Server version

0.2.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #40, #41

`parseUkDesignation()` never reads the UK list's `Designation/PhoneNumbers/PhoneNumber`, `Designation/EmailAddresses/EmailAddress`, or `Designation/Websites/Website`, so none reach `identifiers`. In `UK-Sanctions-List.xml` as fetched 2026-09-21 that is 1,074 phone numbers in 680 records, 719…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/45) · 2026-09-25 · closed · 1 comment

### bug(designation resource): entry IDs arrive percent-encoded

### Server version

0.2.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

stdio

### Description

Related: cyanheads/mcp-ts-core#490

`sanctions://designation/{source}/{entryId}` hands its handler the template variable still percent-encoded, so a URI a client encoded per RFC 3986 misses a designation that exists. Entry IDs with reserved characters (UN reference numbers such as `QDe.004` once they resolve, EU and UN IDs containing `.`) are the…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/44) · 2026-09-25 · closed · 1 comment

### bug(mirror): scheduled refresh has no time bound

### Server version

0.2.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #32

`scheduleRefresh()` in `src/index.ts` calls `designations.runSync({ mode: 'refresh' })` with no `signal`, so the scheduled refresh has no time bound. A source download's 120 s timeout is meant to bound only the wait for response headers (#47), which leaves the body drain bounded only by the…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/43) · 2026-09-25 · closed · 1 comment

### feat(get_designation): surface and accept published list reference numbers

### Use case

Official notices and the lists' own cross-references cite a designation by its published reference number, not by the internal ID `sourceEntryId` uses. The remarks on `un` `111923` (AIMAN MUHAMMED RABI AL-ZAWAHIRI) read "Leader of Al-Qaida (QDe.004)", but `un` entries are keyed by `DATAID` (Al-Qaida is `113458`) and `REFERENCE_NUMBER` is dropped at ingest; the EU's `euReferenceNumber` is dropped the same way. A caller holding `QDe.004` has no way to fetch the record, and…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/42) · 2026-09-25 · closed · 1 comment

## Most recent

### bug(screen_name): a strict hit on one list suppresses fuzzy results on the others

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

Strict mode auto-falls back to fuzzy only when strict returns nothing across every source (`screenName()`, `wantFuzzy`). A strict hit on one list suppresses fuzzy results from all the others, even for records a direct fuzzy screen ranks first.

### Steps to reproduce

1. `sanctions_screen_name` `{ "name":…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/59) · 2026-09-25 · open · 0 comments

### bug(trace_ownership): ultimate-parent edges flatten ownership depth

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

`traverse()` treats `IS_ULTIMATELY_CONSOLIDATED_BY` as an adjacency edge. Every entity whose ultimate parent is the root is reported at depth 1 (or at depth 1 as a parent), which flattens real multi-level chains.

Related: #38, #27

### Steps to reproduce

1. `sanctions_trace_ownership` `{ "lei":…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/58) · 2026-09-25 · open · 0 comments

### feat(screen_name): match across scripts via transliteration

### Use case

`sanctions_screen_name` never matches a non-Latin query against Latin-only list entries, or the reverse. Names in native script, and GLEIF legal names used as the cross-reference input, miss most designations.

Related: #37

```text
"Совкомфлот" → eu 167101 only (it carries a Cyrillic aka); ofac_sdn 34741 and uk missed
"Роснефть"   → eu Роснефть-Аэро only; ofac_sdn/ofac_consolidated 17022 missed
```

### Proposed behavior

- Screen a non-Latin query in both its native and its…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/57) · 2026-09-25 · open · 0 comments

### feat(get_entity): cross-reference the LEI and registration number as identifiers

### Use case

`sanctions_get_entity` and `sanctions_trace_ownership` (`screenNodes: true`) cross-reference an LEI by name only. Lists that publish the LEI or the registry number as an identifier get no exact-identifier check, even though `sanctions_screen_identifier` already answers that lookup.

Related: #37

Repro: `sanctions_get_entity { "lei": "253400DYLWR5A6YAWJ69" }` (PAO Sovcomflot) returns `sanctionsHits: []`, but:

```text
screen_identifier "253400DYLWR5A6YAWJ69" → ofac_sdn 34741…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/56) · 2026-09-25 · open · 0 comments

### bug(screen_name): legal-form and country tokens count toward fuzzy coverage

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

Fuzzy coverage counts legal-form tokens (`ltd`, `co`, `company`, `limited`, …) and bare country tokens (`uk`) as query tokens. They add junk candidates to the numerator and inflate the denominator of the ≥50% coverage gate in `admitFuzzy()`, so a query whose one distinctive word matches exactly is rejected.…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/55) · 2026-09-25 · open · 0 comments

### bug(screen_name): fuzzy candidate pool fills in insertion order, dropping later-list matches

### Server version

0.4.0

### mcp-ts-core version

^0.13.7

### Runtime

Bun

### Runtime version

Bun 1.4.2

### Transport

HTTP (Streamable HTTP)

### OS

Linux (Docker)

### Description

`runFuzzy()` seeds its candidate pool with one blocking query per strategy, each `LIMIT perStrategyLimit(cap)` (200) with no `ORDER BY`. Rows arrive in rowid order, so the earliest-ingested source fills the budget and a strong match from a later list never enters the pool. Ranking happens only over what was…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/54) · 2026-09-25 · open · 0 comments

### bug(resolve_entity): fuzzy scoring cost grows with query word count

### Server version

0.3.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #33, #9

`runLeiFuzzy()` pools up to the per-prefix row limit (200) for every distinct query-word prefix, then scores every pooled row synchronously on the request thread. At the 64-word input bound, a name of common words pools about 12,800 rows. Scoring them takes about 1.3 s whatever the blocking…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/51) · 2026-09-25 · open · 0 comments

### bug(screen_name): fuzzy blocking scans the name table per query word

### Server version

0.3.0

### mcp-ts-core version

^0.13.6

### Runtime

Bun

### Runtime version

Bun 1.4.0

### Transport

HTTP (Streamable HTTP)

### OS

macOS 27.0

### Description

Related: #33

`runFuzzy()` in `src/services/screening/screening-service.ts` blocks designation candidates with one `n.normalized LIKE '%<prefix>%' … LIMIT n` per distinct token prefix over the `name` table. A leading-`%` `LIKE` can't use an index, so any prefix with fewer than `n` matches reads every `name`…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/50) · 2026-09-25 · open · 0 comments

### feat(screening): exact lookup by IMO, SWIFT/BIC, wallet, or document number

### Use case

Maritime, payment, and crypto screening start from an identifier, not a name: a vessel's IMO number, a bank's SWIFT/BIC in a wire, a wallet address, a passport number. The mirror stores these in each designation's `identifiers`, but only names are searchable. Passed as a name, an identifier misses: `ofac_sdn` `4243` (EBANO) publishes `IMO 7406784`, yet `sanctions_screen_name` returns 0 hits for `"7406784"` and 20 unrelated fuzzy candidates for `"IMO 7406784"`.

Depends on: #40…

[Read the thread](https://github.com/cyanheads/sanctions-screening-mcp-server/issues/41) · 2026-09-25 · closed · 1 comment

The remaining reports are on [the project's issue tracker](https://github.com/cyanheads/sanctions-screening-mcp-server/issues).
