Skip to content

better-isms/ismscopilot

v0.1.6MIT

Account MCP connection that lets a compliance specialist take over GRC work: framework interpretation, policy drafting, control mapping, gap analysis, risk registers and audit prep, with workspaces, documents, memories and company context in one place.

MCP servers

Declared configuration, as published in mcp.json. The directory shows indexed content; it never connects to or executes these servers.

ismscopilot-accountstreamable-http
{
  "type": "streamable-http",
  "url": "https://account.ismscopilot.com/v1/account/mcp"
}

What this package declares

The files a client reads when it loads this plugin, exactly as this revision carries them.

{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "ismscopilot",
  "version": "0.1.6",
  "description": "Account MCP connection that lets a compliance specialist take over GRC work: framework interpretation, policy drafting, control mapping, gap analysis, risk registers and audit prep, with workspaces, documents, memories and company context in one place.",
  "author": {
    "name": "Better ISMS",
    "email": "support@ismscopilot.com",
    "url": "https://ismscopilot.com"
  },
  "homepage": "https://ismscopilot.com",
  "repository": "https://github.com/better-isms/ismscopilot-plugin",
  "license": "MIT",
  "keywords": [
    "ismscopilot",
    "grc",
    "compliance",
    "iso-27001",
    "soc-2",
    "gdpr",
    "risk-register",
    "audit-prep"
  ],
  "extensions": {
    "com.openai": {
      "interface": {
        "displayName": "ISMS Copilot",
        "shortDescription": "Compliance and GRC specialist",
        "longDescription": "Connect your account to delegate GRC work: ISO 27001/27701/42001, SOC 2, GDPR, NIS 2, DORA, EU AI Act, HIPAA and PCI DSS interpretation, policy drafting, control mapping, gap analysis, risk registers and audit prep for compliance and audit teams. Ask the specialist a framework question and continue one conversation per deliverable; company context, memories and workspaces stay with your account. The specialist already knows the frameworks, so you do not need to paste source text. The connected tools cover account and workspace reads, document listings, memories, company context and specialist conversations; they do not accept local code, local files, passwords or API keys. Do not share health records, payment card data or government ID numbers. Answers are general compliance guidance for practitioners, not legal advice: review them before you rely on them. Requires an account.",
        "developerName": "Better ISMS",
        "category": "Security",
        "capabilities": [
          "Compliance Q&A",
          "Policy drafting",
          "Risk registers",
          "Company context"
        ],
        "websiteURL": "https://ismscopilot.com",
        "supportURL": "https://docs.ismscopilot.com/docs/getting-started/contact-support-from-the-support-page-91de7",
        "privacyPolicyURL": "https://trust.ismscopilot.com/en/privacy-policy",
        "termsOfServiceURL": "https://trust.ismscopilot.com/en/terms",
        "defaultPrompt": [
          "Ask ISMS Copilot which ISO 27001 controls cover supplier security.",
          "List my ISMS Copilot workspaces, then list the documents in the first one.",
          "Remember in ISMS Copilot that our certification audit is in November."
        ],
        "brandColor": "#5046e4",
        "brandColorDark": "#c7d2fe",
        "logo": "./assets/logo.png",
        "composerIcon": "./assets/logo.png"
      },
      "onboardingSkill": "./skills/get-started/SKILL.md",
      "review": {
        "demo_recording_url": "https://www.ismscopilot.com/videos/ismscopilot-chatgpt-demo.mp4",
        "test_cases": {
          "positive": [
            {
              "description": "Read the stored company profile",
              "prompt": "What company profile does ISMS Copilot have on file for me?",
              "tools_triggered": "get_company_context",
              "expected_behavior": "Returns the company profile stored on the connected account (test account: Example SaaS SAS, a 60-employee French project management SaaS selling to EU customers, ISO 27001 external audit planned for 2027). Read only; no other tool runs and nothing is changed."
            },
            {
              "description": "Ask the compliance specialist a framework question",
              "prompt": "Ask ISMS Copilot which ISO 27001:2022 Annex A controls cover supplier security.",
              "tools_triggered": "create_conversation",
              "expected_behavior": "Starts one conversation and returns the specialist's answer naming A.5.19 through A.5.23 in plain language, without pasting the standard's text. If the reply is still generating, get_reply is called until the answer is complete."
            },
            {
              "description": "Follow up in the same conversation",
              "prompt": "Ask ISMS Copilot to turn that into a five-item supplier review checklist.",
              "tools_triggered": "send_message",
              "expected_behavior": "Continues the same conversation instead of creating a new one and returns a five-item supplier review checklist."
            },
            {
              "description": "List workspaces and their documents",
              "prompt": "List my ISMS Copilot workspaces, then list the documents in My First Workspace.",
              "tools_triggered": "list_workspaces, list_documents",
              "expected_behavior": "Lists the connected account's workspaces, then that workspace's documents by name. Returns only data belonging to the connected account."
            },
            {
              "description": "Save a memory",
              "prompt": "Remember in ISMS Copilot that our certification audit is in November.",
              "tools_triggered": "create_memory",
              "expected_behavior": "Creates one memory on the connected account and confirms what was saved."
            }
          ],
          "negative": [
            {
              "description": "Unrelated request",
              "prompt": "What's the weather in Paris tomorrow?",
              "expected_behavior": "Answered without calling any ISMS Copilot tool. Weather is outside the scope of the connected tools."
            },
            {
              "description": "Credential tools are out of scope",
              "prompt": "Create an ISMS Copilot API key for me.",
              "expected_behavior": "No key tools are exposed over this connection. Declines without calling any tool and says key creation is not available through this connection."
            },
            {
              "description": "Purchases are out of scope",
              "prompt": "Buy 50 dollars of ISMS Copilot API credits.",
              "expected_behavior": "No checkout or credit tools are exposed over this connection. Declines without calling any tool."
            }
          ]
        },
        "commerce": false,
        "commerce_description": "This plugin does not sell products or process payments. The connected tool set has no checkout, credit or API key tools."
      },
      "publication": {
        "release_notes": "Initial directory release (0.1.6). Connects the ISMS Copilot account MCP server over OAuth 2.1: compliance specialist conversations, workspaces, documents, memories and company context."
      }
    }
  }
}

What else this package ships

These files come with the package and this site does not publish them. They are listed so you know what is there before you install it.

  • LICENSE
View on GitHub

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • com.openai