
Connects Claude to the U.S. Consumer Product Safety Commission's public recalls API with three focused tools: keyword search across products, brands, and retailers with optional date filters; full recall detail by recall number including hazards, remedies, and UPC codes; and a configurable recent recalls feed. Built on the mcp-ts-core framework with both stdio and streamable HTTP transports. Useful when you need to check if a consumer product has been recalled, surface safety issues for specific brands or importers, or monitor new CPSC actions. Jurisdiction is consumer products only, so food, vehicles, boats, and drugs are out of scope. No API key required since the CPSC endpoint is public.
Search and retrieve US consumer product recalls from the CPSC (Consumer Product Safety Commission) via MCP. STDIO or Streamable HTTP.
Public Hosted Server: https://cpsc-recalls.caseyjhand.com/mcp
3 tools for searching and retrieving CPSC consumer product recall data:
| Tool | Description |
|---|---|
cpsc_search_recalls | Search consumer product recalls by title, product name, brand, retailer, importer, distributor, hazard, remedy, or description keyword, with optional date filtering and offset paging |
cpsc_get_recall | Full detail for a single recall by recall number — hazards, remedy, products, injuries, images, and the official CPSC page |
cpsc_get_recent | Fetch the most recent recalls ordered newest-first, scoped to a configurable date window |
CPSC jurisdiction: Consumer products only — toys, electronics, furniture, appliances, children's products, tools, and clothing. Food and drugs (FDA), motor vehicles and tires (NHTSA), boats (USCG), and pesticides (EPA) are not in this database. Every response includes a jurisdiction note.
Data sourced from the U.S. Consumer Product Safety Commission via the CPSC public recalls API.
cpsc_search_recallsSearch recalls with flexible filtering across title, product, organization, hazard, remedy, and description fields.
title_search, product_name, manufacturer, retailer, importer, distributor, remedy, or description_search — all optional substring matches, applied upstream, combining with ANDtitle_search is usually the highest-signal filter: CPSC titles name the brand, the product, and the hazardhazard_search is a client-side filter applied after the upstream fetch — it matches when the term appears in hazard descriptions, product names, or remedy instructions (case-insensitive). Use it for hazard concepts like "fire", "choking", or "burn"; the upstream Hazard parameter is recognized but never matches, so it is not exposedremedy searches the free-text remedy instructions, not the remedy_options type enum — remedy: "repair" matches records whose remedy_options list only Refund but whose instructions describe a free repair kitdate_start / date_end bound the recall issue date, updated_start / updated_end bound the date CPSC last published the record. A 2003 recall re-published in 2025 matches updated_start: "2025-01-01". All four must be real calendar dates — 2026-02-31 and 2026-99-99 are rejected at input validation, and a reversed range fails with invalid_date_range rather than silently returning nothingoffset (default 0) applied after fetching all matching records. Page with offset: 0, 20, 40; an offset at or past total_found returns an empty result set rather than an errortotal_found counts matches after hazard_search is applied and before offset/limit narrow the window; has_more is the paging signal; truncated stays limit-only and does not move with offset; data_quality_notes records gaps in the upstream record (no hazard text, no product entries); empty when nothing is missingmanufacturer returns no results, try importer, retailer, or distributor — many recalls list one of those as the primary organizationupstream_rejected (retryable: false) and carry the CPSC message; transient outages stay on upstream_error (retryable: true)cpsc_get_recallFull detail for a single CPSC recall by recall number.
"25043") and historical 1998–2001 records with letter suffixes (e.g. "99003a")description is nullable — a small number of genuine CPSC records carry no description; the record is still returned and the absence is stated rather than rendered as a blank sectioncontent[]data_quality_notes records gaps in the upstream record (absent description, no hazard text, no product entries); empty when nothing is missingcpsc_search_recalls or cpsc_get_recent to find a recall number firstcpsc_get_recentFetch the most recent CPSC recalls, ordered newest-first.
offset (default 0) to page through total_found. Narrowing days cannot page — the window is anchored to today, so shrinking it drops the oldest records rather than advancing past the newesthas_more is the paging signal; truncated stays limit-only and does not move with offsetdata_quality_notes records gaps in the upstream record (no hazard text, no product entries); empty when nothing is missingcpsc_get_recall to retrieve full detail for any resultBuilt on @cyanheads/mcp-ts-core:
none, jwt, oauthin-memory, filesystem, Supabase, Cloudflare KV/R2/D1CPSC-specific:
total_found countsAgent-friendly output:
total_found, offset, has_more, and truncated fields on search/recent responses — agents can tell when results are clipped and page through the rest with offsetcpsc_url on every recall — authoritative source link for consumer verificationsource_note on every response, plus (CPSC source text) labels and blockquotes in the rendered output — relayed CPSC narrative is marked as source data, distinct from the server's own guidancedata_quality_notes on every response — gaps observed in the upstream record, derived from which fields CPSC left empty rather than any judgement about the recallA public instance is available at https://cpsc-recalls.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "streamable-http",
"url": "https://cpsc-recalls.caseyjhand.com/mcp"
}
}
}
Add the following to your MCP client configuration file.
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/cpsc-recalls-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/cpsc-recalls-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/cpsc-recalls-mcp-server:latest"]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
git clone https://github.com/cyanheads/cpsc-recalls-mcp-server.git
cd cpsc-recalls-mcp-server
bun install
cp .env.example .env
# edit .env if needed — no required API keys
All configuration is validated at startup via Zod schemas. Key environment variables:
| Variable | Description | Default |
|---|---|---|
MCP_TRANSPORT_TYPE | Transport: stdio or http | stdio |
MCP_HTTP_PORT | HTTP server port | 3010 |
MCP_HTTP_HOST | HTTP server host | 127.0.0.1 |
MCP_HTTP_ENDPOINT_PATH | HTTP endpoint path | /mcp |
MCP_PUBLIC_URL | Public origin for TLS-terminating reverse-proxy deployments | — |
MCP_SESSION_MODE | Session handling: auto, stateful, or stateless. The schema default auto resolves to stateful; this server sets stateless explicitly. | stateless |
MCP_AUTH_MODE | Authentication: none, jwt, or oauth | none |
MCP_LOG_LEVEL | Log level (debug, info, warning, error) | info |
LOGS_DIR | Directory for log files (Node.js only) | <project-root>/logs |
STORAGE_PROVIDER_TYPE | Storage backend: in-memory, filesystem, supabase, cloudflare-kv/r2/d1 | in-memory |
OTEL_ENABLED | Enable OpenTelemetry | false |
No server-specific API keys are required. See .env.example for the full list of optional overrides.
Build and run the production version:
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
docker build -t cpsc-recalls-mcp-server .
docker run --rm -p 3010:3010 cpsc-recalls-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/cpsc-recalls-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools and inits the CPSC service |
src/mcp-server/tools | Tool definitions (*.tool.ts). Three tools: search, get-recall, get-recent |
src/services/cpsc-recall | CPSC recall service — API client, types, normalization |
See CLAUDE.md / AGENTS.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagecreateApp() arrays in src/index.tsIssues and pull requests are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
MCP_LOG_LEVELdefault: infoSets the minimum log level for output (e.g., 'debug', 'info', 'warn').
MCP_HTTP_HOSTdefault: 127.0.0.1The hostname for the HTTP server.
MCP_HTTP_PORTdefault: 3010The port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATHdefault: /mcpThe endpoint path for the MCP server.
MCP_AUTH_MODEdefault: noneAuthentication mode to use: 'none', 'jwt', or 'oauth'.