Cleo Compliance Skills MCP

Cleo Compliance Skills MCP

Cleo Skills MCP turns 45 production-grade product-compliance skills into a native MCP server. Cosmetics, food, electronics, toys, textiles, supplements, medical devices, customs, recalls, claims, sustainability — exposed as MCP resources (skill://), parameterized prompts, and 3 structured tools (list_skills, find_skill, read_skill). Drop into Claude Desktop, Cursor, or Continue. MIT licensed

Category
访问服务器

README

Compliance Product Guidance

npm npm downloads MCP server License: MIT Skills GitHub stars Cleo Labs Powered by Cleo Legal API CI

Read in your language: English · Français · Español · Deutsch · 日本語 · 简体中文

AI compliance copilot for physical products — REACH, FDA, CE, customs, and 24 more regulations, inside your Claude Code / Cursor / Codex.

What is this?

Selling a physical product across borders means navigating 25,000+ regulations spread across 49 countries: substance bans you've never heard of, labels that change every quarter, customs codes that move duty rates by 12%, marketplace rules that delist you overnight. Most small brands learn this the expensive way — at the border, or after Amazon takes the listing down.

Compliance Product Guidance is 40 production-grade skills + 2 MCP servers that teach an AI agent how to answer one question: "What do I actually need to do to sell this product in this market?"

The hero skill is product-compliance. You paste an ingredient list (or BOM, or formula), pick your target markets, and it runs:

ingredients  →  CAS resolution  →  13 regulatory databases  →
verdict per substance per market  →  Revenue-at-Risk calculation

Sample output:

Retinol 0.4%   EU: BLOCKED (Annex III cap 0.3% face products, eff. Nov 2025)   €/year at risk: ~€180k
Retinol 0.4%   US: OK (no federal cap; CA Prop 65 warning not required at this dose)
Retinol 0.4%   UK: BLOCKED (UK Cosmetics Reg mirrors EU Annex III)
Retinol 0.4%   JP: REVIEW (quasi-drug threshold — needs MHLW review)

Same pattern works for an electronics BOM (RoHS, REACH SVHC, CE/FCC, battery reg), a food recipe (allergens, novel foods, FDA FSMA), a textile (PFAS, fiber labeling, OEKO-TEX), or any of the 18 product verticals below.

Install

# As an MCP server (fastest)
npx -y @cleo-labs/skills-mcp@latest

# As Claude Code skills (file-based)
git clone https://github.com/Cleo-Labs-IA/skills_library.git ~/.claude/skills/comply

The npm package is the one-line install for Claude Desktop, Cursor, Continue, Zed, and any MCP-compatible client. The skills appear as native MCP resources (skill://<name>), parameterized prompts, and three structured tools (list_skills, find_skill, read_skill).

Drop this into your client config:

{
  "mcpServers": {
    "cleo-skills": {
      "command": "npx",
      "args": ["-y", "@cleo-labs/skills-mcp@latest"]
    }
  }
}

For Claude Code, the git clone variant drops the skills into ~/.claude/skills/comply and they auto-trigger when you ask about substances, labels, customs, markets, or recalls — no manual invocation needed.

Manual copy

git clone https://github.com/Cleo-Labs-IA/skills_library.git
cp -r skills_library/skills/* ~/.claude/skills/

Cursor / Codex / other Claude-skills-compatible runtimes

Point your skills directory at skills_library/skills/. Each skill is a self-contained folder with a SKILL.md plus references — runtime-agnostic by design.

See mcp-server/README.md for full MCP setup (Docker, per-client examples) and INSTALL.md for the 30-second version and EXAMPLES.md for real prompts.

The 40 skills

Core compliance engine (6)

The skills that touch your actual product.

Skill What it does
product-compliance Hero skill. Full substance check across 13 databases, verdict per market, Revenue-at-Risk.
substance-screening Deep ingredient/material screening: INCI→CAS, concentration margins, per-jurisdiction verdicts.
labeling-compliance Country-specific labels: INCI, allergens, warnings, CE/UKCA marks, multi-language rules.
testing-certification Required tests/certs per product per market (CPSR, CE, FCC, UL, EN 71, HACCP). Lab selection, cost, timeline.
claims-substantiation Validate marketing claims: EU 655/2013, FDA drug-vs-cosmetic, FTC, green claims.
market-entry-checklist Step-by-step: classify → regulations → substances → labels → certs → customs → notification.

Cross-market intelligence & action (13)

The skills that move you from "we have a problem" to "we shipped it."

Skill What it does
regulatory-intelligence Signal monitoring: substance bans, labeling changes, recalls, enforcement dates.
multi-jurisdiction-scan Parallel scan across all target markets. RED/ORANGE/YELLOW/GREEN per market. One agent per jurisdiction.
customs-and-trade HS code, duty, landed cost, dual-use, sanctions.
compliance-audit-sprint Pre-launch sprint: identify → map → check → verify → estimate cost. Dispatches parallel agents.
compliance-remediation Fix issues to unblock market entry: reformulate, relabel, test, certify.
evidence-blitz Parallel gather of compliance evidence for audit, certification, or marketplace listing.
responsible-person Set up EU RP, UK RP, US Agent, EAEU AR, China NMPA holder. Mandate letters, costs, obligations.
packaging-compliance EPR per EU member state, PPWR transition, SUP, plastic tax, US state EPR.
recall-response Severity assessment, authority notification (EU 10 days, US 24h, UK 3 days), close-out.
product-safety-incident CPSC 24h, EU Safety Gate 10-day, risk matrix, root cause, consumer comms.
import-export-docs Commercial invoice, packing list, EUR.1/REX/USMCA, DG declarations, Incoterms 2020.
marketplace-compliance Required docs per platform per category: Amazon EU GPSR+EPR, Walmart, Shopify, Etsy, TikTok Shop.
regulatory-calendar Notification renewals, cert expiry, upcoming enforcement (GPSR, CRA, MoCRA GMP, EUDR, ESPR).

18 industry verticals

Deep, regulation-specific playbooks per product category:

cosmetics-compliance · food-compliance · electronics-compliance · textile-compliance · toy-compliance · alcohol-spirits-compliance · supplement-compliance · jewelry-compliance · medical-device-compliance · pet-product-compliance · automotive-aftermarket-compliance · agricultural-compliance · tobacco-vape-compliance · sporting-goods-compliance · baby-children-products-compliance · household-chemicals-compliance · candle-fragrance-compliance · sustainability-compliance

Each vertical covers the full regulatory stack for that category across EU, US, UK, Canada, Japan, Korea, China, ASEAN — not a summary, the actual articles, fee structures, notification portals, and transition dates.

Reference & integration (3)

compliance-frameworks-ref (regulation reference index) · compliance-mcp-tools (Cleo Legal API + Cleo Insight integration patterns) · compliance-reporting (per-product per-market matrix, exportable).

The MCP moat

Most skill libraries are static knowledge — they age the day they ship. This one is wired to live data via two MCP servers:

  • Cleo Legal API — customs classification, substance lookups, duty calculation, landed cost, sanctions screening. The data backbone for product-compliance, customs-and-trade, and substance-screening.
  • Cleo Insight — live regulatory signals across 25,000+ regulations in 49 countries. The signal feed for regulatory-intelligence, multi-jurisdiction-scan, and regulatory-calendar.

The skills work standalone — without MCP, they fall back to web search and file-based evidence with the same prompt structure. With MCP enabled, the same prompts get back current data instead of best-effort lookups.

Multi-agent by default

The Tier 3 action skills dispatch parallel agents via superpowers:dispatching-parallel-agents:

  • compliance-audit-sprint — one agent per target market
  • multi-jurisdiction-scan — one agent per jurisdiction cluster
  • evidence-blitz — one agent per document category

A multi-market launch audit that took a regulatory consultant 3 weeks runs in ~12 minutes.

Built for

  • Indie founders and small product teams (1–10 people) launching physical goods
  • D2C brands expanding from one market to three, five, or ten
  • Marketplace sellers fighting delisting (Amazon GPSR, EPR, MoCRA)
  • Operators handling REACH, CLP, FDA MoCRA, Prop 65, GPSR, CRA, EUDR, CE/UKCA/FCC, EN 71, and the long tail
  • Regulatory consultants who want first-pass screening done in minutes, not days

Not built for

We're not trying to replace your specialists. We get you 80% of the way there so your specialist can focus on the hard 20%.

  • We don't replace a CE Notified Body audit (Class IIa+ medical devices, Cat III PPE, etc.)
  • We don't replace a Cosmetic Product Safety Assessor signing your CPSR
  • We don't replace a licensed customs broker for actual border clearance
  • We don't replace legal counsel for litigation, enforcement defense, or product liability
  • We don't give legal advice. Always verify against official sources before a shipping decision.

Why we built this

We're Anaëlle (CEO) and Naomie (CDO), the cofounders of Cleo Labs. We started compliance work because we kept watching the same scene repeat: a small brand spends 14 months building a beautiful product, ships their first container into Rotterdam or Felixstowe, and gets it held at customs over a missing REACH dossier or an Annex III substance they didn't know was capped last quarter. A 40-foot container blocked at the EU border costs €15–40k in storage, demurrage, and rework before anyone touches the product itself.

The knowledge to prevent that exists. It just isn't where the founder is — it's locked in €800/hour consultant decks and 4,000-page regulation PDFs. So we put it where the founder is: in their AI agent. That's this repo.

Examples

See EXAMPLES.md for full walkthroughs (face cream in EU+UK, Bluetooth speaker in US+EU, chocolate to Japan, toy safety, Amazon EU evidence pack).

Contributing

PRs welcome — especially new vertical playbooks, jurisdiction updates, and corrections to substance limits. Start with CONTRIBUTING.md and CODE_OF_CONDUCT.md. Security issues: see SECURITY.md.

License

MIT. See LICENSE.

Disclaimer

This is compliance guidance, not legal advice.

The skills provide a starting point based on publicly available regulations. They do not replace a qualified regulatory consultant, Notified Body, safety assessor, customs broker, or legal counsel.

Regulatory data (substance limits, enforcement dates, fee amounts, classification rules) changes constantly. Always verify critical information against the official source (EUR-Lex, FDA, gov.uk, MHLW, etc.) before making a business decision. Cleo Labs is not liable for decisions made on the basis of these skills.


Built by Cleo Labs. Backed by the MARIA engine — 25,000 regulations, 49 countries, live.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选