Trivy Security Scanner MCP Server

Created By
norbinsha year ago
A Model Context Protocol (MCP) server that provides Trivy security scanning capabilities through a standardized interface.
Overview

what is Trivy Security Scanner MCP Server?

Trivy Security Scanner MCP Server is a Model Context Protocol (MCP) server that provides Trivy security scanning capabilities through a standardized interface, designed for experimentation and learning purposes.

how to use Trivy Security Scanner MCP Server?

To use the server, install the required dependencies, start the server using the command python server.py --transport sse --port 54321, and configure it in Cursor IDE to automatically scan for vulnerabilities when dependencies are modified.

key features of Trivy Security Scanner MCP Server?

  • 🔍 Project Scanning: Automatically scans project directories for security vulnerabilities using Trivy.
  • 🛠️ Automated Fixes: Updates vulnerable dependencies to secure versions automatically.
  • 📦 Multi-Package Support: Supports multiple package managers including Python, Node.js, Ruby, and Go.

use cases of Trivy Security Scanner MCP Server?

  1. Scanning a project for security vulnerabilities before deployment.
  2. Automatically fixing vulnerable dependencies during development.
  3. Integrating security checks into the development workflow with Cursor IDE.

FAQ from Trivy Security Scanner MCP Server?

  • Is this project production-ready?

No, this is a proof of concept project intended for experimentation and learning purposes only.

  • What are the prerequisites for using this server?

You need Python 3.12 or higher and Trivy installed on your system.

  • How does the server integrate with Cursor IDE?

You can configure the server in Cursor IDE to automatically trigger security scans when dependency files are modified.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
norbinsh
Star
-
Language
-
License
-
Category
security

Recommend Servers

View All
Tavily Mcp
@tavily-ai

JavaScript
a year ago
AI Work Market — USDC settlement rails for AI labor on Base Mainnet)
@Dario (DME)

AI Work Market is a USDC escrow protocol on Base Mainnet, designed for autonomous AI agents to find work, post jobs, and settle payments without humans in the loop. This MCP server exposes 10 tools: **Escrow lifecycle** - `create_intent_quote` — get calldata + gas estimate for funding a new escrow intent - `submit_proof_quote` — get calldata for the seller to submit a proof URI - `release_funds_quote` — get calldata for the buyer to release payment (or claim/refund) **x402 single-call binding** - `x402_consume` — replaces the 5-step x402 flow with one HMAC-signed POST that returns a delivery URL **Onboarding & discovery** - `agent_onboard` — generate a signed agent card with marketplace attestation - `agent_search` — tf-idf search over the live agent catalog - `agent_reputation` — server-side reputation from on-chain Released/Refunded/Disputed events **Live state** - `system_status` — live on-chain state (nextIntentId, accumulatedFees, contract balance, owner) - `escrow_rules` — contract semantics, lifecycle, call guides, failure modes - `events_subscribe` — SSE stream of new on-chain intent events All endpoints are serverless (Vercel) and return their schema on GET. No browser, no wallet UI required for an agent to integrate. The protocol takes a 1% commission on every settlement; the rest goes to the seller. The full AgentCard is at `/.well-known/agent-card.json` (A2A-compatible). The OpenAPI 3.0.3 spec is at `/.well-known/openapi.json` with `components.securitySchemes` (none, hmacX402). `robots.txt` allows GPTBot, ClaudeBot, anthropic-ai, PerplexityBot, Google-Extended, Applebot-Extended, CCBot, Amazonbot.

16 hours ago
Voyei

6 hours ago