Skip to main content
Glama

Trivy MCP Server Plugin

GitHub All Releases

https://github.com/user-attachments/assets/125791b0-3164-4dcc-8fb3-e45481a9cbf7

This plugin starts a Model Context Protocol (MCP) server that integrates Trivy's security scanning capabilities with VS Code and other MCP-enabled tools.

Features

  • Natural Language Scanning: Ask questions about security issues in natural language

  • Multiple Scan Types:

    • Filesystem scanning for local projects

    • Container image vulnerability scanning

    • Remote repository security analysis

  • Integration with Aqua Platform: Optional integration with Aqua Security's platform for enhanced scanning capabilities and assurance policy compliance

  • Flexible Transport: Support for stdio, streamable HTTP, and SSE (Server-Sent Events) transport protocols

  • IDE Integration: Seamless integration with VS Code, Cursor, JetBrains IDEs, and Claude Desktop

Related MCP server: Algolia

Quick Start

Installation

trivy plugin install mcp

Starting the Server

trivy mcp

Documentation

For comprehensive documentation, please see the docs directory:

Example Query

After setting up the plugin and configuring your IDE, you can start asking security-related questions:

Are there any vulnerabilities or misconfigurations in this project?

For more examples, see the Example Queries page.

License

MIT License - see the LICENSE file for details.

-
security - not tested
A
license - permissive license
-
quality - not tested

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/aquasecurity/trivy-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server