Grype MCP Server
OfficialRelated Servers
Alternatives to Grype MCP Server
No user-submitted related servers found.
Related Servers
- FlicenseAqualityNot gradedmaintenancePerforms vulnerability scans using Trivy to generate Software Bill of Materials (SBOM) in CycloneDX format. It enables automated security auditing and dependency tracking through the Model Context Protocol.1-
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to drive OWASP ZAP vulnerability scanning via the Model Context Protocol.4MIT

Aribot MCPofficial
AlicenseNot gradedqualityBmaintenanceEnables security work such as threat modeling, scanning, compliance checks, and remediation through AI assistants using the Model Context Protocol.MIT- AlicenseAqualityFmaintenanceMulti-engine container and system vulnerability scanning for AI agents. Wraps Trivy and Grype with cross-engine validation, SBOM generation, and IaC misconfiguration scanning.158 npmMIT
- AlicenseAqualityDmaintenanceEnables AI agents to search, retrieve, and analyze vulnerability data from the NIST National Vulnerability Database through a comprehensive Model Context Protocol server.88MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to perform vulnerability scanning on Docker/OCI images, check CVE details, analyze licenses, and compare scan results via ScanRook.88 npmMIT
TDQS
Scored across 9 tools
Each tool has a clearly distinct purpose: installation check, DB info, vulnerability details, three scan types (directory, image, PURL), search, and two update operations. No overlap.
All tool names follow a consistent verb_noun pattern in snake_case (e.g., find_grype, scan_dir, update_db), making them predictable and easy to use.
9 tools is well-scoped for a vulnerability scanning server: covering installation, scanning, searching, and updates without unnecessary bloat or missing essentials.
Covers core workflows: installation check, DB info, scanning (directory, image, PURL), vulnerability details, search, and updates. Minor gaps like returning raw scan results or listing installed packages, but not critical.