Skip to main content
Glama
friendlygeorge

Security Scanner MCP Server

Security Scanner MCP Server

npm License: MIT Glama

Multi-engine container & system vulnerability scanning for AI agents. Wraps Trivy and Grype with cross-engine validation, SBOM generation, and IaC misconfiguration scanning.

Why This Exists

Most security MCP servers wrap a single scanner. This one wraps two — Trivy (Aqua Security) and Grype (Anchore) — and runs them against the same target to surface what each engine catches alone. Different vulnerability databases + different detection logic = broader coverage.

Key differentiator: No other MCP server offers multi-engine cross-validation.

Related MCP server: Grype MCP Server

Features

  • 15 tools covering vulnerability scanning, SBOM generation, IaC checks, and database management

  • Cross-engine validation — run Trivy + Grype on the same image and see what each catches alone

  • MIT licensed — no AGPL encumbrance (unlike @aikidosec/mcp)

  • npm-native — install via npx, works with Claude Desktop, Cursor, and any MCP client

  • No cloud account required — runs locally against Docker daemon or filesystem

Quick Start

🚀 New here? See the Quick Start Guide — get scanning in under 5 minutes.

Prerequisites

Install at least one scanning engine:

# Trivy (recommended)
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin

# Grype (for cross-validation)
curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin

Claude Desktop / Cursor

Add to your MCP configuration:

{
  "mcpServers": {
    "security-scanner": {
      "command": "npx",
      "args": ["-y", "@supernova123/security-scanner-mcp-server"]
    }
  }
}

Standalone

npx @supernova123/security-scanner-mcp-server

Tools

#

Tool

Engine

Description

1

scan_image

Trivy

Scan Docker image for vulnerabilities

2

scan_image_grype

Grype

Same target via Grype (cross-validation)

3

vulnerability_report

Trivy

Detailed report with remediation

4

scan_filesystem

Trivy

Local dir/file vulnerability + misconfig scan

5

scan_filesystem_grype

Grype

Cross-engine filesystem scan

6

scan_repository

Trivy

Remote git repo scan

7

scan_remote_image

Grype

Pull from registry directly (no Docker daemon)

8

scan_purl

Grype

Single Package URL vulnerability lookup

9

scan_sbom

Trivy

Scan SBOM file for vulnerabilities

10

generate_sbom

Trivy

Generate CycloneDX/SPDX SBOM

11

scan_config

Trivy

IaC misconfiguration scan

12

cross_validate

Both

Run both engines, surface divergence

13

db_status

Grype

Check vulnerability DB status

14

update_db

Grype

Update vulnerability database

15

get_version

Both

Engine version + availability

Cross-Validation Example

The cross_validate tool runs both Trivy and Grype on the same Docker image and compares results:

{
  "combined_summary": {
    "total_unique_cves": 47,
    "critical": 2,
    "high": 8,
    "medium": 23,
    "low": 14
  },
  "divergence": {
    "only_in_trivy_count": 5,
    "only_in_grype_count": 3,
    "severity_mismatches": 2,
    "only_in_trivy": ["CVE-2023-1234", ...],
    "only_in_grype": ["CVE-2023-5678", ...]
  },
  "insight": "Cross-validation found 5 CVEs only in Trivy and 3 only in Grype. Using both engines gives broader coverage than either alone."
}

Competitive Landscape

Package

Engine

License

Weekly Downloads

@aikidosec/mcp

Cloud API

AGPL-3.0

~11,800

@paretools/security

Trivy + Semgrep

MIT

~75

@supernova123/security-scanner-mcp-server

Trivy + Grype

MIT

TBD

aquasecurity/trivy-mcp

Trivy (Go plugin)

MIT

N/A (not npm)

anchore/grype-mcp

Grype (Python)

Apache-2.0

N/A (not npm)

Development

git clone https://github.com/friendlygeorge/security-scanner-mcp-server.git
cd security-scanner-mcp-server
npm install
npm run build
npm test

License

MIT — see LICENSE

Install Server
A
license - permissive license
A
quality
F
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Security co-pilot for AI agents. Scans for vulnerabilities like prompt injection, infinite loops, and token bombing in AI Agents, audits MCP servers, verifies AGENTS.md governance, and generates EU AI Act compliance reports.
    Last updated
    10
    108
    3
    Apache 2.0
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.
    Last updated
    9
    9
    Apache 2.0
  • A
    license
    -
    quality
    A
    maintenance
    Real security scanners for AI coding agents — SAST (441 rules), secret detection (419+ patterns), dependency CVEs (OSV.dev), MCP/skill vetting, MITRE ATT&CK. Open-source, Rust, free
    Last updated
    27
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/friendlygeorge/security-scanner-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server