Best Trivy MCP Servers
Trivy is a comprehensive open source vulnerability scanner for containers and other artifacts, maintained by Aqua Security.
Why this server?
Integrates security scanning capabilities for container images and infrastructure configurations to identify vulnerabilities.
AlicenseBqualityCmaintenanceAn MCP server that enables Claude to manage infrastructure across Kubernetes, Docker, Prometheus, and Terraform through natural language. It provides over 42 specialized tools with a safety-first design, including risk-based command classification and audit logging.Last updated43MITWhy this server?
Enables software composition analysis (SCA) and security assessments using Trivy to find vulnerabilities in project dependencies.
AlicenseBqualityCmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.Last updated6MITWhy this server?
Performs security scans using Trivy to identify vulnerabilities and generate Software Bill of Materials (SBOM) in CycloneDX format.
FlicenseAquality-maintenancePerforms vulnerability scans using Trivy to generate Software Bill of Materials (SBOM) in CycloneDX format. It enables automated security auditing and dependency tracking through the Model Context Protocol.Last updated1Why this server?
Integrates Trivy vulnerability scanner for container image and filesystem security scanning with configurable severity filtering
FlicenseBqualityCmaintenanceEnables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.Last updated7Why this server?
Provides methodology and documentation for CVE and dependency scanning, guiding AI agents through vulnerability detection in project dependencies
Alicense-qualityCmaintenanceProvides security assessment methodology, tool documentation, and step-by-step workflows to guide AI agents through vulnerability scanning, static analysis, and penetration testing of applications and URLs.Last updated1MITWhy this server?
Performs container and application vulnerability scanning using Trivy and produces a Software Bill of Materials (SBOM) in CycloneDX format.
FlicenseBqualityCmaintenanceA Model Context Protocol server that performs Trivy scans to generate Software Bill of Materials (SBOM) in CycloneDX format.Last updated13Why this server?
Provides vulnerability scanning capabilities for various sources including filesystems, container images, and code repositories, allowing users to identify vulnerabilities and misconfigurations through an MCP server interface.
MITWhy this server?
Enables container and Infrastructure as Code vulnerability scanning through Trivy integration for Docker images and IaC templates
Alicense-qualityCmaintenanceIntegrates 15+ static application security testing tools (Semgrep, Bandit, TruffleHog, etc.) with Claude Code AI, enabling automated vulnerability scanning and security analysis through natural language commands. Supports cross-platform operation with remote execution on dedicated security VMs.Last updated6MITWhy this server?
Integrated vulnerability scanner for comprehensive security reports across repositories