Best Trivy MCP Servers
Trivy is a comprehensive open source vulnerability scanner for containers and other artifacts, maintained by Aqua Security.
Why this server?
Provides CVE vulnerability scanning using Trivy.
AlicenseBqualityCmaintenanceA comprehensive MCP server for infrastructure operations with 92 tools across 13 categories, covering system monitoring, networking, containers, multi-cloud management, databases, CI/CD, IaC, security, and remote SSH fleet management.Last updated921MITWhy this server?
Enables software composition analysis (SCA) and security assessments using Trivy to find vulnerabilities in project dependencies.
AlicenseBqualityDmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.Last updated6MITWhy this server?
Provides access to Trivy for vulnerability scanning of containers, filesystems, and repositories, integrated into AI-driven security pipelines.

SecPipeofficial
FlicenseAqualityFmaintenanceEnables AI agents to orchestrate security research workflows by connecting to containerized security tools via MCP, allowing automated vulnerability analysis and pipeline execution.Last updated24796Why this server?
Integrates with Trivy to scan Docker images for CVEs and provide security vulnerability summaries.
AlicenseBqualityAmaintenanceManage your entire Docker infrastructure through natural language with 180 tools.Last updated100157MITWhy this server?
Integrates security scanning capabilities for container images and infrastructure configurations to identify vulnerabilities.
AlicenseBqualityCmaintenanceAn MCP server that enables Claude to manage infrastructure across Kubernetes, Docker, Prometheus, and Terraform through natural language. It provides over 42 specialized tools with a safety-first design, including risk-based command classification and audit logging.Last updated43MITWhy this server?
Provides vulnerability scanning for Terraform configurations.
AlicenseAqualityFmaintenanceA Model Context Protocol (MCP) server for producing better Terraform through CLI analysis (tflint, checkov, trivy, kics, infracost), best-practice guidance from terraform-best-practices.com, cloud provider recommendations (Azure, AWS, GCP), and Terraform Registry resource and module guidance.Last updated18691MITWhy this server?
Allows running Trivy scans for vulnerability and security issue detection.
AlicenseBqualityBmaintenanceEnables AI agents to manage the entire ArvanCloud platform (compute, networking, storage, CDN, DNS, etc.) plus a cloud-DevOps toolbox for provisioning, Kubernetes, IaC, security, and networking through natural language.Last updated100MITWhy this server?
Integrates Trivy vulnerability scanner for container image and filesystem security scanning with configurable severity filtering
FlicenseBqualityCmaintenanceEnables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.Last updated7Why this server?
Performs security scans using Trivy to identify vulnerabilities and generate Software Bill of Materials (SBOM) in CycloneDX format.
FlicenseAquality-maintenancePerforms vulnerability scans using Trivy to generate Software Bill of Materials (SBOM) in CycloneDX format. It enables automated security auditing and dependency tracking through the Model Context Protocol.Last updated1