scorecard_mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@scorecard_mcpWhat is the OpenSSF Scorecard for the expressjs/express project?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
scorecard_mcp
This is an example MCP server for OpenSSF Scorecard.
You can use it to ask questions like:
Is urllib3/urllib3 secure?
That's not an endorsement of asking a LLM with limited context if something is secure, but if users are going to ask they should get back an answer informed by context. A better phrased question would be:
What security best practices does node-semver follow?
Installation
There are several ways to install, depending on what editor you're using; see the installation instructions on the example fetch MCP server.
I recommend using:
...
"command": "uxv",
"args": ["scorecard-mcp"]
...So if you're using Visual Studio Code you'd create a .vscode/ directory in your project and add a mcp.json file that looks like this:
{
"servers": {
"scorecard": {
"type": "stdio",
"command": "uvx",
"args": ["scorecard-mcp"]
}
}
}This server cannot be deployed
Maintenance
Related MCP Connectors
Ask any GitHub repository a question. Get source-backed answers.
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Related MCP Servers
AlicenseBqualityDmaintenanceAllows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.179MIT- AlicenseAqualityCmaintenanceEnables interaction with SonarCloud projects, issues, quality gates, and security hotspots through natural language.15MIT
- FlicenseAqualityDmaintenanceEnables natural-language queries about public GitHub repositories, including issues, pull requests, repo metadata, and READMEs, via the GitHub API.5-
- FlicenseNot gradedqualityBmaintenanceProvides natural language querying of open-source community data, including health scores, PR/Issue statistics, contributor analysis, and CLA signings via Claude Desktop.-