Skip to main content
Glama

What it does

The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records and tools for mapping project dependencies to vendor security-documentation pages.

Tools

Tool

What it does

Cost

trustlists_search

Search thousands of trust centers by name or domain

Free

trustlists_lookup

Look up a single vendor by exact domain

Free

trustlists_browse

Filter by platform, listed framework, or CSA STAR level

Free

trustlists_audit_dependencies

Audit package.json, requirements.txt, go.mod, etc.

Free

Skills

The plugin ships with skills your AI assistant uses automatically:

  • lookup-vendor - Find a vendor's trust center and listed frameworks

  • audit-dependencies - Map project dependencies to public trust center records

  • compliance-quick-check - Check whether a directory record lists a requested framework

Related MCP server: Depfender MCP Server

Example usage

In Cursor or Claude Code, just ask:

"Look up Stripe's trust center"

"Audit my package.json for vendor security"

"Does Datadog's trust center list HIPAA information?"

The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.

Quick Install (Cursor, Claude Desktop, Claude Code)

Add this to your MCP config and restart:

{
  "mcpServers": {
    "trustlists": {
      "command": "npx",
      "args": ["-y", "@trustlists/mcp"]
    }
  }
}

App

Config location

Cursor

Settings → MCP → Edit config (or ~/.cursor/mcp.json)

Claude Desktop

~/Library/Application Support/Claude/claude_desktop_config.json

Claude Code

~/.claude/settings.json or .claude/settings.json in your project

Full installation guide → (includes troubleshooting)

Pricing

The four directory tools are free and require no trustlists account. SOC 2 analysis and other account-based workflows live in trustlists Companion.

  • Free MCP tools - Search, lookup, browse, and dependency mapping

  • Companion - Account-based SOC 2 analysis, favorites, sharing, and vendor follow-up

Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.

Development

# Install dependencies
npm install

# Build the MCP server
npm run build

# Test locally
npm run test:local

See docs/development.md for the full development guide.

License

Apache 2.0. See LICENSE and NOTICE.

A
license - permissive license
Not graded
quality - not tested
A
maintenance

Maintenance

Maintainers
Response time
8wRelease cycle
3Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    F
    maintenance
    Enables AI agents to query trust scores for MCP servers and agent skills while scanning content for potential security issues. It provides direct access to the Vigile trust registry to help users evaluate the safety of third-party tools and integrations.
    9
    91
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables users to scan software packages for data exfiltration and security threats directly within their IDE across npm, PyPI, Cargo, and Maven ecosystems. This tool helps ensure the safety of project dependencies by identifying potential risks before they are integrated.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Passive website security and trust auditor that checks for security, SEO, AI surface, email, and other exposures, producing a score and remediation plan.
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.
    4
    MIT

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/trustlists/trustlists-plugin'

If you have feedback or need assistance with the MCP directory API, please join our Discord server