Skip to main content
Glama

What it does

The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records and tools for mapping project dependencies to vendor security-documentation pages.

Tools

Tool

What it does

Cost

trustlists_search

Search thousands of trust centers by name or domain

Free

trustlists_lookup

Look up a single vendor by exact domain

Free

trustlists_browse

Filter by platform, listed framework, or CSA STAR level

Free

trustlists_audit_dependencies

Audit package.json, requirements.txt, go.mod, etc.

Free

Skills

The plugin ships with skills your AI assistant uses automatically:

  • lookup-vendor - Find a vendor's trust center and listed frameworks

  • audit-dependencies - Map project dependencies to public trust center records

  • compliance-quick-check - Check whether a directory record lists a requested framework

Related MCP server: mcp-dependency-version

Example usage

In Cursor or Claude Code, just ask:

"Look up Stripe's trust center"

"Audit my package.json for vendor security"

"Does Datadog's trust center list HIPAA information?"

The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.

Quick Install (Cursor, Claude Desktop, Claude Code)

Add this to your MCP config and restart:

{
  "mcpServers": {
    "trustlists": {
      "command": "npx",
      "args": ["-y", "@trustlists/mcp"]
    }
  }
}

App

Config location

Cursor

Settings → MCP → Edit config (or ~/.cursor/mcp.json)

Claude Desktop

~/Library/Application Support/Claude/claude_desktop_config.json

Claude Code

~/.claude/settings.json or .claude/settings.json in your project

Full installation guide → (includes troubleshooting)

Pricing

The four directory tools are free and require no trustlists account. SOC 2 analysis and other account-based workflows live in trustlists Companion.

  • Free MCP tools - Search, lookup, browse, and dependency mapping

  • Companion - Account-based SOC 2 analysis, favorites, sharing, and vendor follow-up

Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.

Development

# Install dependencies
npm install

# Build the MCP server
npm run build

# Test locally
npm run test:local

See docs/development.md for the full development guide.

License

Apache 2.0. See LICENSE and NOTICE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    F
    maintenance
    Enables AI agents to query trust scores for MCP servers and agent skills while scanning content for potential security issues. It provides direct access to the Vigile trust registry to help users evaluate the safety of third-party tools and integrations.
    9
    23 npm
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.
    4
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables searching and analyzing CVEs and vulnerabilities from multiple sources, optimized for PR review scenarios to help developers identify the latest security issues.
    8
    2
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables checking whether software packages are deprecated, archived, stale, active, or unknown with supporting evidence, auditing dependency manifests, and looking up runtime support and end-of-life dates.
    MIT