trustlists
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@trustlistsAudit my package.json for vendor security"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
What it does
The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records and tools for mapping project dependencies to vendor security-documentation pages.
Tools
Tool | What it does | Cost |
| Search thousands of trust centers by name or domain | Free |
| Look up a single vendor by exact domain | Free |
| Filter by platform, listed framework, or CSA STAR level | Free |
| Audit | Free |
Skills
The plugin ships with skills your AI assistant uses automatically:
lookup-vendor - Find a vendor's trust center and listed frameworks
audit-dependencies - Map project dependencies to public trust center records
compliance-quick-check - Check whether a directory record lists a requested framework
Related MCP server: mcp-dependency-version
Example usage
In Cursor or Claude Code, just ask:
"Look up Stripe's trust center"
"Audit my package.json for vendor security"
"Does Datadog's trust center list HIPAA information?"
The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.
Quick Install (Cursor, Claude Desktop, Claude Code)
Add this to your MCP config and restart:
{
"mcpServers": {
"trustlists": {
"command": "npx",
"args": ["-y", "@trustlists/mcp"]
}
}
}App | Config location |
Cursor | Settings → MCP → Edit config (or |
Claude Desktop |
|
Claude Code |
|
Full installation guide → (includes troubleshooting)
Pricing
The four directory tools are free and require no trustlists account. SOC 2 analysis and other account-based workflows live in trustlists Companion.
Free MCP tools - Search, lookup, browse, and dependency mapping
Companion - Account-based SOC 2 analysis, favorites, sharing, and vendor follow-up
Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.
Development
# Install dependencies
npm install
# Build the MCP server
npm run build
# Test locally
npm run test:localSee docs/development.md for the full development guide.
License
Apache 2.0. See LICENSE and NOTICE.
Links
This server cannot be deployed
Maintenance
Related MCP Connectors
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
Live trust signals for domains & packages: age, registrar, typosquat resemblance.
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Related MCP Servers
- AlicenseAqualityFmaintenanceEnables AI agents to query trust scores for MCP servers and agent skills while scanning content for potential security issues. It provides direct access to the Vigile trust registry to help users evaluate the safety of third-party tools and integrations.923 npmMIT
- AlicenseNot gradedqualityAmaintenanceEnables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.4MIT
- FlicenseAqualityDmaintenanceEnables searching and analyzing CVEs and vulnerabilities from multiple sources, optimized for PR review scenarios to help developers identify the latest security issues.82-
- AlicenseNot gradedqualityBmaintenanceEnables checking whether software packages are deprecated, archived, stale, active, or unknown with supporting evidence, auditing dependency manifests, and looking up runtime support and end-of-life dates.MIT