MCP server to perform a Trivy scan and produce an SBOM in CycloneDX format.
MCP Sbom Server MCP server exists for a simple reason — assistants are far more useful when they can act on MCP Sbom Server directly instead of describing what you should do. MCP server to perform a Trivy scan and produce an SBOM in CycloneDX format.
Once MCP Sbom Server is connected, these are the calls the assistant has available:
Prerequisites — The Prerequisites tool exposed by this serverConfiguration — The Configuration tool exposed by this serverWindows — The Windows tool exposed by this serverInstall the following. - uv - trivy - Node.js
@modelcontextprotocol/inspector on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. MCP Sbom Server's toolset — Prerequisites, Configuration, Windows — is a fair guide to whether it matches your workflow. It is maintained by gkhays; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| Prerequisites | The Prerequisites tool exposed by this server. |
| Configuration | The Configuration tool exposed by this server. |
| Windows | The Windows tool exposed by this server. |
"mcpServers": {
"mcp-sbom": {
"command": "uv",
"args": [
"--directory",
"/path/to/mcp-sbom",
"run",
"mcp-sbom"
]
}
}Configuration as documented by the project. Restart the client after saving.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.