SkillAgentSearch skills...

trivy-mcp

Trivy plugin for starting an MCP server

Install / Use

claude mcp add aquasecurity -- npx -y github:aquasecurity/trivy-mcp

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

64/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop
Cursor

Trivy MCP Server Plugin

GitHub All Releases

https://github.com/user-attachments/assets/125791b0-3164-4dcc-8fb3-e45481a9cbf7

This plugin starts a Model Context Protocol (MCP) server that integrates Trivy's security scanning capabilities with VS Code and other MCP-enabled tools.

Features

  • Natural Language Scanning: Ask questions about security issues in natural language
  • Multiple Scan Types:
    • Filesystem scanning for local projects
    • Container image vulnerability scanning
    • Remote repository security analysis
  • Integration with Aqua Platform: Optional integration with Aqua Security's platform for enhanced scanning capabilities and assurance policy compliance
  • Flexible Transport: Support for stdio, streamable HTTP, and SSE (Server-Sent Events) transport protocols
  • IDE Integration: Seamless integration with VS Code, Cursor, JetBrains IDEs, and Claude Desktop

Quick Start

Installation

trivy plugin install mcp

Starting the Server

trivy mcp

Documentation

For comprehensive documentation, please see the docs directory:

Example Query

After setting up the plugin and configuring your IDE, you can start asking security-related questions:

Are there any vulnerabilities or misconfigurations in this project?

For more examples, see the Example Queries page.

License

MIT License - see the LICENSE file for details.

Related Skills

View on GitHub
GitHub Stars49
CategorySecurity
Updated9mo ago
Forks8

Languages

Go

Security Score

86/100

Audited on Dec 17, 2025

2 low1 info