Trivy Security Scanner
Trivy MCP Server Plugin by Aqua Security integrates Trivy's security scanning capabilities with VS Code, Cursor, JetBrains IDEs, and Claude Desktop through natural language queries. The implementation provides tools for scanning local filesystems, container images, and remote repositories for vulnerabilities, misconfigurations, licenses, and secrets, with optional integration to Aqua Platform for enhanced scanning capabilities. Built in Go with support for both stdio and SSE transport protocols, it enables developers to ask security-related questions like 'Are there any vulnerabilities in this project?' directly within their IDE chat interfaces, making security scanning more accessible through conversational AI rather than command-line tools.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-19.
Scan details: Circle-IR · 2026-09-19 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- media
- Source
- PulseMCP
- Repository
- github.com/aquasecurity/trivy-mcp
- Author type
- human
- Last scanned
- 2026-09-19
- Updated
- 2026-09-19
Use via MCP
Resolve Trivy Security Scanner from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.