# Trivy Security Scanner

> Use this tool when you need to identify security vulnerabilities, misconfigurations, licenses, and secrets in your codebase, container images, or remote repositories. It solves problems related to security scanning, compliance, and risk management by providing instant answers to security-related questions through conversational AI interfaces. It takes natural language queries as input and outputs detailed scan results, making it ideal for developers to integrate security checks directly into their IDEs and workflows.

Canonical page: https://skillsregistry.net/skills/aquasecurity-trivy  
JSON: https://api.skillsregistry.net/v1/skills/aquasecurity-trivy

## Description

Trivy MCP Server Plugin by Aqua Security integrates Trivy's security scanning capabilities with VS Code, Cursor, JetBrains IDEs, and Claude Desktop through natural language queries. The implementation provides tools for scanning local filesystems, container images, and remote repositories for vulnerabilities, misconfigurations, licenses, and secrets, with optional integration to Aqua Platform for enhanced scanning capabilities. Built in Go with support for both stdio and SSE transport protocols, it enables developers to ask security-related questions like 'Are there any vulnerabilities in this project?' directly within their IDE chat interfaces, making security scanning more accessible through conversational AI rather than command-line tools.

## Trust

- **Trust score (0–1):** 0.86
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** media
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/aquasecurity-trivy)
- **Repository:** <https://github.com/aquasecurity/trivy-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "aquasecurity-trivy"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/aquasecurity-trivy` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/aquasecurity-trivy/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
