SAST SCA SBOM Security Analyzer
This MCP server provides AI assistants with enterprise-grade security analysis capabilities through integrated SAST, SCA, SBOM generation, and vulnerability scanning tools, built using TypeScript with Snyk integration and CycloneDX SBOM support. The implementation offers four core security analysis tools: Snyk-powered vulnerability testing with configurable severity filtering and multiple output formats, automated Software Bill of Materials generation in JSON/XML/SPDX formats, security-focused code review with pattern-based detection for SQL injection, XSS, command injection, and hardcoded secrets, and comprehensive vulnerability scanning across multiple attack vectors including container security and infrastructure-as-code analysis. Built with fallback mechanisms when commercial tools aren't available, custom security rule engines, and support for multiple package managers, it serves DevSecOps teams needing automated security analysis in CI/CD pipelines, security engineers requiring comprehensive vulnerability assessment capabilities, and development teams wanting to integrate security scanning into their AI-assisted workflows with detailed remediation guidance and compliance reporting.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve SAST SCA SBOM Security Analyzer from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.