# SAST SCA SBOM Security Analyzer

> Use this tool when you need to integrate automated security analysis into your CI/CD pipelines or AI-assisted workflows to identify vulnerabilities, generate Software Bills of Materials, and conduct security-focused code reviews. It solves problems related to security testing, compliance, and remediation for DevSecOps teams, security engineers, and development teams. The tool accepts code repositories and package manager inputs, and outputs vulnerability reports, SBOMs, and remediation guidance in various formats.

Canonical page: https://skillsregistry.net/skills/blackkhawkk-sast-sca-sbom-security-analyzer  
JSON: https://api.skillsregistry.net/v1/skills/blackkhawkk-sast-sca-sbom-security-analyzer

## Description

This MCP server provides AI assistants with enterprise-grade security analysis capabilities through integrated SAST, SCA, SBOM generation, and vulnerability scanning tools, built using TypeScript with Snyk integration and CycloneDX SBOM support. The implementation offers four core security analysis tools: Snyk-powered vulnerability testing with configurable severity filtering and multiple output formats, automated Software Bill of Materials generation in JSON/XML/SPDX formats, security-focused code review with pattern-based detection for SQL injection, XSS, command injection, and hardcoded secrets, and comprehensive vulnerability scanning across multiple attack vectors including container security and infrastructure-as-code analysis. Built with fallback mechanisms when commercial tools aren't available, custom security rule engines, and support for multiple package managers, it serves DevSecOps teams needing automated security analysis in CI/CD pipelines, security engineers requiring comprehensive vulnerability assessment capabilities, and development teams wanting to integrate security scanning into their AI-assisted workflows with detailed remediation guidance and compliance reporting.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/blackkhawkk-sast-sca-sbom-security-analyzer)
- **Repository:** <https://github.com/blackkhawkk/mcp_sast_sca_sbom/tree/HEAD/mcp-security-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "blackkhawkk-sast-sca-sbom-security-analyzer"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/blackkhawkk-sast-sca-sbom-security-analyzer` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/blackkhawkk-sast-sca-sbom-security-analyzer/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
