# fortify-sca-mcp

> fortify-sca-mcp — debricked-fortify-sca-mcp. Use this tool when you need to integrate dependency policy checks into your development workflow, solving issues with vulnerable dependencies and ensuring compliance with security standards. It takes in code repositories as input and outputs vulnerability reports, allowing for seamless integration with existing Git workflows. Ideal for use in CI/CD pipelines or standalone security audits.

Canonical page: https://skillsregistry.net/skills/debricked-fortify-sca-mcp  
JSON: https://api.skillsregistry.net/v1/skills/debricked-fortify-sca-mcp

## Description

Embeddable MCP server for Fortify SCA dependency policy checks, designed for standalone use and Debricked CLI integration.

## Trust

- **Trust score (0–1):** 0.86
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/debricked/fortify-sca-mcp)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "debricked-fortify-sca-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/debricked-fortify-sca-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/debricked-fortify-sca-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
