# ScanRook MCP Server

> Use this tool when you need to identify security vulnerabilities and compliance issues in Docker/OCI images. It enables AI assistants to perform vulnerability scanning, check CVE details, and analyze licenses, providing outputs such as scan results and comparison data. Ideal for use cases requiring image security analysis and compliance checks, such as containerized application development and deployment.

Canonical page: https://skillsregistry.net/skills/devinshawntripp-scanrook-mcp  
JSON: https://api.skillsregistry.net/v1/skills/devinshawntripp-scanrook-mcp

## Description

Enables AI assistants to perform vulnerability scanning on Docker/OCI images, check CVE details, analyze licenses, and compare scan results via ScanRook.

## Trust

- **Trust score (0–1):** 1.00
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-19

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/tg6v4nos1w)
- **Repository:** <https://github.com/devinshawntripp/scanrook-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "devinshawntripp-scanrook-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/devinshawntripp-scanrook-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/devinshawntripp-scanrook-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
