# Endor Labs

> Use this tool when you need to integrate real-time security scanning into your development workflow, enabling immediate detection of vulnerabilities and security issues as you write code. It solves problems such as exposed credentials, open source risks, and common security issues, providing outputs like comprehensive security scans and vulnerability database lookups. Ideal for shift-left security practices, it takes inputs like code dependencies and environment variables, and supports configurable language-specific scanning.

Canonical page: https://skillsregistry.net/skills/endor-labs-security  
JSON: https://api.skillsregistry.net/v1/skills/endor-labs-security

## Description

The Endor Labs MCP server integrates security scanning directly into IDEs like Cursor and Visual Studio Code, enabling real-time vulnerability detection and security analysis as developers write code. Built around the endorctl CLI tool, it provides four core capabilities: dependency vulnerability checking, vulnerability database lookups, resource context retrieval, and comprehensive security scans that detect open source risks, common security issues, and exposed credentials in Git repositories. The implementation supports configurable language-specific scanning, environment variable customization, and selective tool management, making it valuable for shift-left security practices where developers need immediate feedback on security issues during development rather than waiting for CI/CD pipeline results.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/endor-labs-security)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "endor-labs-security"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/endor-labs-security` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/endor-labs-security/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
