# SBOM Generator (Trivy)

> Use this tool when you need to generate a Software Bill of Materials (SBOM) for container images to analyze dependencies, comply with security requirements, or integrate into CI/CD pipelines. It takes container image references as input and returns detailed component information, including package metadata, licenses, and vulnerability data in CycloneDX format. Ideal for DevOps and security teams, it provides an asynchronous interface for executing Trivy scanner commands and processing SBOM data.

Canonical page: https://skillsregistry.net/skills/trivy-sbom-generator  
JSON: https://api.skillsregistry.net/v1/skills/trivy-sbom-generator

## Description

MCP-SBOM Server is a Python-based implementation that performs Trivy scans on container images to generate Software Bill of Materials (SBOM) in CycloneDX format. Built using the FastMCP library, it provides an asynchronous interface for executing Trivy scanner commands and processing the resulting SBOM data. The server exposes a single tool endpoint that accepts container image references, executes the scan, and returns detailed component information including package metadata, licenses, and vulnerability data. This implementation is particularly valuable for DevOps and security teams who need to analyze container dependencies, comply with security requirements, or integrate SBOM generation into their CI/CD pipelines.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** scanned
- **Last scanned:** 2026-09-02

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** devops-ci
- **Updated:** 2026-09-02

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/trivy-sbom-generator)
- **Repository:** <https://github.com/gkhays/mcp-sbom-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "trivy-sbom-generator"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/trivy-sbom-generator` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/trivy-sbom-generator/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
