High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
Trivy MCP server plugin for security scans
This plugin adds an MCP server to Trivy so tools like Cursor and other MCP clients can query security results in natural language. It supports filesystem scans, container image scans, and remote repository analysis, with optional Aqua Platform integration and multiple transport options.
Builders who want their editor or MCP client to ask Trivy about security issues in code, images, and repositories.
You can check security problems from your agent or IDE instead of switching to separate Trivy commands.
What it does
Natural language security queries
You can ask questions about vulnerabilities and misconfigurations in plain language.
Multiple scan types
It can scan local filesystems, container images, and remote repositories.
MCP transport options
It supports stdio, streamable HTTP, and SSE transport.
IDE integration
The README calls out support for VS Code, Cursor, JetBrains IDEs, and Claude Desktop.
Optional Aqua Platform integration
It can connect to Aqua Security's platform for extra scanning and assurance policy compliance.
How to get it
- 1Run
trivy plugin install mcp
- 2Run
trivy mcp
README
Trivy MCP Server Plugin
https://github.com/user-attachments/assets/125791b0-3164-4dcc-8fb3-e45481a9cbf7
This plugin starts a Model Context Protocol (MCP) server that integrates Trivy's security scanning capabilities with VS Code and other MCP-enabled tools.
Features
- Natural Language Scanning: Ask questions about security issues in natural language
- Multiple Scan Types:
- Filesystem scanning for local projects
- Container image vulnerability scanning
- Remote repository security analysis
- Integration with Aqua Platform: Optional integration with Aqua Security's platform for enhanced scanning capabilities and assurance policy compliance
- Flexible Transport: Support for stdio, streamable HTTP, and SSE (Server-Sent Events) transport protocols
- IDE Integration: Seamless integration with VS Code, Cursor, JetBrains IDEs, and Claude Desktop
Quick Start
Installation
trivy plugin install mcp
Starting the Server
trivy mcp
Documentation
For comprehensive documentation, please see the docs directory:
- Installation Guide
- Quick Start Guide
- Configuration Options
- IDE Integration
- Example Queries
- Authentication
Example Query
After setting up the plugin and configuring your IDE, you can start asking security-related questions:
Are there any vulnerabilities or misconfigurations in this project?
For more examples, see the Example Queries page.
License
MIT License - see the LICENSE file for details.
Files in the repo
- .github
- cmd
- docs
- internal
- pkg
- .gitignore
- .golangcli.yml
- CODE_OF_CONDUCT.md
- DEVELOPMENT.md
- go.mod
- go.sum
- LICENSE
- Makefile
- plugin.yaml
- README.md
Discussion (0)
Ask about usage, or say what you built with itSign in to join the discussion.
No comments yet. Be the first to say what this is good for.
More connectors

Universal provider proxy for OpenAI Codex & Claude Code — use any LLM (Claude, Gemini, Grok, DeepSeek, Ollama…) with Codex CLI, App, SDK, and Claude Code
Git-native persistent memory for AI coding agents. Implements Google OKF v0.2 with sub-300µs in-memory BM25 search, embedded MCP server, and progressive disclosure. Slashes token bloat by 80% with zero external databases or dependencies. Built in pure Go.
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.
20 MB lightweight cross-platform database client for 90+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and Docker. | 轻量级跨平台数据库管理工具,支持 MySQL、PostgreSQL、SQLite、Redis、MongoDB、达梦等 90+ 数据库,提供桌面端、Docker、CLI、内置 AI 助手和 MCP Server。