Trivy MCP Server Plugin
@aquasecurity
About Trivy MCP Server Plugin
Trivy plugin for starting an MCP server
Config
No standard config provided
This server doesn't expose a parseable MCP config block in its README. See the repository for install instructions.
RepositoryTools
No tools detected
We auto-extract tools from the README. The maintainer can list them under a ## Tools heading to populate this section.
Overview
What is Trivy MCP Server Plugin?
Trivy MCP Server Plugin starts a Model Context Protocol (MCP) server that integrates Trivy's security scanning capabilities with VS Code and other MCP-enabled tools, allowing users to ask security-related questions in natural language.
How to use Trivy MCP Server Plugin?
Install the plugin with trivy plugin install mcp, then start the server with trivy mcp. After configuring your IDE, you can ask natural language security questions such as "Are there any vulnerabilities or misconfigurations in this project?"
Key features of Trivy MCP Server Plugin
- Natural language scanning for security issues
- Filesystem scanning for local projects
- Container image vulnerability scanning
- Remote repository security analysis
- Optional integration with Aqua Security’s platform
- Support for stdio, streamable HTTP, and SSE transports
Use cases of Trivy MCP Server Plugin
- Scan a local project’s filesystem for vulnerabilities and misconfigurations
- Analyze container images for known security issues
- Audit remote repositories without cloning them locally
- Ask security questions directly from VS Code, Cursor, JetBrains IDEs, or Claude Desktop
FAQ from Trivy MCP Server Plugin
What transport protocols does Trivy MCP Server Plugin support?
It supports stdio, streamable HTTP, and Server‑Sent Events (SSE) transport protocols.
Can I use it without the Aqua Platform?
Yes, the Aqua Platform integration is optional and only needed for enhanced scanning and assurance policy compliance.
How do I install the Trivy MCP Server Plugin?
Run trivy plugin install mcp in your terminal, then start the server with trivy mcp.
Which IDEs are supported?
The plugin works with VS Code, Cursor, JetBrains IDEs, and Claude Desktop.
Does the plugin require authentication?
Authentication is not required by default, but optional authentication is available for Aqua Platform integration (see the docs for details).
Frequently asked questions
What transport protocols does Trivy MCP Server Plugin support?
It supports stdio, streamable HTTP, and Server‑Sent Events (SSE) transport protocols.
Can I use it without the Aqua Platform?
Yes, the Aqua Platform integration is optional and only needed for enhanced scanning and assurance policy compliance.
How do I install the Trivy MCP Server Plugin?
Run `trivy plugin install mcp` in your terminal, then start the server with `trivy mcp`.
Which IDEs are supported?
The plugin works with VS Code, Cursor, JetBrains IDEs, and Claude Desktop.
Does the plugin require authentication?
Authentication is not required by default, but optional authentication is available for Aqua Platform integration (see the docs for details).
Basic information
More Developer Tools MCP servers
Mobbin
MobbinMobbin MCP connects your AI agents to 600,000+ real product screens, so what they build starts with what already works.

SSH MCP Server
hypnosisSSH MCP server for AI agents: remote commands, file transfer, log search and server audits through OpenSSH.
Vibgrate MCP
VibgrateQuery your team's drift, vulnerability, and migration data from any AI assistant. Vibgrate MCP connects Cursor, Claude, ChatGPT, Windsurf, or VS Code to Vibgrate Cloud: 51 tools for DriftScores, CVEs and EOL runtimes, up
LocalCan
LocalCanGives AI agents public URLs (tunnels) for localhost, live HTTP traffic inspection, snapshot publishing, and access control. Part of LocalCan, the ngrok alternative for Mac, Windows and Linux. Free plan.

Perfex CRM
themesicTurn Perfex CRM into an AI-ready workspace. This MCP server exposes your full REST API to Claude, ChatGPT and any AI agent, so leads, invoices and tasks are one prompt away.
Comments