Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"io-github-mcpsbom-sbom-mcp": {
"command": "<see-readme>",
"args": []
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
SBOM MCP Server - SBOMApp MCP Server brings software supplychain security assistant inside VS Code. With a simple natural language prompt, developers can instantly generate SBOMs (SPDX/CycloneDX), scan for CVEs, Verify Licence Compliance, and get actionable remediation guidance.
No automated test available for this server. Check the GitHub README for setup instructions.
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
No package registry to scan.
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in security / devops
MCP server for using the GitLab API
An evil MCP server used for redteam testing
Enhanced MCP server for GitLab: group projects listing and activity tracking
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
MCP Security Weekly
Get CVE alerts and security updates for io.github.mcpsbom/sbom-mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
SBOM MCP Server - SBOMApp MCP Server brings software supplychain security assistant inside VS Code. With a simple natural language prompt, developers can instantly generate SBOMs (SPDX/CycloneDX), scan for CVEs, Verify Licence Compliance, and get actionable remediation guidance.
No switching tools, no manual scripts, everything happens right inside your editor, keeping you fast, secure, and focused.

Endtoend visibility: Build complete SBOMs (including transitive deps) from local workspaces or Git repos, then attach them to builds and releases.
Actionable security: Run vulnerability scans, drill into CVE details, and get fix versions and upgrade paths.
License clarity: Identify copyleft and other risky licenses early with auditfriendly summaries.
Copilot + MCP native: Works naturally in Agent Mode, so prompts like “generate sbom”, “scan vulnerabilities”
Frictionless onboarding: Start with a 7day free trial or connect your enterprise server using secure tokens stored by VS Code.
Designed for securityminded engineering orgs: Whether you’re shipping regulated software, hardening your SDLC, or preparing for customer SBOM requests, SBOMApp MCP delivers the SBOM, CVE, and license insights your teams need
We don’t store your code, your SBOMs, your dependencies, or any project data — ever. Only your email (for free trial) and API token are stored securely. Everything else stays completely on your machine.
Connect to a remote SBOM MCP Server to perform software bill of materials analysis, vulnerability scanning, opensource license details and dependency management.
Ctrl+Shift+X or Cmd+Shift+X on Mac)Or install directly from the VS Code Marketplace
New users get a FREE 90-day trial with 100 Tokens - no credit card required!
Simple steps to Activate Trial!
prerequisites : Visual Studio Code should be Installed with langauage Models enabled.
Click on the SBOM MCP status bar!
Click on the start free trial option,
Click on th start free trial popup,
Enter your official email-id & click Enter,
After sucessful Registration, you will get the trial activation notification!
Reload the Window using the command "CTRL+SHIFT+P" or click "Command Palette" and Select "Developer:Reload Window" to Refresh the MCP Server!
| Feature | Trial |
|---|---|
| Validity | 90 days |
| Token Requests | 100 tokens |
| SBOM Generation | yes |
| Vulnerability Scanning | yes |
When your trial expires or tokens are exhausted, upgrade at: https://payment.sbomapp.com or https://sbomapp.com
If you have a license key from your administrator:
Ctrl+Shift+P → "SBOMApp: Configure Remote Server"https://mcp.sbomapp.com/mcpCtrl+Shift+P againMandatory step! Once credentials and connections are tested, Kindly restart the VS Code.
Once