Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. 🔒 Security
  3. SBOMApp SBOM Generator & Vulnerability Scanner
SBOMApp   SBOM Generator & Vulnerability Scanner logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 10:38:30 PM

SBOMApp SBOM Generator & Vulnerability Scanner

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time — check back soon.
View RepositoryVisit Website

Generate SBOMs, scan vulnerabilities, and analyze dependencies from Git repos via MCP.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON â–Ÿ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself — its README, its docs, or a verified owner. We haven’t found those for SBOMApp - SBOM Generator & Vulnerability Scanner, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing Alternatives🔒 More in Security

Documentation Overview

SBOM for VS Code by SBOMApp!

“AI wrote the code – now audit what’s inside”

SBOM MCP Server - SBOMApp MCP Server brings software supplychain security assistant inside VS Code. With a simple natural language prompt, developers can instantly generate SBOMs (SPDX/CycloneDX), scan for CVEs, Verify Licence Compliance, and get actionable remediation guidance.

No switching tools, no manual scripts, everything happens right inside your editor, keeping you fast, secure, and focused.

alt text

Why teams choose SBOMApp MCP:

Endtoend visibility: Build complete SBOMs (including transitive deps) from local workspaces or Git repos, then attach them to builds and releases.

Actionable security: Run vulnerability scans, drill into CVE details, and get fix versions and upgrade paths.

License clarity: Identify copyleft and other risky licenses early with auditfriendly summaries.

Copilot + MCP native: Works naturally in Agent Mode, so prompts like “generate sbom”, “scan vulnerabilities” 

Frictionless onboarding: Start with a 7day free trial or connect your enterprise server using secure tokens stored by VS Code.

Designed for securityminded engineering orgs: Whether you’re shipping regulated software, hardening your SDLC, or preparing for customer SBOM requests, SBOMApp MCP delivers the SBOM, CVE, and license insights your teams need

Absolute Privacy Guarantee!

We don’t store your code, your SBOMs, your dependencies, or any project data — ever. Only your email (for free trial) and API token are stored securely. Everything else stays completely on your machine.

SBOMApp MCP Server

Connect to a remote SBOM MCP Server to perform software bill of materials analysis, vulnerability scanning, opensource license details and dependency management.

Quick Start Guide

Step 1: Install the Extension

  1. Open VS Code
  2. Go to Extensions (Ctrl+Shift+X or Cmd+Shift+X on Mac)
  3. Search for "SBOMApp MCP Server"
  4. Click Install

Or install directly from the VS Code Marketplace

Step 2: Free Trial - Get Started Instantly!

New users get a FREE 90-day trial with 100 Tokens - no credit card required!

Automatic Trial Registration:

  1. Install the extension
  2. On first launch, you'll be prompted to start your free trial
  3. Enter your email address
  4. Your API key is automatically configured - you're ready to go!

Simple steps to Activate Trial!

prerequisites : Visual Studio Code should be Installed with langauage Models enabled.

  • Click on the SBOM MCP status bar!

  • Click on the start free trial option,

  • Click on th start free trial popup,

  • Enter your official email-id & click Enter,

  • After sucessful Registration, you will get the trial activation notification!

  • Reload the Window using the command "CTRL+SHIFT+P" or click "Command Palette" and Select "Developer:Reload Window" to Refresh the MCP Server!

Trial Features:

FeatureTrial
Validity90 days
Token Requests100 tokens
SBOM Generationyes
Vulnerability Scanningyes

Upgrade to Pro:

When your trial expires or tokens are exhausted, upgrade at: https://payment.sbomapp.com or https://sbomapp.com

Manual Configuration (Enterprise Users):

If you have a license key from your administrator:

  1. Press Ctrl+Shift+P → "SBOMApp: Configure Remote Server"
  2. Enter your Server URL: https://mcp.sbomapp.com/mcp
  3. Enter your API Key

Step 3: Test the Connection

  1. Press Ctrl+Shift+P again
  2. Type "SBOMApp: Test Connection" and press Enter
  3. You should see a success message with available tools count

Step 4: Restart the VS code.

Mandatory step! Once credentials and connections are tested, Kindly restart the VS Code.

Step 5: Start Using "@sbomapp" in chat box

Once connected (green status bar shows ✓), you can ask GitHub Copilot:

Note: Ensure your project is imported in VS Code before using SBOMApp MCP.

Code
"@sbomapp/help"
"@sbomapp Generate an SBOM for my current project or 
Generate an SBOM for my current project".
"@sbomapp scan vulnerabilities" or "Check if lodash 4.17.0 has any security vulnerabilities" 

Features

  • Easy Configuration: Simple setup wizard to connect to your SBOM MCP Server
  • Secure Authentication: Bearer token authentication with secure storage
  • Connection Testing: Verify your server connection before use
  • Status Bar Indicator: See connection status at a glance
  • Tool Browser: View all available SBOM analysis tools
  • Direct Tool: Say "@sbomapp Generate SBOM for my current project" in chat - it just works!

Commands

CommandDescription
SBOMApp: Start Free TrialRegister for a free 7-day trial
SBOMApp: Check Trial StatusView remaining tokens and expiry
SBOMApp: Check Token UsageView detailed Token usage statistics
SBOMApp: Configure Remote ServerSet up server URL and API key
SBOMApp: Test ConnectionVerify connection to the server
SBOMApp: Show Available ToolsBrowse available SBOM analysis tools
SBOMApp: DisconnectDisconnect from the server

Configuration

This extension provides the following settings:

SettingDescriptionDefault
sbomRemoteMcp.serverUrlURL of the remote SBOM MCP Server(empty)
sbomRemoteMcp.apiKeyAPI key for authentication(empty)
sbomRemoteMcp.autoConnectAuto-connect on VS Code startuptrue
sbomRemoteMcp.showStatusBarShow status in status bartrue

Available Tools

Once connected, you can use these SBOM analysis tools with GitHub Copilot:

ToolDescription
sbomapp_generateSbomFromWorkspaceGenerate SBOM, scan vulnerabilities, analyze dependencies, and check licenses for your current project
generate_sbomGenerate a complete SBOM with vulnerability report for your project
scan_vulnerabilitiesScan your project for security vulnerabilities with CVE details
analyze_dependenciesAnalyze all dependencies — types, licenses, and risk assessment

Tip: Just type "generate sbom", "scan vulnerabilities", or "analyze dependencies" in Copilot chat — the extension automatically analyzes your current project!

Example Copilot Prompts after SBOM and vulnerabilities Generation

Try asking Copilot these questions:

  • "Fix the above Identified vulnerabilities"
  • "Replace component_1 with suitable secure component"

Requirements

  • VS Code 1.106 or higher
  • Access to a running SBOM MCP Server
  • Valid API key for authentication

Getting an API Key

Option 1: Free Trial (Recommended for Individual Users)

  • Start the extension and follow the trial registration prompt
  • Or run command: SBOMApp: Start Free Trial
  • Trial includes: 90 days, 100 Tokens

Option 2: Purchase Pro License

  • Visit https://payment.sbomapp.com or https://sbomapp.com to purchase
  • Get Tokens and advanced features
  • API key delivered instantly via email

Option 3: Enterprise License

  • Contact your SBOM MCP Server administrator
  • Email: sbomappsupport@iarminfo.com

Troubleshooting

Connection Failed

  • Verify the server URL is correct (should end with /mcp)
  • Check that the server is running and accessible
  • Ensure your API key is valid and not expired
  • Check if firewall allows the connection

Tools Not Working

  • Make sure the connection is established (green ✓ in status bar)
  • Check VS Code MCP settings are configured correctly
  • Try disconnecting and reconnecting
  • Restart VS Code if issues persist

Status Bar Not Showing

  • Check that sbomRemoteMcp.showStatusBar is enabled in settings
  • Try reloading VS Code (Ctrl+Shift+P → "Reload Window")

Check Token Usage Status

  • Click on the status bar "SBOM MCP" → Select "Check token Usage"
  • View detailed usage statistics in the output panel

Check Trial Status

  • Click on the status bar "SBOM MCP" → Select "Check Trial Status"
  • View remaining tokens, days left, and upgrade options
  • Status bar shows trial info: ✓ SBOM MCP [Trial: 450]

Trial Expired or Tokens Exhausted

  • Status bar shows: SBOM MCP [Trial Expired]
  • Click "Upgrade Now" in the popup to purchase Pro license
  • Or run command: SBOMApp: Configure Remote Server to enter a new API key
  • Upgrade at: https://payment.sbomapp.com or https://sbomapp.com

Authentication Errors

  • Verify your API key is correct
  • Ensure the API key has proper permissions
  • Contact your administrator if the key was recently rotated

Privacy & Security

  • API keys are stored in VS Code's secure storage
  • All communication uses HTTPS (when configured)
  • No data is sent to third parties
  • Credentials are never logged or exported

Support

  • 📧 Email: sbomappsupport@iarminfo.com

Read the full README →View source on GitHub →

Related MCP Servers

View all in Security View all alternatives
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    🔒 Security2 views
    Compare vs Mobb Vibe Shield MCP →
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    🔒 Security3 views
    Compare vs Jadx AI MCP →
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    🔒 Security3 views
    Compare vs Apktool MCP Server →
  • MCP Maigret logoMCP Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    🔒 Security4 views
    Compare vs MCP Maigret →

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about SBOMApp SBOM Generator & Vulnerability Scanner

We don't have a confirmed install command for SBOMApp - SBOM Generator & Vulnerability Scanner yet, so we don't publish a generated one — a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/mcpsbom/sbomapp-mcp-server) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSBOMApp   SBOM Generator & Vulnerability Scanner AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sbomapp-sbom-generator-vulnerability-scanner?style=directory)](https://allmcps.com/mcp/sbomapp-sbom-generator-vulnerability-scanner)
HTML Embed
<a href="https://allmcps.com/mcp/sbomapp-sbom-generator-vulnerability-scanner"><img src="https://allmcps.com/api/badge/sbomapp-sbom-generator-vulnerability-scanner?style=directory" alt="SBOMApp SBOM Generator & Vulnerability Scanner on AllMCPs" /></a>

Technical Specs & Signals

Category🔒Security
More technical detailsExpand â–Ÿ
Last updatedSep 7, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
29Quality signal: Emerging · 29/100How this signal is calculated â–Ÿ
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

★ FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in 🔒 Security →Best MCP servers for Security →Alternatives to SBOMApp SBOM Generator & Vulnerability Scanner →Install in Claude DesktopInstall in CursorInstall in VS Code