The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Trustlists listing page.
Public vendor trust center tools for Cursor and Claude Code.
Find trust centers, browse listed frameworks, and map project dependencies without leaving your editor.
The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records and tools for mapping project dependencies to vendor security-documentation pages.
| Tool | What it does | Cost |
|---|---|---|
trustlists_search | Search thousands of trust centers by name or domain | Free |
trustlists_lookup | Look up a single vendor by exact domain | Free |
trustlists_browse | Filter by platform, listed framework, or CSA STAR level | Free |
trustlists_audit_dependencies | Audit package.json, requirements.txt, go.mod, etc. | Free |
The plugin ships with skills your AI assistant uses automatically:
In Cursor or Claude Code, just ask:
"Look up Stripe's trust center"
"Audit my package.json for vendor security"
"Does Datadog's trust center list HIPAA information?"
The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.
Add this to your MCP config and restart:
| App | Config location |
|---|---|
| Cursor | Settings → MCP → Edit config (or ~/.cursor/mcp.json) |
| Claude Desktop | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Code | ~/.claude/settings.json or .claude/settings.json in your project |
Full installation guide → (includes troubleshooting)
The four directory tools are free and require no trustlists account. SOC 2 analysis and other account-based workflows live in trustlists Companion.
Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.
See docs/development.md for the full development guide.
Apache 2.0. See LICENSE and NOTICE.