Mmcp.market

Snyk MCP server

by snyk.io·io.snyk/mcp·v1.1304.2·55 stars

Easily find and fix security issues in your applications leveraging Snyk platform capabilities.

B71/100grade B
What users say
No reviews yet
Be the first
Safety scan
B71/100

full report

Adoption
Established

55 stars792k downloads/wk

Reviews

Write one

Nobody has reviewed Snyk yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Snyk tools

No tool declarations could be read from the package source. They show once the server is installed.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

3 medium
  • Code scan321 source files scanned10/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 7 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10

Findings (3)

  • mediumnpm install lifecycle script presentinstall.script
  • mediumeval / new Function usedexec.eval
    dist/cli/231.index.js: …he policy this.wasmInstance.exports.eval(ctxAddr); // Retrieve the result …
  • mediumnpm install lifecycle script presentinstall.script
    package.json: …t/", "test": "npx jest test/*", "postinstall": "node wrapper_dist/bootstrap.js exec" …
Overall 71/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install Snyk in Claude Code, Cursor or VS Code

Runs npx -y snyk on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp -- npx -y snyk
Add to Cursor

What the publisher says

From the Snyk repository's README, as published. We do not edit it. Read it on GitHub

Snyk Studio MCP

MCP (Model Context Protocol) is an open protocol that standardizes how applications share context with large language models.

MCP can provide AI systems with additional information needed to generate accurate and relevant responses for use cases where the AI systems do not have the context, by integrating the AI systems with tools and platforms that have specific capabilities. 

You can integrate Snyk MCP into MCP-supporting tools to provide Snyk security context.

Snyk is introducing an MCP server as part of the Snyk CLI. This allows MCP-enabled agentic tools to integrate Snyk security scanning capabilities directly, thus bridging the gap between security scanning and AI-assisted workflows.

In environments or applications that use MCP, you can use the snyk mcp CLI command to:

Trigger CLI security scans for code, dependencies, or configurations in your codebase in your current MCP context.

  • Invoke Snyk scans:\

Obtain Snyk security findings directly in your MCP-enabled tool or environment.

  • Retrieve results:\

 The Snyk MCP server supports integrating the following Snyk security tools into an AI system:

  • snykscascan (Open Source scan)
  • snykcodescan (Code scan)
  • snykiacscan (IaC scan)
  • snykcontainerscan (Container scan)
  • snyksbomscan (SBOM file scan)
  • snyksecretscan (Secret detection scan)
  • snyk_aibom (Create AIBOM)
  • snykpackagehealth_check (Package health and security assessment)
  • snyk_trust (Trust a given folder before running a scan)
  • snyk_auth (authentication)
  • snyk_logout (logout)
  • snykauthstatus (authentication status check)

Running snykscascan may execute third-party ecosystem tools (for example, Gradle or Maven) on your machine to fetch the project's dependency tree.

For more details, see the Snyk MCP installation, configuration and startup and Troubleshooting for the Snyk MCP server pages.

This repository is closed to public contributions.

Nothing above is checked by us. What we check is on the safety report.

Snyk: common questions

Is Snyk MCP server safe?
Mostly: it is graded B (71/100). Read the Snyk safety report
How do I install Snyk?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does Snyk need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Snyk maintained?
The last commit was 7 days ago (2026-09-21). The latest release is v1.1304.2.
What can I use instead of Snyk?
Servers from other publishers that do the same job: MobiLoop MCP server, WP HealthKit MCP server and CrowdStrike Falcon MCP Server. Compare all Snyk alternatives.

Alternatives to Snyk

Same job from other publishers: the closest match first, then the best rated.

All Snyk alternatives →
  • MobiLoop
    Guarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.
    A
  • WP HealthKit
    Security audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs.
    A
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • SSH Manager
    SSH server management for agents, with per-server read-only and allowlist security modes
    B
  • Wireshark
    Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
    A

More from snyk.io →