Server data from the Official MCP Registry
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...
This SBOM generation MCP server has a functional purpose but exhibits several concerning patterns around authentication, monetization logic, and code quality. While the core tools are stubs (reducing immediate risk), the authentication system relies on environment variables without clear validation, the rate-limiting and monetization logic is embedded in tool code, and there are subtle issues with auth middleware fallback behavior. The server lacks input validation on the query parameters and doesn't validate API keys cryptographically. These issues, combined with the overall code organization, warrant caution for production use. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
4 files analyzed ยท 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-sbom-cyclonedx-mcp": {
"args": [
"sbom-cyclonedx-mcp"
],
"command": "uvx"
}
}
}From the project's GitHub README.
SBOM generation in CycloneDX 1
SBOM generation in CycloneDX 1.6 + SPDX 2.3. Required by EO 14028, NIS2, CRA. MIT
# Install via pip
pip install sbom_cyclonedx_mcp
# Or install via Smithery
npx -y @smithery/cli@latest install sbom-cyclonedx-mcp --client claude
This MCP server is built with EU AI Act compliance built-in:
Free: 10 calls/day. No API key required.
Pro ยฃ79/mo: unlimited + signed attestations. Subscribe
Enterprise ยฃ1,499/mo: white-label + on-premise + SLA. hello@meok.ai
โ Article 9 โ Risk Management System
โ Article 13 โ Transparency & Instructions for Use
โ Article 15 โ Bias Detection & Testing
โ Article 26 โ FRIA Support (where applicable)
โ Article 50 โ AI Content Watermarking (where applicable)
Need help getting compliant? Book a free 15-min diagnostic โ
Need custom development, SLA guarantees, or white-label deployment?
View Pricing โ | Contact Sales โ
This server is part of the MEOK AI Labs ecosystem โ 300+ MCP servers for sovereign AI governance.
| Domain | Purpose |
|---|---|
| councilof.ai | EU AI Act compliance marketplace |
| safetyof.ai | AI safety & monitoring |
| meok.ai | Sovereign AI platform |
| cobolbridge.ai | Legacy modernization |
MIT ยฉ CSOAI-ORG
Pricing options:
| Option | Price | Best for |
|---|---|---|
| Self-host (this MCP) | ยฃ0 โ MIT | Devs |
| This MCP Starter | ยฃ29/mo | One-MCP teams |
| This MCP Pro | ยฃ79/mo | Production + 24h SLA |
| Universal PAYG | ยฃ29/mo + ยฃ0.0002/call | Spiky usage across many MCPs |
| Substrate bundle (this category) | ยฃ99-ยฃ499/mo | A whole pack |
| MEOK Universe | ยฃ1,499/mo | All 47 MCPs, 500K calls |
Each tier above the free self-host adds HMAC-signed attestations verifiable at
verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated
buyers can deploy without vendor-lock-in objections.
| Tier | Price | What you get | Stripe |
|---|---|---|---|
| Smoke test | ยฃ1 | Signed sample MCP-Hardening report + Article 50 PDF | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
| Quick Kit | ยฃ9 | EU AI Act Article 50 implementation guide (C2PA + EU-Icon) | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
| Founder Call | ยฃ29 | 30-min 1-on-1 with the founder | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
Refundable. UK Stripe โ VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.
Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:
{
"mcpServers": {
"sbom-cyclonedx-mcp": {
"command": "uvx",
"args": ["sbom-cyclonedx-mcp"]
}
}
}
Or: pip install sbom-cyclonedx-mcp then run the sbom-cyclonedx-mcp command (stdio transport).
Once configured, ask your assistant, for example:
generate_sbom_cyclonedx to โฆ"generate_sbom_spdx to โฆ"validate_sbom to โฆ"Be the first to review this server!
by Modelcontextprotocol ยท Developer Tools
Read, search, and manipulate Git repositories programmatically
by Modelcontextprotocol ยท Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno ยท Developer Tools
Toleno Network MCP Server โ Manage your Toleno mining account with Claude AI using natural language.