Server data from the Official MCP Registry
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Remote endpoints: streamable-http: https://mcp.sbomapp.com/mcp
Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.
Endpoint verified · Open access · No issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"io-github-mcpsbom-sbom-mcp": {
"url": "https://mcp.sbomapp.com/mcp"
}
}
}From the project's GitHub README.
SBOM MCP Server - SBOMApp MCP Server brings software supplychain security assistant inside VS Code. With a simple natural language prompt, developers can instantly generate SBOMs (SPDX/CycloneDX), scan for CVEs, Verify Licence Compliance, and get actionable remediation guidance.
No switching tools, no manual scripts, everything happens right inside your editor, keeping you fast, secure, and focused.

Endtoend visibility: Build complete SBOMs (including transitive deps) from local workspaces or Git repos, then attach them to builds and releases.
Actionable security: Run vulnerability scans, drill into CVE details, and get fix versions and upgrade paths.
License clarity: Identify copyleft and other risky licenses early with auditfriendly summaries.
Copilot + MCP native: Works naturally in Agent Mode, so prompts like “generate sbom”, “scan vulnerabilities”
Frictionless onboarding: Start with a 7day free trial or connect your enterprise server using secure tokens stored by VS Code.
Designed for securityminded engineering orgs: Whether you’re shipping regulated software, hardening your SDLC, or preparing for customer SBOM requests, SBOMApp MCP delivers the SBOM, CVE, and license insights your teams need
We don’t store your code, your SBOMs, your dependencies, or any project data — ever. Only your email (for free trial) and API token are stored securely. Everything else stays completely on your machine.
Connect to a remote SBOM MCP Server to perform software bill of materials analysis, vulnerability scanning, opensource license details and dependency management.
Ctrl+Shift+X or Cmd+Shift+X on Mac)Or install directly from the VS Code Marketplace
New users get a FREE 90-day trial with 100 Tokens - no credit card required!
Simple steps to Activate Trial!
prerequisites : Visual Studio Code should be Installed with langauage Models enabled.
Click on the SBOM MCP status bar!
Click on the start free trial option,
Click on th start free trial popup,
Enter your official email-id & click Enter,
After sucessful Registration, you will get the trial activation notification!
Reload the Window using the command "CTRL+SHIFT+P" or click "Command Palette" and Select "Developer:Reload Window" to Refresh the MCP Server!
| Feature | Trial |
|---|---|
| Validity | 90 days |
| Token Requests | 100 tokens |
| SBOM Generation | yes |
| Vulnerability Scanning | yes |
When your trial expires or tokens are exhausted, upgrade at: https://payment.sbomapp.com or https://sbomapp.com
If you have a license key from your administrator:
Ctrl+Shift+P → "SBOMApp: Configure Remote Server"https://mcp.sbomapp.com/mcpCtrl+Shift+P againMandatory step! Once credentials and connections are tested, Kindly restart the VS Code.
Once connected (green status bar shows ✓), you can ask GitHub Copilot:
Note: Ensure your project is imported in VS Code before using SBOMApp MCP.
"@sbomapp/help"
"@sbomapp Generate an SBOM for my current project or
Generate an SBOM for my current project".
"@sbomapp scan vulnerabilities" or "Check if lodash 4.17.0 has any security vulnerabilities"
| Command | Description |
|---|---|
SBOMApp: Start Free Trial | Register for a free 7-day trial |
SBOMApp: Check Trial Status | View remaining tokens and expiry |
SBOMApp: Check Token Usage | View detailed Token usage statistics |
SBOMApp: Configure Remote Server | Set up server URL and API key |
SBOMApp: Test Connection | Verify connection to the server |
SBOMApp: Show Available Tools | Browse available SBOM analysis tools |
SBOMApp: Disconnect | Disconnect from the server |
This extension provides the following settings:
| Setting | Description | Default |
|---|---|---|
sbomRemoteMcp.serverUrl | URL of the remote SBOM MCP Server | (empty) |
sbomRemoteMcp.apiKey | API key for authentication | (empty) |
sbomRemoteMcp.autoConnect | Auto-connect on VS Code startup | true |
sbomRemoteMcp.showStatusBar | Show status in status bar | true |
Once connected, you can use these SBOM analysis tools with GitHub Copilot:
| Tool | Description |
|---|---|
sbomapp_generateSbomFromWorkspace | Generate SBOM, scan vulnerabilities, analyze dependencies, and check licenses for your current project |
generate_sbom | Generate a complete SBOM with vulnerability report for your project |
scan_vulnerabilities | Scan your project for security vulnerabilities with CVE details |
analyze_dependencies | Analyze all dependencies — types, licenses, and risk assessment |
Tip: Just type "generate sbom", "scan vulnerabilities", or "analyze dependencies" in Copilot chat — the extension automatically analyzes your current project!
Try asking Copilot these questions:
SBOMApp: Start Free Trial/mcp)sbomRemoteMcp.showStatusBar is enabled in settingsCtrl+Shift+P → "Reload Window")✓ SBOM MCP [Trial: 450] SBOM MCP [Trial Expired]SBOMApp: Configure Remote Server to enter a new API keyBe the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.