Server data from the Official MCP Registry
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...
About
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...
Security Report
This MCP server implements SBOM generation and validation with an authentication layer, but has several concerning security issues. The server makes unauthenticated HTTP requests to external metering endpoints without proper error handling, stores API keys in plaintext in local JSON files, and includes overly broad rate-limiting logic that may leak information. While the tools themselves are stubs and pose limited direct risk, the authentication middleware and metering infrastructure contain vulnerabilities that could be exploited. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.
7 files analyzed Β· 16 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-sbom-cyclonedx-mcp": {
"args": [
"sbom-cyclonedx-mcp"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
Sbom Cyclonedx MCP
SBOM generation in CycloneDX 1
SBOM generation in CycloneDX 1.6 + SPDX 2.3. Required by EO 14028, NIS2, CRA. MIT
π Quick Start
# Install via pip
pip install sbom_cyclonedx_mcp
# Or install via Smithery
npx -y @smithery/cli@latest install sbom-cyclonedx-mcp --client claude
β¨ Features
- MCP protocol compliant
- Easy installation
- Well-documented API
- Production-ready
- Active maintenance
π Documentation
π‘οΈ Compliance
This MCP server is built with EU AI Act compliance built-in:
-
Free: 10 calls/day. No API key required.
-
Pro Β£79/mo: unlimited + signed attestations. Subscribe
-
Enterprise Β£1,499/mo: white-label + on-premise + SLA. hello@meok.ai
-
β Article 9 β Risk Management System
-
β Article 13 β Transparency & Instructions for Use
-
β Article 15 β Bias Detection & Testing
-
β Article 26 β FRIA Support (where applicable)
-
β Article 50 β AI Content Watermarking (where applicable)
Need help getting compliant? Book a free 15-min diagnostic β
π’ Enterprise
Need custom development, SLA guarantees, or white-label deployment?
- Pro: $99/mo β Full MCP suite + EU AI Act tracking
- Enterprise: $499/mo β Custom dev + SLA + Dedicated support
View Pricing β | Contact Sales β
π€ Part of the MEOK Ecosystem
This server is part of the MEOK AI Labs ecosystem β 300+ MCP servers for sovereign AI governance.
| Domain | Purpose |
|---|---|
| councilof.ai | EU AI Act compliance marketplace |
| safetyof.ai | AI safety & monitoring |
| meok.ai | Sovereign AI platform |
| cobolbridge.ai | Legacy modernization |
π License
MIT Β© CSOAI-ORG
- β MCP (Anthropic) β native
- β A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
- β IBM ACP β covered via A2A merge
- β Stripe ACP (Agentic Commerce Protocol) β Q3 bridge via agent-commerce-protocol-mcp
- β AP2 (Google Agent Payments) β partial via agent-commerce-payments-mcp
- β x402 (Coinbase HTTP 402) β partial via api.meok.ai gateway
- β OASF / AGNTCY (Cisco Outshift + Linux Foundation) β Q3 bridge
- π ANP (Cisco Agent Network) β watch-list
Pricing options:
| Option | Price | Best for |
|---|---|---|
| Self-host (this MCP) | Β£0 β MIT | Devs |
| This MCP Starter | Β£29/mo | One-MCP teams |
| This MCP Pro | Β£79/mo | Production + 24h SLA |
| Universal PAYG | Β£29/mo + Β£0.0002/call | Spiky usage across many MCPs |
| Substrate bundle (this category) | Β£99-Β£499/mo | A whole pack |
| MEOK Universe | Β£1,499/mo | All 47 MCPs, 500K calls |
Each tier above the free self-host adds HMAC-signed attestations verifiable at
verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated
buyers can deploy without vendor-lock-in objections.
πΈ Try MEOK in 30 seconds β instant buy ladder
| Tier | Price | What you get | Stripe |
|---|---|---|---|
| Smoke test | Β£1 | Signed sample MCP-Hardening report + Article 50 PDF | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
| Quick Kit | Β£9 | EU AI Act Article 50 implementation guide (C2PA + EU-Icon) | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
| Founder Call | Β£29 | 30-min 1-on-1 with the founder | https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t |
Refundable. UK Stripe β VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.
Configuration
Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:
{
"mcpServers": {
"sbom-cyclonedx-mcp": {
"command": "uvx",
"args": ["sbom-cyclonedx-mcp"]
}
}
}
Or: pip install sbom-cyclonedx-mcp then run the sbom-cyclonedx-mcp command (stdio transport).
Examples
Once configured, ask your assistant, for example:
- "Use
generate_sbom_cyclonedxto β¦" - "Use
generate_sbom_spdxto β¦" - "Use
validate_sbomto β¦"
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol Β· Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno Β· Developer Tools
Toleno Network MCP Server β Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace Β· Developer Tools
Create, build, and publish Python MCP servers to PyPI β conversationally.
MarkItDown
Freeby Microsoft Β· Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace Β· Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace Β· Finance
Free stock data and market news for any MCP-compatible AI assistant.
