Back to Browse

Sbom Cyclonedx MCP Server

Developer ToolsUse Caution2.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...

About

Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...

Security Report

2.2
Use Caution2.2Critical Risk

This MCP server implements SBOM generation and validation with an authentication layer, but has several concerning security issues. The server makes unauthenticated HTTP requests to external metering endpoints without proper error handling, stores API keys in plaintext in local JSON files, and includes overly broad rate-limiting logic that may leak information. While the tools themselves are stubs and pose limited direct risk, the authentication middleware and metering infrastructure contain vulnerabilities that could be exploited. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

7 files analyzed Β· 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-csoai-org-sbom-cyclonedx-mcp": {
      "args": [
        "sbom-cyclonedx-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MCP Scorecard: 90/100

Sbom Cyclonedx MCP

MEOK AI Labs EU AI Act License PyPI

SBOM generation in CycloneDX 1

SBOM generation in CycloneDX 1.6 + SPDX 2.3. Required by EO 14028, NIS2, CRA. MIT


πŸš€ Quick Start

# Install via pip
pip install sbom_cyclonedx_mcp

# Or install via Smithery
npx -y @smithery/cli@latest install sbom-cyclonedx-mcp --client claude

✨ Features

  • MCP protocol compliant
  • Easy installation
  • Well-documented API
  • Production-ready
  • Active maintenance

πŸ“– Documentation

πŸ›‘οΈ Compliance

This MCP server is built with EU AI Act compliance built-in:

  • Free: 10 calls/day. No API key required.

  • Pro Β£79/mo: unlimited + signed attestations. Subscribe

  • Enterprise Β£1,499/mo: white-label + on-premise + SLA. hello@meok.ai

  • βœ… Article 9 β€” Risk Management System

  • βœ… Article 13 β€” Transparency & Instructions for Use

  • βœ… Article 15 β€” Bias Detection & Testing

  • βœ… Article 26 β€” FRIA Support (where applicable)

  • βœ… Article 50 β€” AI Content Watermarking (where applicable)

Need help getting compliant? Book a free 15-min diagnostic β†’

🏒 Enterprise

Need custom development, SLA guarantees, or white-label deployment?

  • Pro: $99/mo β€” Full MCP suite + EU AI Act tracking
  • Enterprise: $499/mo β€” Custom dev + SLA + Dedicated support

View Pricing β†’ | Contact Sales β†’

🀝 Part of the MEOK Ecosystem

This server is part of the MEOK AI Labs ecosystem β€” 300+ MCP servers for sovereign AI governance.

DomainPurpose
councilof.aiEU AI Act compliance marketplace
safetyof.aiAI safety & monitoring
meok.aiSovereign AI platform
cobolbridge.aiLegacy modernization

πŸ“œ License

MIT Β© CSOAI-ORG


  • βœ… MCP (Anthropic) β€” native
  • βœ… A2A (Google + Linux Foundation, absorbed IBM ACP Sept 2025)
  • βœ… IBM ACP β€” covered via A2A merge
  • ◐ Stripe ACP (Agentic Commerce Protocol) β€” Q3 bridge via agent-commerce-protocol-mcp
  • ◐ AP2 (Google Agent Payments) β€” partial via agent-commerce-payments-mcp
  • ◐ x402 (Coinbase HTTP 402) β€” partial via api.meok.ai gateway
  • β†’ OASF / AGNTCY (Cisco Outshift + Linux Foundation) β€” Q3 bridge
  • πŸ‘ ANP (Cisco Agent Network) β€” watch-list

Pricing options:

OptionPriceBest for
Self-host (this MCP)Β£0 β€” MITDevs
This MCP StarterΒ£29/moOne-MCP teams
This MCP ProΒ£79/moProduction + 24h SLA
Universal PAYGΒ£29/mo + Β£0.0002/callSpiky usage across many MCPs
Substrate bundle (this category)Β£99-Β£499/moA whole pack
MEOK UniverseΒ£1,499/moAll 47 MCPs, 500K calls

Each tier above the free self-host adds HMAC-signed attestations verifiable at verify.meok.ai. Linux Foundation governance on the A2A spine means EU regulated buyers can deploy without vendor-lock-in objections.

πŸ’Έ Try MEOK in 30 seconds β€” instant buy ladder

TierPriceWhat you getStripe
Smoke testΒ£1Signed sample MCP-Hardening report + Article 50 PDFhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Quick KitΒ£9EU AI Act Article 50 implementation guide (C2PA + EU-Icon)https://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t
Founder CallΒ£2930-min 1-on-1 with the founderhttps://buy.stripe.com/aFa7sNcgAdQS0ZT1Uc8k91t

Refundable. UK Stripe β€” VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report at https://meok.ai/verify.

Configuration

Add to your claude_desktop_config.json (Claude Desktop) or your MCP client config:

{
  "mcpServers": {
    "sbom-cyclonedx-mcp": {
      "command": "uvx",
      "args": ["sbom-cyclonedx-mcp"]
    }
  }
}

Or: pip install sbom-cyclonedx-mcp then run the sbom-cyclonedx-mcp command (stdio transport).

Examples

Once configured, ask your assistant, for example:

  • "Use generate_sbom_cyclonedx to …"
  • "Use generate_sbom_spdx to …"
  • "Use validate_sbom to …"

Reviews

No reviews yet

Be the first to review this server!