Sign inSign up

trustsource/ts-mcp

By trustsource

•Updated 4 days ago

MCP-Sever to use TrustSource API through LLMs

Image
Security
Machine learning & AI
Developer tools
0

967

trustsource/ts-mcp repository overview

TrustSource

⁠TrustSource MCP Server

An MCP (Model Context Protocol)⁠ server that connects LLM agents like Claude to the TrustSource⁠ platform. Manage SBOMs, run compliance checks, track vulnerabilities, and handle risk management — all through natural language.

⁠Quick Start

docker run -i --rm \
  -e TS_API_KEY=your-api-key \
  trustsource/ts-mcp

The server speaks MCP over stdio and works with any MCP-compatible client.

⁠Configuration

VariableRequiredDefaultDescription
TS_API_KEYYes—TrustSource API key
TS_ACCESS_MODENoreadAccess tier: read, readwrite, or full
TS_API_BASE_URLNohttps://api.trustsource.io/v2API base URL
TS_LOG_LEVELNoinfoLog verbosity: debug, info, warn, error

⁠Client Setup (Claude Desktop)

{
  "mcpServers": {
    "trustsource": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "TS_API_KEY", "trustsource/ts-mcp"],
      "env": {
        "TS_API_KEY": "your-api-key"
      }
    }
  }
}

⁠Available Tools

16 domain-grouped tools covering the full TrustSource API v2:

ToolDescription
projectsManage projects, retrieve parts lists and SBOMs
modulesManage modules, retrieve parts lists and SBOMs
productsProduct lifecycle management
scansSubmit scans, import SBOMs (CycloneDX, SPDX)
reportsCompliance, vulnerability, license, and EOL reports
releasesPublished SBOMs, notice files, CSAF/VEX advisories
compliance-checkLicense and component compliance checks
approvalsCompliance approval workflows
vulnerabilitiesCVE/CWE lookup and search
risksRisk assessments and task tracking
psirtProduct Security Incident Response advisories
deepscanRepository deep scans
testsSARIF test result imports
companyCompany FOSS compliance settings
usersUser activity and API usage statistics
accountAPI key authorization status

⁠Access Modes

  • read (default) — list and view resources only
  • readwrite — create and update resources
  • full — all operations including delete, retire, and approve/reject

⁠Get Your API Key

  1. Sign in at app.trustsource.io⁠
  2. Navigate to Company Admin > Scanners & API
  3. Create a new API key

Free subscriptions are available — see trustsource.io/editions⁠ for details.

⁠Support

For questions, issues, or feedback reach out to [email protected]⁠.

⁠License

AGPL-3.0⁠

Tag summary

Content type

Image

Digest

sha256:362f6a008…

Size

61.8 MB

Last updated

4 days ago

docker pull trustsource/ts-mcp