MCP-Sever to use TrustSource API through LLMs
967
An MCP (Model Context Protocol) server that connects LLM agents like Claude to the TrustSource platform. Manage SBOMs, run compliance checks, track vulnerabilities, and handle risk management — all through natural language.
docker run -i --rm \
-e TS_API_KEY=your-api-key \
trustsource/ts-mcp
The server speaks MCP over stdio and works with any MCP-compatible client.
| Variable | Required | Default | Description |
|---|---|---|---|
TS_API_KEY | Yes | — | TrustSource API key |
TS_ACCESS_MODE | No | read | Access tier: read, readwrite, or full |
TS_API_BASE_URL | No | https://api.trustsource.io/v2 | API base URL |
TS_LOG_LEVEL | No | info | Log verbosity: debug, info, warn, error |
{
"mcpServers": {
"trustsource": {
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "TS_API_KEY", "trustsource/ts-mcp"],
"env": {
"TS_API_KEY": "your-api-key"
}
}
}
}
16 domain-grouped tools covering the full TrustSource API v2:
| Tool | Description |
|---|---|
projects | Manage projects, retrieve parts lists and SBOMs |
modules | Manage modules, retrieve parts lists and SBOMs |
products | Product lifecycle management |
scans | Submit scans, import SBOMs (CycloneDX, SPDX) |
reports | Compliance, vulnerability, license, and EOL reports |
releases | Published SBOMs, notice files, CSAF/VEX advisories |
compliance-check | License and component compliance checks |
approvals | Compliance approval workflows |
vulnerabilities | CVE/CWE lookup and search |
risks | Risk assessments and task tracking |
psirt | Product Security Incident Response advisories |
deepscan | Repository deep scans |
tests | SARIF test result imports |
company | Company FOSS compliance settings |
users | User activity and API usage statistics |
account | API key authorization status |
read (default) — list and view resources onlyreadwrite — create and update resourcesfull — all operations including delete, retire, and approve/rejectFree subscriptions are available — see trustsource.io/editions for details.
For questions, issues, or feedback reach out to [email protected].
Content type
Image
Digest
sha256:362f6a008…
Size
61.8 MB
Last updated
4 days ago
docker pull trustsource/ts-mcp