MCP server intelligence profile

Grype MCP Server

Enables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol

Local OnlyOfficial distributionanchore
Awaiting current scanPypi · 0.4.0

The selected current version does not yet have completed public verification. Unknown does not mean clean or vulnerable.

1Distribution channel
PendingTool inventory
0Linked remote endpoints
AvailableVersion intelligence

Install and connect

Installation and connection instructions are shown only when supported by retained package, repository, or endpoint evidence.

Install grype-mcp from PyPI

Version 0.4.0 declares 1 executable entrypoint.

python -m pip install 'grype-mcp==0.4.0'
uvx --from 'grype-mcp==0.4.0' grype-mcp
MCP client configuration example
{
  "mcpServers": {
    "grype-mcp": {
      "command": "uvx",
      "args": [
        "--from",
        "grype-mcp==0.4.0",
        "grype-mcp"
      ]
    }
  }
}

Identity

Canonical sluggrype-mcp-server-0fc48f4bDeploymentLocal Only
Canonical packagepypi:grype-mcpRepositoryanchore/grype-mcp
First publishedAug 29, 2025Latest releaseAug 29, 2025
Last security verificationClassification confidence90%
PublicationPublishedOfficial distributionYes

Distributions

ChannelIdentifierCurrent versionVersionsSource
pypigrype-mcp0.4.01Repository

Current release

PackageVersionPublished / observedInventorySecurity scan
pypigrype-mcp0.4.0CurrentAug 29, 2025Not scanned
Enterprise protection

Continuously monitor this MCP for security risk

Independently scan the exact version your agents use, receive alerts when its risk changes, and investigate every finding with retained version evidence.

  • Independent exact-version security scans
  • Continuous release and vulnerability monitoring
  • Risk-change alerts with capability context
  • Historical evidence and API exports
Custom pricingContact salesTailored to your organization, integrations, data needs, and support requirements.

Current version evidence

Provenanceartifact_hash_verifiedSignature
MCP SDKpython_mcp_source_evidence Artifact SHA-25645bc16ac2a006ac090381f3326256dcd6c860c6173fffc4749e1200ce5525e6c
ScannerScan completed
Security rating20 / 100Methodologyversion-rating-1.0
Executable entrypoints
[
  "grype-mcp"
]
Rating reasons
[
  "security_policy_not_observed"
]

Best available protocol inventory

Tool inventory is pending. This does not mean the MCP exposes zero tools. Tools, resources, templates, and prompts appear here after the current version completes independent protocol inventory.

Remote endpoints

EndpointTransportAuthenticationHealthObserved
No verified remote endpoint is linked.

Grype MCP Server questions

How do I install Grype MCP Server?

Install the selected package version with: python -m pip install 'grype-mcp==0.4.0'

What tools does Grype MCP Server provide?

A current independently observed tool inventory is not available yet. This does not mean Grype MCP Server exposes zero tools.

Is Grype MCP Server secure?

The selected current version does not yet have completed public verification. Unknown does not mean clean or vulnerable.

Explore related MCP server guides

Curated product and capability guides containing this catalog record.

Official vs Community MCP Servers

Let’s talk about MCP security.

Share your details and our security team will contact you.