💻

Snyk MCP Server (snyk-mcp-rest)

Updated June 2026⚠ ArchivedTrust grade E25/100

The Snyk MCP Server (snyk-mcp-rest), built by Axel Springer, provides a TypeScript MCP server for Snyk security scanning built and maintained by engineering at Axel Springer, the German media company, that unifies two complementary tool sets in one server. It is no longer maintained and best for Coding & Dev.

by Axel Springer

This repository is archived

GitHub reports the repository below as archived, so it takes no further commits, issues or pull requests — but the published package has not been unpublished, so git clone https://github.com/axelspringer/snyk-mcp-rest.git && cd snyk-mcp-rest && npm install && npm run prepare still installs and runs. Read the section below before you build on it: where a maintained replacement exists, it is named there.

About

A TypeScript MCP server for Snyk security scanning built and maintained by engineering at Axel Springer, the German media company, that unifies two complementary tool sets in one server. The first set proxies the Snyk CLI directly, exposing snyk_test (dependency vulnerability testing), snyk_code_test (static application security analysis), snyk_container_test (container image scanning), snyk_iac_test (infrastructure-as-code scanning), snyk_monitor (continuous project monitoring registration), snyk_sbom_test (software bill-of-materials generation and testing), plus snyk_send_feedback, snyk_trust, and snyk_version as native CLI passthroughs. The second set is custom-built against the official Snyk REST API for management and querying workloads the CLI doesn’t cover well: snyk_rest_find_projects (search projects by name), snyk_rest_get_issues and snyk_rest_get_issue (retrieve and drill into vulnerability issues), and snyk_rest_get_repo_issues (aggregate issues across every project tied to a repository). The REST client itself is auto-generated from Snyk’s official OpenAPI specification for full type safety, giving AI assistants both deep scanning power and efficient dashboard-style querying from a single install. Requires a SNYK_API_KEY and the Snyk CLI installed locally for the proxy tools; install by cloning the repo and running npm install && npm run prepare (generates the API client, then compiles). MIT licensed, actively pushed as of February 2026.

E
At risk25/100
low confidence · 1 measured signal

Grade E (25/100, at risk) from 1 measured signal, based on repository evidence. Only one signal stands behind it, so treat the grade as provisional.

What was measured

  • Repository maintenance0/100 · weight 20

    The repository is archived by its owner, so it is by definition no longer maintained.

  • Source verification15/100 · weight 25

    The repository resolves, but its owner has archived it. Archived means read-only: no fixes, no releases, no response to issues.

  • Provenance65/100 · weight 10

    Community-built. That is not a mark against it — most of the ecosystem is community-built — but there is no vendor accountable for keeping it working.

  • Listing ↔ repository match100/100 · weight 5

    The listing name lines up with the linked repository axelspringer/snyk-mcp-rest.

What could not be measured

These contributed nothing to the score — not a penalty, not a zero. They are why the confidence reads the way it does.

  • Live MCP handshakeunknown

    No remote endpoint to handshake — this server installs and runs locally over stdio, so there is nothing to probe from the outside.

  • Measured uptimeunknown

    No probe history recorded for this server yet.

  • Tool-schema stabilityunknown

    Drift is a difference between two successive checks, and this server has none recorded.

Installation

source
git clone https://github.com/axelspringer/snyk-mcp-rest.git && cd snyk-mcp-rest && npm install && npm run prepare

Frequently Asked Questions

What is Snyk MCP Server (snyk-mcp-rest)?
Snyk MCP Server (snyk-mcp-rest) is an MCP server built by Axel Springer. A TypeScript MCP server for Snyk security scanning built and maintained by engineering at Axel Springer, the German media company, that unifies two complementary tool sets in one server. The first set proxies the Snyk CLI directly, exposing snyk_test (dependency vulnerability testing), snyk_code_test (static application security analysis), snyk_container_test (container image scanning), snyk_iac_test (infrastructure-as-code scanning), snyk_monitor (continuous project monitoring registration), snyk_sbom_test (software bill-of-materials generation and testing), plus snyk_send_feedback, snyk_trust, and snyk_version as native CLI passthroughs. The second set is custom-built against the official Snyk REST API for management and querying workloads the CLI doesn’t cover well: snyk_rest_find_projects (search projects by name), snyk_rest_get_issues and snyk_rest_get_issue (retrieve and drill into vulnerability issues), and snyk_rest_get_repo_issues (aggregate issues across every project tied to a repository). The REST client itself is auto-generated from Snyk’s official OpenAPI specification for full type safety, giving AI assistants both deep scanning power and efficient dashboard-style querying from a single install. Requires a SNYK_API_KEY and the Snyk CLI installed locally for the proxy tools; install by cloning the repo and running npm install && npm run prepare (generates the API client, then compiles). MIT licensed, actively pushed as of February 2026.
Who built Snyk MCP Server (snyk-mcp-rest)?
Snyk MCP Server (snyk-mcp-rest) was built by Axel Springer.
Is Snyk MCP Server (snyk-mcp-rest) free?
Yes, Snyk MCP Server (snyk-mcp-rest) has a free option. This MCP server is free and open-source. Check the GitHub repository for details.
How do I install Snyk MCP Server (snyk-mcp-rest)?
Install Snyk MCP Server (snyk-mcp-rest) with source: git clone https://github.com/axelspringer/snyk-mcp-rest.git && cd snyk-mcp-rest && npm install && npm run prepare. Note that its repository is archived and no longer maintained — the package is still published, so this command succeeds, but the project takes no further fixes.
What does Snyk MCP Server (snyk-mcp-rest) integrate with?
Snyk MCP Server (snyk-mcp-rest) integrates with Claude Desktop, Cursor, VS Code.

Repo Health

Maintained

Local/stdio install — runs on your machine, so there is no remote endpoint to verify live. Trust signal below is from the source repo.

Last commit
6mo ago
Install
source

Quick Info

Install Type
source
Author
Axel Springer
Categories
2
Integrations
3

Related Servers

💻

Everything

Reference/test server with prompts, resources, and tools. Perfect for testing MCP implementations.

Local
💻

Git

Tools to read, search, and manipulate Git repositories. Full Git operations support.

Local
🤖

Sequential Thinking MCP Server

a single structured-reasoning tool that lets a model plan, revise and branch its own chain of thought instead of answering in one shot. Published by Anthropic as part of the official modelcontextprotocol/servers monorepo (89,000+ stars, actively maintained), it exposes exactly one tool — sequential_thinking — and that tool is the whole product. Each call carries a `thought` string plus bookkeeping fields: `thoughtNumber`, `totalThoughts`, and `nextThoughtNeeded`, which the model flips to false when it is done. The interesting fields are the optional ones. `isRevision` and `revisesThought` let the model go back and correct an earlier step rather than plowing ahead on a bad assumption; `branchFromThought` and `branchId` let it fork into an alternative line of reasoning and carry both forward; `needsMoreThoughts` lets it extend past its own original estimate when a problem turns out to be deeper than it looked. In practice you never call the tool by hand. You connect the server to an MCP host and ask a question that deserves more than one pass — plan a PostgreSQL 14 to 16 migration and revise if downtime exceeds five minutes, work out why a deploy only fails in production, compare three architectures and branch when an assumption breaks. You can tell it is working when the host inspector shows repeated sequential_thinking calls with a rising `thoughtNumber` rather than a single response. Install with `npx -y @modelcontextprotocol/server-sequential-thinking` — note the hyphenated package name, which differs from both the `sequentialthinking` directory in the repo and the Docker image `mcp/sequentialthinking`, a mismatch that breaks a lot of copied configs. A Docker image is published alongside the npm package, and the README carries one-click VS Code install buttons for both transports. Set `DISABLE_THOUGHT_LOGGING=true` if you do not want every thought written to the server log.

Local
💻

21st.dev Magic

Create crafted UI components inspired by the best 21st.dev design engineers.

Local
💻

GitHub MCP Server

authenticated access to the whole GitHub platform — repositories, files, branches, issues, pull requests, Actions runs, security alerts, discussions and notifications — from Claude, Cursor, VS Code, Copilot CLI and any other MCP host. There is no npm package for this server, and that trips up most people who try to install it: `@github/mcp-server` is not published to the npm registry, so any `npx` line you find for it will fail. GitHub ships it three other ways. The easiest is the hosted remote server at https://api.githubcopilot.com/mcp/, which needs no install at all — point an HTTP-transport MCP client at that URL and log in with OAuth (VS Code 1.101+, Claude Desktop, Claude Code, Cursor and Windsurf all support this). The second is the official Docker image ghcr.io/github/github-mcp-server, which is what the copy-paste command on this page runs; on github.com it now performs a browser-based OAuth login on first use and keeps the token in memory only, which is why the published Docker configs map a fixed loopback callback port (-p 127.0.0.1:8085:8085 with GITHUB_OAUTH_CALLBACK_PORT=8085) so the container can receive the callback. Prefer a token? Set GITHUB_PERSONAL_ACCESS_TOKEN instead — it takes precedence over OAuth, and the minimum useful scopes are repo, read:org and read:packages. The third is the native Go binary from the repository's releases, which needs no fixed port for the OAuth flow. GitHub Enterprise Server has no hosted option: use the local server with --gh-host or GITHUB_HOST set to your instance (include the https:// scheme — it defaults to http://, which GHES rejects). Toolsets can be narrowed with GITHUB_TOOLSETS, and an insiders channel is available at /mcp/insiders or via the X-MCP-Insiders header.

Auth required📘

Sponsored

Better Stack

Free Plan

Get alerted when your APIs, browser tests, payment pipelines, or MCP server dependencies go down. Used by 100K+ developers.

Start monitoring free →