About this integration
MCP server for SecObserve: triage findings, manage products, import scan reports and SBOMs.
- Transport
- stdio
- Authentication
- api-key
- Initial setup
- credentials
- Runtime
- unattended
- Evidence
- documented
- Version
- 0.1.2
- Package
- secobserve-mcp
- Last compatibility test
- Not independently tested
Connect your agent
secobserve-mcpPublisher README and pyproject manifest were reviewed from pinned captures. The package and SecObserve API were not executed. This server can perform writes and destructive operations; use least-privilege product tokens and the documented read-only/delete guards. Qualification does not verify SecObserve permissions or background-job outcomes.
Capabilities: Browse and triage vulnerability observations, Import scan reports, SBOMs, and VEX, Trigger scans and background jobs, Generate VEX documents
Connected profiles
Additional details
io.github.nh4ttruong/secobserve-mcp
Source ↗ · Checked 2026-09-170.1.2
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17pypi
Source ↗ · Checked 2026-09-17SECOBSERVE_BASE_URL, SECOBSERVE_API_TOKEN
Source ↗ · Checked 2026-09-17secobserve-mcp
Source ↗ · Checked 2026-09-190.2.2
Source ↗ · Checked 2026-09-19Publisher documentation provides a stdio client configuration with a fixed SecObserve base URL and API token. Once configured, the server exposes read, write, import, scan, and background-task tools without documenting a per-call client authorization flow; SecObserve's own assessment approval workflow and server-side permissions still apply.
Source ↗ · Checked 2026-09-19The recommended credential is a SecObserve user or product API token passed as SECOBSERVE_API_TOKEN; SECOBSERVE_JWT is documented as an alternative. Token scope and SecObserve permissions remain authoritative.
Source ↗ · Checked 2026-09-19The reviewed client configuration launches uvx secobserve-mcp as a local MCP process with SECOBSERVE_BASE_URL and SECOBSERVE_API_TOKEN. Publisher documentation states that stdio is the default transport; its separate HTTP deployment is not the connection qualified here.
Source ↗ · Checked 2026-09-19Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-19