Developer · Local MCP server

Secobserve MCP

MCP server for SecObserve: triage findings, import scan reports and SBOMs, generate VEX.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.nh4ttruong/secobserve-mcp
Version
1.0.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
PyPI, OCI image (Docker)
Published
2026-09-21
Updated
2026-09-21
Publisher
nh4ttruong (GitHub)
Repository
github.com/nh4ttruong/secobserve-mcp
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
PyPIsecobserve-mcp1.0.0stdioSECOBSERVE_BASE_URL (required), SECOBSERVE_API_TOKEN (required, secret), SECOBSERVE_READ_ONLY, SECOBSERVE_ALLOW_DELETE
OCI image (Docker)runtime: dockerghcr.io/nh4ttruong/secobserve-mcp:1.0.0—stdioSECOBSERVE_BASE_URL (required), SECOBSERVE_API_TOKEN (required, secret), SECOBSERVE_READ_ONLY, SECOBSERVE_ALLOW_DELETE

How to connect Secobserve MCP

Secobserve MCP runs locally from a Python package published to PyPI: secobserve-mcp version 1.0.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Python; clients usually start it with uvx (from uv) or after pip install — the usual command is uvx secobserve-mcp. It reads these environment variables: SECOBSERVE_BASE_URL (required), SECOBSERVE_API_TOKEN (required, secret), SECOBSERVE_READ_ONLY and SECOBSERVE_ALLOW_DELETE; set them in the client's configuration for this server.

Secobserve MCP runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/nh4ttruong/secobserve-mcp:1.0.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e SECOBSERVE_BASE_URL -e SECOBSERVE_API_TOKEN -e SECOBSERVE_READ_ONLY -e SECOBSERVE_ALLOW_DELETE ghcr.io/nh4ttruong/secobserve-mcp:1.0.0. It reads these environment variables: SECOBSERVE_BASE_URL (required), SECOBSERVE_API_TOKEN (required, secret), SECOBSERVE_READ_ONLY and SECOBSERVE_ALLOW_DELETE; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "secobserve-mcp": {
      "command": "uvx",
      "args": [
        "secobserve-mcp"
      ],
      "env": {
        "SECOBSERVE_BASE_URL": "<value>",
        "SECOBSERVE_API_TOKEN": "<secret>",
        "SECOBSERVE_READ_ONLY": "<value>",
        "SECOBSERVE_ALLOW_DELETE": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Sec Edgar MCPSEC EDGAR MCP server that provides access to the US public filings through the US SEC EDGAR API.Local · stdioPyPI: sec-edgar-mcp
secdim.comPersonalised developer security learning pathways from SecDim's challenges and courses.Remote · HTTPmcp.secdim.com
Secenv MCPCentralized secrets manager MCP server. Generate.env files, rotate keys, sync to GitHub Actions.Local · stdioMCP Bundle (.mcpb): chirag127/secenv-mcp/releases/download/v1.1.0/se
SecHelixEvidence-first security review of authorized repositories. Read-only, root-confined, no shell.Local · stdioPyPI: sechelix
Secop MCP ServerConsulta contratación pública de Colombia (SECOP I y II) desde datos.gov.co.Local · stdioPyPI: secop-mcp-server
Secret MCPLocal MCP server for isolated, evidence-backed GDWEB design analysis and web search.Local · stdionpm: secret-design-mcp
Secretguard MCPScans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.Local · stdioMCP Bundle (.mcpb): vladimirbakalov/secretguard-mcp/releases/downloa
Secrets Audit MCPDetects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.Local · stdioOCI image (Docker): ghcr.io/eltociear/secrets-audit-mcp:1.0.1