Snyk, verificado

Servidor MCP de Snyk · Verificado

Scan code, dependencies, containers, IaC and secrets for vulnerabilities with Snyk from your AI assistant.

Se ejecuta en local (Se ejecuta en tu equipo: su página tiene el comando de instalación)Se ejecuta con npx

Instalar Snyk

Se ejecuta en tu equipo. Tu cliente lo inicia con este comando:

npx -y snyk@latest mcp -t stdio

Requiere Node.js en tu equipo. Los pasos de configuración de abajo muestran dónde va el comando en cada cliente.

Compartir este servidor

Abre esta página, con el comando de instalación y los pasos de configuración.

mcp.tc/i/snyk

Descripción

Snyk Studio is the MCP server built into the Snyk CLI. It lets an MCP-enabled assistant run Snyk scans on your local codebase and read the findings. Scans cover open source dependencies, source code, infrastructure as code, containers, SBOM files and secrets. It can also create an AIBOM and check the health of a package.

It runs locally over stdio with the command npx -y snyk@latest mcp -t stdio. You sign in to Snyk through the browser with snyk auth or the snyk_auth tool, or you set SNYK_TOKEN. The dependency scan may run ecosystem tools such as Gradle or Maven on your machine to read the dependency tree.

Qué puedes hacer

  • Scan open source dependencies for known vulnerabilities
  • Run static analysis on source code
  • Scan IaC files and container images
  • Scan SBOM files and detect secrets
  • Create an AIBOM for a project
  • Check the health and security of a package
  • Sign in, sign out and check auth status

Herramientas

Snyk solo muestra sus herramientas después de iniciar sesión, así que no podemos listarlas aquí. Tu cliente las muestra cuando te conectes.

Prompts de ejemplo

  • Scan this project's dependencies for vulnerabilities with Snyk.

  • Run a Snyk code scan on the current repository and list high severity issues.

  • Check my Terraform files for misconfigurations using Snyk IaC.

  • Is the package lodash healthy and safe to use?

Configuración

Todos los clientes inician Snyk en tu equipo con el mismo comando. Elige el tuyo; la página recuerda tu elección.

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio snyk -- npx -y snyk@latest mcp -t stdio
  1. Start Claude Code and type /mcp. snyk should show as connected.

Add --scope user to make it available in every project.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
  1. Save the file and restart Claude Desktop.

Needs Node.js on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}

Needs Node.js on your computer.

VS Code

Or from a terminal:

code --add-mcp '{"name":"snyk","type":"stdio","command":"npx","args":["-y","snyk@latest","mcp","-t","stdio"]}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "snyk": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}

Needs Node.js on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
  1. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add snyk -- npx -y snyk@latest mcp -t stdio

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.snyk]
command = "npx"
args = ["-y", "snyk@latest", "mcp", "-t", "stdio"]

Needs Node.js on your computer.

Gemini CLI

gemini mcp add snyk npx -- -y snyk@latest mcp -t stdio

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs Node.js on your computer.

Preguntas frecuentes

Can I paste mcp.tc/i/snyk into my MCP client?

No. Snyk runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is npx -y snyk@latest mcp -t stdio.

Does Snyk need an API key?

No. It doesn’t declare any keys or environment variables. It runs with your user account’s permissions, so check what its tools can reach.

Is Snyk a remote or a local server?

Local. Your client starts it as a process on your computer with npx -y snyk@latest mcp -t stdio, which needs Node.js.

What can Snyk do?

You can scan open source dependencies for known vulnerabilities, run static analysis on source code y scan IaC files and container images.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc’s robot read Snyk’s public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

Insertar

Muestra Snyk en un README o en tu web. Cada inserción enlaza a esta página, usa el comando de instalación del servidor y no instala cookies. Cómo funcionan las inserciones

Insignia para README

Vista previa de la insignia, claraVista previa de la insignia, oscura
Markdown
[![Snyk on mcp.tc](https://mcp.tc/i/snyk/badge.svg)](https://mcp.tc/i/snyk)
HTML
<a href="https://mcp.tc/i/snyk"><img src="https://mcp.tc/i/snyk/badge.svg" alt="Snyk on mcp.tc" height="20"></a>

Sigue el modo claro u oscuro de quien lee. Añade ?theme=light o ?theme=dark para fijarlo, o ?style=compact para mostrar el símbolo sin la palabra.

Tarjeta para web

HTML
<script src="https://mcp.tc/w/snyk.js" async></script>

La tarjeta aparece donde esté la etiqueta. Añade data-theme="dark" o data-size="compact" a la etiqueta para cambiarla. El archivo contiene todo lo que necesita, así que no hace otras solicitudes ni instala cookies.

iframe

HTML
<iframe src="https://mcp.tc/embed/snyk" title="Snyk on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

Úsalo en páginas que no permiten scripts. Añade ?theme=light o ?theme=dark a la dirección para fijar los colores.

JSON

La ficha como datos para tus propias páginas y herramientas: nombre, descripción corta, comando de instalación, herramientas y los enlaces «Add to». Cualquier web puede leerla (CORS abierto).

https://mcp.tc/i/snyk.json

Qué significa cada campo

mcp.tc no tiene relación con Snyk. Esta página se creó a partir de los metadatos públicos de Snyk, comprobados por última vez el 3 oct 2026, y un modelo de IA escribió la descripción, así que puede contener errores. Los nombres y marcas pertenecen a sus titulares. ¿Algo no cuadra? Reportar esta ficha.