Snyk MCP Server
Snyk ships its MCP server inside the Snyk CLI rather than as a separate package — the snyk mcp command exposes Snyk's scanners to agentic tools, so a coding agent can scan the code it just wrote instead of deferring security to CI. It covers open-source dependency (SCA), static code, infrastructure-as-code and container scanning, plus SBOM and AIBOM generation and the auth and folder-trust steps those require. Available from CLI version 1.1296.2 in experimental mode.
Tools
snyk_aibom
Generate an AI bill of materials describing the AI models and dependencies a project uses.
snyk_auth
Authenticate the Snyk CLI so subsequent scans run against the correct account.
snyk_auth_status
Report whether the Snyk CLI is currently authenticated and which account it is using.
snyk_code_scan
Run Snyk's static application security testing over first-party source code.
snyk_container_scan
Scan a container image and its base layers for known operating-system and dependency vulnerabilities.
snyk_iac_scan
Scan infrastructure-as-code files such as Terraform and Kubernetes manifests for misconfigurations.
snyk_logout
Log the Snyk CLI out and clear the stored authentication credentials.
snyk_sbom_scan
Test an existing software bill of materials file for components with known vulnerabilities.
snyk_sca_scan
Scan a project's open-source dependencies for known vulnerabilities and license issues.
snyk_trust
Mark a folder as trusted, which Snyk requires before it will run a scan against it.
snyk_version
Return the installed Snyk CLI version, which gates whether MCP support is available.