nh4ttruong/secobserve-mcp
by Various
MCP server for SecObserve: triage vulnerability findings, manage products and rules, import scan reports and SBOMs, generate VEX documents
MCP
nh4ttruong/secobserve-mcp
Added 21 Sept 2026
Overview
MCP server for SecObserve that enables triage of vulnerability findings, management of products and rules, import of scan reports and SBOMs, and generation of VEX documents. Written in Python, it exposes these SecObserve operations through the Model Context Protocol for use by MCP-compatible clients.
Best for
Best for
Developers building MCP-based tooling that needs to interact with SecObserve for security workflows.
Use cases
- Automate vulnerability triage workflows in SecObserve via MCP
- Manage products and rules programmatically from an MCP client
- Import scan reports and SBOMs, and generate VEX documents
How to use
Install
uvx secobserve-mcp --help Tools exposed
secobserve_list_resourcessecobserve_describe_resourcesecobserve_call_actionsecobserve_assess_observationsecobserve_bulk_assess_observationssecobserve_approve_observation_logsecobserve_product_metricssecobserve_upload_filesecobserve_api_importsecobserve_trigger_scansecobserve_run_periodic_tasksecobserve_statussecobserve_vex_documenttriage-productdaily-changesweekly-changesdaily-reportweekly-reportmonthly-reportSECOBSERVE_BASE_URL
Tested with
Claude Code, VS Code
Notes
MCP server for SecObserve that enables triage of vulnerability findings, management of products and rules, import of scan reports and SBOMs, and generation of VEX documents. Written in Python, it exposes these SecObserve operations through the Model Context Protocol for use by MCP-compatible clients.
1 stars on GitHub. Last updated 2026-09-21. Licensed MIT.
Use cases
- Automate vulnerability triage workflows in SecObserve via MCP
- Manage products and rules programmatically from an MCP client
- Import scan reports and SBOMs, and generate VEX documents
Pros
- Covers core SecObserve operations in one MCP server
- Python-based, easy to extend or integrate
- Follows the MCP standard for interoperability
Cons
- Low star count suggests limited community adoption
- Early-stage project, likely minimal testing or documentation
- Requires a running SecObserve instance and MCP client setup
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- Covers core SecObserve operations in one MCP server
- Python-based, easy to extend or integrate
- Follows the MCP standard for interoperability
Cons
- Low star count suggests limited community adoption
- Early-stage project, likely minimal testing or documentation
- Requires a running SecObserve instance and MCP client setup
Pairs with
Other entries in the index that connect to this one. Click through to see the chain.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
