Enterprise DNA Enterprise DNA
M MCP Servers Developer low

nh4ttruong/secobserve-mcp

by Various

MCP server for SecObserve: triage vulnerability findings, manage products and rules, import scan reports and SBOMs, generate VEX documents

MCP

nh4ttruong/secobserve-mcp

Added 21 Sept 2026

#appsec #devsecops #mcp #model-context-protocol #python #sbom #secobserve #vex

Overview

MCP server for SecObserve that enables triage of vulnerability findings, management of products and rules, import of scan reports and SBOMs, and generation of VEX documents. Written in Python, it exposes these SecObserve operations through the Model Context Protocol for use by MCP-compatible clients.

Best for

Best for
Developers building MCP-based tooling that needs to interact with SecObserve for security workflows.

Use cases

  • Automate vulnerability triage workflows in SecObserve via MCP
  • Manage products and rules programmatically from an MCP client
  • Import scan reports and SBOMs, and generate VEX documents

How to use

Install

uvx secobserve-mcp --help

Tools exposed

  • secobserve_list_resources
  • secobserve_describe_resource
  • secobserve_call_action
  • secobserve_assess_observation
  • secobserve_bulk_assess_observations
  • secobserve_approve_observation_log
  • secobserve_product_metrics
  • secobserve_upload_file
  • secobserve_api_import
  • secobserve_trigger_scan
  • secobserve_run_periodic_task
  • secobserve_status
  • secobserve_vex_document
  • triage-product
  • daily-changes
  • weekly-changes
  • daily-report
  • weekly-report
  • monthly-report
  • SECOBSERVE_BASE_URL

Tested with

Claude Code, VS Code

Notes

MCP server for SecObserve that enables triage of vulnerability findings, management of products and rules, import of scan reports and SBOMs, and generation of VEX documents. Written in Python, it exposes these SecObserve operations through the Model Context Protocol for use by MCP-compatible clients.

1 stars on GitHub. Last updated 2026-09-21. Licensed MIT.

Use cases

  • Automate vulnerability triage workflows in SecObserve via MCP
  • Manage products and rules programmatically from an MCP client
  • Import scan reports and SBOMs, and generate VEX documents

Pros

  • Covers core SecObserve operations in one MCP server
  • Python-based, easy to extend or integrate
  • Follows the MCP standard for interoperability

Cons

  • Low star count suggests limited community adoption
  • Early-stage project, likely minimal testing or documentation
  • Requires a running SecObserve instance and MCP client setup

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Covers core SecObserve operations in one MCP server
  • Python-based, easy to extend or integrate
  • Follows the MCP standard for interoperability

Cons

  • Low star count suggests limited community adoption
  • Early-stage project, likely minimal testing or documentation
  • Requires a running SecObserve instance and MCP client setup

Pairs with

Other entries in the index that connect to this one. Click through to see the chain.

Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks