Snyk MCP Server
Snyk MCP Server is an MCP server published by Snyk, verified on MCP revision 2025-11-25; support for the current revision (2026-07-28) is not yet confirmed. It is the first-party server from Snyk. Last verified 2026-08-25.
Does Snyk MCP Server support the current MCP specification (2026-07-28)?
Not yet confirmed. Snyk MCP Server is verified on revision 2025-11-25; we have not confirmed support for the current revision (2026-07-28) as of 2026-08-25.
Is Snyk MCP Server a first-party (official) MCP server?
Yes. Snyk MCP Server is the first-party MCP server published by Snyk (last verified 2026-08-25).
How do I connect to Snyk MCP Server?
Snyk MCP Server is available via the package npm:snyk, the official MCP Registry under io.snyk/mcp, the source repository at https://github.com/snyk/studio-mcp. Authentication: none. Transports: stdio.
Does Snyk MCP Server support MCP revision 2025-11-25?
Yes. Snyk MCP Server supports MCP revision 2025-11-25 (checked 2026-08-25).
When were Snyk MCP Server's facts last verified?
2026-08-25. Each fact on this page links to the sources used to verify it.
Snyk's MCP server is not a standalone package: it ships inside the Snyk
CLI and is invoked with the snyk mcp command. The README's framing is
that it "bridges the gap between security scanning and AI-assisted
workflows", letting an agentic tool trigger Snyk scans and read the
findings in place. The exposed tools cover open-source (snyk_sca_scan),
code (snyk_code_scan), IaC (snyk_iac_scan), container
(snyk_container_scan), and SBOM (snyk_sbom_scan) scanning, plus an
experimental secret-detection tool.
The registry record is arranged accordingly: its package is the snyk
npm CLI, and the version string (1.1304.2) follows the CLI's own
numbering rather than a separate MCP-server version. The development
repository is snyk/studio-mcp, a Go module in the GitHub-verified snyk
organization, which grounds the first-party authority.
No surface names a supported MCP specification revision; spec_status
is unknown.
Which MCP spec revisions does Snyk MCP Server support?
Snyk MCP Server has 1 verified spec-support record. Each row lists the revision, the verified status, the evidence URL, and the date that fact was last checked.
| Spec revision | Status | Last checked | Evidence |
|---|---|---|---|
| MCP 2025-11-25 | Supported | Source |
How widely adopted is Snyk MCP Server?
Ranked #25 in The MCP 500 with Adoption Index 67.17 (snapshot , methodology v1).
| Measurement | Value | Source |
|---|---|---|
| Official MCP Registry | yes | API · |
| Docker MCP Catalog | no | API · |
| npm downloads (weekly) | 515,671 | API · |
| GitHub stars | 55 | API · |
| GitHub forks | 16 | API · |
| Last push | 2026-08-19T15:55:54Z | API · |
| Repository archived | no | API · |
Repository and package signals for Snyk MCP Server
Measured directly from the source registries, not asserted from a document. Each figure carries the date it was read; none of it affects the verified spec status above.
Repository as of
- Created
- Open issues
- 1
- Primary language
- Go
- License (repository)
- Apache-2.0
- Continuous integration
- Present
- Tests
- None detected
- Security policy
- Present
Package (npm) as of
- Latest version
1.1306.4- Last published
- First published
- Releases
- 2066
- License (package)
- Apache-2.0
- Maintainers
- 1
- Direct dependencies
- 2
- Unpacked size
- 50.3 MB
- Registry signature
- Signed
- Build provenance
- No attestation
How was this verified, and what are the sources?
Verified · method: repo-source
· confidence 0.85 (Good).
- Official MCP Registry record io.snyk/mcp version 1.1304.2 (published 2026-05-06) - npm package snyk (the Snyk CLI), stdio transport, repository snyk/studio-mcp; the io.snyk namespace is domain-verified - accessed
- snyk/studio-mcp README - "Snyk is introducing an MCP server as part of the Snyk CLI. This allows MCP-enabled agentic tools to integrate Snyk security scanning capabilities directly"; run via the snyk mcp CLI command; tools include snyk_sca_scan, snyk_code_scan, snyk_iac_scan, snyk_container_scan, snyk_sbom_scan, and an experimental snyk_secret_scan; the repository is a Go module (go.mod) - accessed
- Staleness re-verification 2026-08-18 - official registry record io.snyk/mcp is at v1.1304.2 (published 2026-05-06, status active) and ships inside the npm snyk CLI package, no remote endpoints listed; snyk/studio-mcp is not archived and was pushed 2026-08-07 - accessed
- snyk/studio-mcp, internal/mcp/mcp_spec_conformance_test.go - "These tests verify compliance with the Model Context Protocol specification: - Version 2025-11-25 ... - Version 2025-06-18", with individual tests citing 2025-11-25 spec sections - accessed
- snyk/studio-mcp repository - the MCP server shipped inside the Snyk CLI as the snyk mcp subcommand; latest release v1.15.4 (2026-08-19); go.mod depends on github.com/mark3labs/mcp-go v0.31.0 - accessed