Skip to content
mcp/skillhub

Securityscorecard MCP Server

by callmarcusio.github.CallMarcus/securityscorecard-mcpv2.0.0

Community-built, comprehensive MCP server for the SecurityScorecard API (unofficial).

0Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active5d ago

Install Securityscorecard MCP server

Install in Claude Code

claude mcp add securityscorecard -e SECURITY_SCORECARD_API_TOKEN='<security-scorecard-api-token>' -- npx -y @callmarcus/securityscorecard-mcp

Configuration

VariableRequiredSecretDescription
SECURITY_SCORECARD_API_TOKENyesyesSecurityScorecard API token (get one from your SecurityScorecard dashboard).
COMPANY_DOMAIN——Optional default company domain for queries (e.g. example.com).

Freshness

Active — last maintenance signal 5d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-04 · 5d ago · GitHub

  2. Latest release

    2026-10-04 · 5d ago · GitHub · v2.0.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-10-04 · 5d ago · official registry · v2.0.0

FAQ

›How do I install the Securityscorecard MCP server in Claude Code?

Run: claude mcp add securityscorecard -e SECURITY_SCORECARD_API_TOKEN='<security-scorecard-api-token>' -- npx -y @callmarcus/securityscorecard-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Securityscorecard require an API key?

Yes. It expects SECURITY_SCORECARD_API_TOKEN, of which 1 is a secret.

›Can I use Securityscorecard as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Securityscorecard in the official MCP registry?

Yes, as io.github.CallMarcus/securityscorecard-mcp.