SBOM Dependency Risk Scorer Connector for AI agents.
4 live capabilities
Turn complex software bills of materials into prioritized security risk scores.
Waiting for input…
Why people use SBOM Dependency Risk Scorer
SBOM Dependency Risk Scorer for Software Supply Chain Audits
This Connector changes the game. Instead of clicking through tabs and spreadsheets, you can have your AI client process the file and immediately tell you which components are the biggest headaches. You get a clear risk score and a list of specific packages to fix first.
What Vinkius changes
You turn a messy list of software components into a prioritized security to-do list.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 6,100+ Connectors
- Real-world use case 01
Prioritizing a massive security backlog
A security engineer finds a 500-line SBOM and needs to know where to start.
- Real-world use case 02
Checking the impact of a new library
A developer wants to know if adding a new library is safe.
- Real-world use case 03
Generating a compliance summary
A compliance team needs a high-level risk summary for a report.
Complete set · 4capabilities
The complete SBOM Dependency Risk Scorer capability set.
These are the exact actions your AI can choose when you ask it to work with SBOM Dependency Risk Scorer.
01—04
4 capabilities in this set.
Part of 4 available through SBOM Dependency Risk Scorer.
- 01 Capability
Evaluate package stalness
Evaluates how outdated packages are based on release dates
- 02 Capability
Tally vulnerability exposure
Scans the SBOM to count every known CVE associated with your current dependencies. This provides a clear count of your total vulnerability surface area.
- 03 Capability
Analyze dependency structure
Maps out the depth and complexity of your software's dependency tree. It helps you see how many nested libraries are being pulled into your project.
- 04 Capability
Calculate composite risk score
Produces a single, actionable score that summarizes the overall risk of the SBOM. This gives you a high-level view of your security posture.
Set up in minutes
One URL. Then ask SBOM Dependency Risk Scorer to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use SBOM Dependency Risk Scorer from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it SBOM Dependency Risk Scorer, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable SBOM Dependency Risk Scorer for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the SBOM Dependency Risk Scorer URL.
- Step 03
Save and start
Save the connection and enable SBOM Dependency Risk Scorer in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"sbom-dependency-risk-scorer": {
"url": "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using SBOM Dependency Risk Scorer
Open Agent mode in chat and ask: "Using SBOM Dependency Risk Scorer, help me...". 4 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"sbom-dependency-risk-scorer": {
"url": "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using SBOM Dependency Risk Scorer
Ask Copilot: "Using SBOM Dependency Risk Scorer, help me...". 4 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"sbom-dependency-risk-scorer": {
"url": "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using SBOM Dependency Risk Scorer
Open Cascade and ask: "Using SBOM Dependency Risk Scorer, help me...". 4 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"sbom-dependency-risk-scorer": {
"url": "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using SBOM Dependency Risk Scorer
Ask Cline: "Using SBOM Dependency Risk Scorer, help me...". 4 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add sbom-dependency-risk-scorer --transport http "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using SBOM Dependency Risk Scorer
Ask Claude: "Using SBOM Dependency Risk Scorer, show me...". 4 tools are ready
Where the request belongs
Work SBOM Dependency Risk Scorer can move forward.
This is for security engineers and DevSecOps leads who are drowning in dependency hell. It's for the person tasked with proving that the software they're shipping isn't a ticking time bomb of outdated libraries.
Security Engineer
Uses this to audit third-party libraries and find the highest-risk entries during a sprint.
DevSecOps Lead
Integrates risk scoring into the CI/CD pipeline to block builds with high composite risk scores.
Compliance Officer
Uses the risk scores to generate reports for SOC2 or other supply chain security audits.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsLicense Compatibility Checker
Audit software licenses and check compatibility between dependencies.
Prompt Injection Shield Prover
LLMs cannot distinguish system instructions from user input. This capability forces 5-layer injection defense analysis: intent isolation, privilege containment, indirect vector scanning, output sanitization, and scope enforcement. OWASP LLM Top 10 #1 compliance.
Security Audit Prover
An AI agent committed a Stripe API key to git, built SQL queries with string concatenation, and deployed an admin endpoint with no authentication. all in 4 minutes. The key was scraped from GitHub within 90 seconds. This capability forces input sanitization validation, secret management auditing, authentication enforcement, injection prevention, and dependency supply chain checks against OWASP Top 10.
Semantic Version Compatibility Checker
Verify if a target version satisfies semver constraints and identify breaking changes.
Socket.dev (Dependency Security)
Protect your software supply chain by scanning dependencies, checking package security scores, and monitoring threat feeds directly from your AI agent.
Google Deps.dev Security Hacker
Transform your AI into a Senior DevSecOps Engineer. Instantly audit any open-source package, hunt for hidden supply-chain threats in dependency trees, and analyze full GitHub repositories using Google's deps.dev API. No authentication required.
Bring your own AI
Change the model, client or framework. Keep SBOM Dependency Risk Scorer connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about SBOM Dependency Risk Scorer.
The practical details behind the request, access and result.
What does the SBOM Dependency Risk Scorer actually do?
It turns raw software bill of materials into a prioritized security report. It identifies which libraries are outdated, counts their vulnerabilities, and gives you a score to help you decide what to fix first.
Can it handle different types of SBOM files?
Yes, it supports both SPDX and CycloneDX formats. You can provide either type of file and the capability will parse the data to perform its risk analysis.
How does it determine what is risky?
It looks at three main factors: how many known vulnerabilities (CVEs) a package has, how long it has been since its last update, and how complex the dependency tree is.
Is this for real-time monitoring?
No, this is for static file analysis. It is designed to help you audit and score SBOM files rather than monitoring live network traffic or production servers.
How does this help with software supply chain security?
It helps you move from reactive to proactive security. By identifying the highest-risk components first, your team can allocate resources more effectively to patch the most dangerous parts of your software stack.
Can I use this for SOC2 compliance?
Yes, it's a great capability for compliance audits. It provides a clear, quantifiable way to demonstrate that you are monitoring and managing risks within your software supply chain.
What types of SBOM formats are supported?
The engine supports both SPDX and CycloneDX formats for analyzing dependency structures.
How is the final risk score calculated?
The calculate_composite_risk_score capability aggregates metrics from structural complexity, package staleness, and vulnerability counts to produce a normalized risk level.
Can I use this to find outdated packages?
Yes, by using the evaluate_package_stalness capability with a reference date, you can identify components that have not been updated recently.
One connection away
Give your agent a direct line to SBOM Dependency Risk Scorer.
Connect SBOM Dependency Risk Scorer once. Keep it beside 6,100+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available