Use SBOM Dependency Risk Scorer with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Analyze SBOM files to quantify supply chain risk through dependency structure, package staleness, and vulnerability exposure.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 4 capabilities
The complete SBOM Dependency Risk Scorer capability set.
These are the exact actions your AI can choose when you ask it to work with SBOM Dependency Risk Scorer.
01-04
4 capabilities in this set.
Part of 4 available through SBOM Dependency Risk Scorer.
- 01
Analyze dependency structure
Analyzes the dependency tree structure of an SBOM
- 02
Evaluate package stalness
Evaluates how outdated packages are based on release dates
- 03
Tally vulnerability exposure
Counts known vulnerabilities in the SBOM
- 04
Calculate composite risk score
Calculates the final security risk score
Observed, not estimated
638ms average. Fast in production.
SBOM Dependency Risk Scorer is checked daily against the live service.
- Fastest day
- 533ms
- Slowest day
- 837ms
- 14-day trend
- Slowing+7%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 4 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of SBOM Dependency Risk Scorer, so you can see the experience inside your AI.
It does not authenticate your account with SBOM Dependency Risk Scorer. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
SBOM Dependency Risk Scorer Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — SBOM Dependency Risk Scorer capabilities are ready to use.
{
"mcpServers": {
"sbom-dependency-risk-scorer-mcp": {
"url": "https://edge.vinkius.com/vk_preview_KlPJrIwRzxzKDRHQ287k2q0iQyXI2BLIopz2ESTV/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions SBOM Dependency Risk Scorer owners ask.
- 01
What types of SBOM formats are supported?
The engine supports both SPDX and CycloneDX formats for analyzing dependency structures.
- 02
How is the final risk score calculated?
The calculate_composite_risk_score capability aggregates metrics from structural complexity, package staleness, and vulnerability counts to produce a normalized risk level.
- 03
Can I use this to find outdated packages?
Yes, by using the evaluate_package_stalness capability with a reference date, you can identify components that have not been updated recently.
Explore
More in Security
Dependency Impact Analyzer AI Connector
Analyzes the security, legal, and structural impact of adding or updating dependencies.
ViewFile Change Impact Assessor AI Connector
Quantifies the blast radius and risk of file modifications through deterministic dependency tracing.
ViewSensitive Data Exposure Detector AI Connector
Intercepts and redacts sensitive information from file reads and tool outputs.
ViewSafety Stock Calculator AI Connector
Calculate optimal safety stock levels using Square Root, Statistical, and Fixed Coverage methods.
View
Suggestions
Socket.dev (Dependency Security) AI Connector
Protect your software supply chain by scanning dependencies, checking package security scores, and monitoring
ViewRisk Matrix Calculator AI Connector
Quantify risk levels using configurable assessment matrices.
ViewVolatility Targeting Strategy AI Connector
A deterministic risk-management engine that adjusts position sizes to maintain constant portfolio volatility.
ViewContract Review Prover AI Connector
AI models summarize contracts instead of analyzing them. This tool forces clause-level rigor: score risk per c
View
