Trent MCP server
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
A97/100grade A
Adoption
Growing
9 stars
Reviews
Write oneNobody has reviewed Trent yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Trent tools
Tool list not cached yet. `describe` through the gateway fetches it live.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 180ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenancelast push 16 days ago15/15
- Maintainer identitynamespace and repository owner differ; GitHub account older than a year; website matches verified namespace8/10
Overall 97/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
claude mcp add --transport http trent https://mcp.trent.ai/mcp
Trent: common questions
- Is Trent MCP server safe?
- Yes, by our scan: it is graded A (97/100). Read the Trent safety report
- How do I install Trent?
- It runs remotely at mcp.trent.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Trent need an API key?
- No key to paste: it signs you in with OAuth when your client connects.
- Is Trent maintained?
- The last commit was 16 days ago (2026-09-03). The latest release is v0.1.0.
- Is Trent up?
- 100% of our last 2 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Trent?
- Servers from other publishers that do the same job: SecHelix MCP server, ScanLabsAI Security Scanner MCP server and Fedramp Oscal Ssp Lint MCP server. Compare all Trent alternatives.
Alternatives to Trent
Same job from other publishers: the closest match first, then the best rated.
- SecHelixEvidence-first security review of authorized repositories. Read-only, root-confined, no shell.not reviewedGrowingA
ScanLabsAI Security ScannerScan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixesnot reviewedNewB- Fedramp Oscal Ssp Lint16 checks on a system-security-plan JSON, in your editor, before a validator returns the packagenot reviewedNewA
- CISA Cybersecurity & ICS Advisories — buy per-query in-session (cisaalerts)CISA advisories & ICS alerts: new CVEs, remediation. Register in-session — free testnet funds.not reviewedNewC
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB