# Trivy

**Canonical:** https://apis.io/providers/trivy/  
**Website:** https://trivy.dev/  
**APIs profiled:** 4

Trivy is a comprehensive and versatile open-source security scanner from Aqua Security that finds vulnerabilities, misconfigurations, secrets, and SBOM in containers, Kubernetes, code repositories, clouds, and more. Trivy runs as a CLI tool, in client/server mode with an HTTP API, and as a Kubernetes Operator (trivy-operator) that continuously scans clusters and generates security reports as native Kubernetes Custom Resources.

## Kin Score — 32.4 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 32.4).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 53.8 |
| Governance | 13.6 |
| Contract Governance | 13.6 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 46.7 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | na |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | na |
| Error Semantics | no |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | na |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (4)

- **Trivy Operator** — The Trivy Operator is a Kubernetes-native security toolkit that automatically scans clusters and generates security reports as Kubernetes Custom Resources. It defines 12 CRDs co...
- **Trivy CLI** — The primary interface for Trivy is its command-line tool, which scans container images, filesystems, Git repositories, Kubernetes clusters, virtual machine images, and SBOMs. Su...
- **Trivy Health API** — Server health and liveness checks
- **Trivy Server API** — Server metadata and version information

## MCP servers (1)

- **MCP Server**

## Agentic access (1)

- **Trivy Agentic Access** — 2 operations

## Security (2)

- **Trivy Authentication** — apiKey · 1 scheme
- **Trivy Domain Security** — TLSv1.3

## Plans (1)

- **Trivy Plans Pricing**

## Tags

Containers, Kubernetes, SBOM, Security, Vulnerability Scanning, Open-Source, DevSecOps, Cloud Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/trivy/). Scores are computed from the provider's own public artifacts under a published rubric.
