Snyk Code: Support for MCP Server Sources

New

Starting July 23, 2025, Snyk Code will be updated to recognize new application entry points within MCP (Model Context Protocol) server implementations.

The security analysis will now trace data from these MCP sources as it enters an application, expanding security coverage for agentic workflows. As a result of this expanded analysis, findings in affected projects may change.

This support covers the following key frameworks and libraries:

  • Java: Spring AI (org.springframework.ai)

  • JavaScript: FastMCP, modelcontextprotocol/typescript-sdk

  • Python: FastMCP, modelcontextprotocol/python-sdk, aiofiles

Headshot of Sebastian Roth

Sebastian Roth | Senior Product Manager

Tags: