sonatype-guide

PackSecurity

sonatype-guide is a plugin that adds a Sonatype Guide MCP server for software supply chain intelligence and dependency security. It lets an AI agent analyze project dependencies for known vulnerabilities, recommend secure versions, and check component quality metrics.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have a project with dependencies you want analyzed.

What your AI can do with it

  • Analyze project dependencies for known vulnerabilities
  • Get secure version recommendations for components
  • Check component quality metrics
  • Provide software supply chain intelligence through the Sonatype Guide MCP server

Getting started

  1. Have a project with dependencies you want analyzed.
  2. Add the sonatype-guide plugin to your agent setup.
  3. Enable the Sonatype Guide MCP server it provides.
  4. Ask the agent to scan your dependencies for vulnerabilities and version recommendations.

Signals

GitHub stars
37k
Forks
4k
Last commit
Sep 2026

Questions

What does sonatype-guide do?
It is a plugin that provides a Sonatype Guide MCP server, letting an agent scan project dependencies for known vulnerabilities and suggest safer versions.
Does it check component quality?
Yes, it can check component quality metrics in addition to vulnerability analysis and version recommendations.
What kind of tool is it?
It is a plugin in the security category, built around a Sonatype Guide MCP server.
Advanced
Item type
plugin
Key
anthropics-claude-plugins-official-sonatype-guide
Source
github.com/anthropics/claude-plugins-official