trustlists Plugin
MCP serverDev toolsLets your agent find vendor trust centers, review SOC 2 reports, and request access to them.
Unavailable. This server has no hosted endpoint yet, so Ahel can't serve it.
Add to setup to save this item as a reference. Ahel cannot run it, and signing in will not install it.
About this server
Find public vendor trust centers, analyze SOC 2 reports, and request trust-center access.
Getting started
- Save this item in Your setup as a reference.
- Read the source or reference documentation for its setup requirements. Saving it here does not connect it to your AI.
- Check this page for availability before trying to install it through Ahel.
From the project's README
As published by trustlists/trustlists-plugin in README.md.
What it does
The trustlists_ plugin gives your AI assistant access to thousands of public company trust center records, local SOC 2 analysis, and SafeBase/Vanta access requests.
Tools
| Tool | What it does | Cost |
|---|---|---|
trustlists_search | Search thousands of trust centers by name or domain | Free |
trustlists_lookup | Look up a single vendor by exact domain | Free |
trustlists_browse | Filter by platform, listed framework, or CSA STAR level | Free |
trustlists_audit_dependencies | Audit package.json, requirements.txt, go.mod, etc. | Free |
trustlists_login / whoami / logout | Device-code sign-in (~/.trustlists/auth.json) | Free |
trustlists_soc2_analyze / status / report | Analyze local SOC 2 PDFs after a credit preview | Credits |
trustlists_requester_profile | Identity used on vendor access forms | Free |
trustlists_access_request / status / continue / request_batch | Request SafeBase or Vanta access (max 5 per batch) | Free (beta) |
Hosted endpoint (ChatGPT and other remote clients)
https://mcp.trustlists.org/mcp serves the same tools over Streamable HTTP after
an OAuth sign-in with a trustlists account (Google or Microsoft). Connecting the
app replaces trustlists_login and trustlists_logout. Because a hosted server
cannot read your disk, the dependency audit takes pasted manifest text, and SOC 2
PDFs are uploaded in the trustlists app via trustlists_soc2_upload.
Skills
The plugin ships with skills your AI assistant uses automatically:
- lookup-vendor - Find a vendor's trust center and listed frameworks
- audit-dependencies - Map project dependencies to public trust center records
- compliance-quick-check - Check whether a directory record lists a requested framework
- sign-in - Connect a trustlists account with a device code
- analyze-soc2 - Preview credits, then analyze a local SOC 2 PDF
- request-trust-center-access - Complete the requester profile and request access
Example usage
In Cursor or Claude Code, just ask:
"Look up Stripe's trust center"
"Audit my package.json for vendor security"
"Does Datadog's trust center list HIPAA information?"
The AI uses the plugin's tools to answer with current public trustlists data. A directory record is a discovery aid, not an audit, certification, endorsement, or security rating.
Quick Install (Cursor, Claude Desktop, Claude Code)
Add this to your MCP config and restart:
{
"mcpServers": {
"trustlists": {
"command": "npx",
"args": ["-y", "@trustlists/mcp"]
}
}
}
| App | Config location |
|---|---|
| Cursor | Settings → MCP → Edit config (or ~/.cursor/mcp.json) |
| Claude Desktop | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Code | ~/.claude/settings.json or .claude/settings.json in your project |
Full installation guide → (includes troubleshooting)
Pricing
The directory and audit tools are free and require no trustlists account. SOC 2 analysis and access requests use a device-code login on the local MCP.
- Free MCP tools - Search, lookup, browse, and dependency mapping
- Signed-in MCP tools - SOC 2 analysis (credits) and trust-center access requests
- Companion - The same account workflows in the browser at app.trustlists.org
Visit the MCP overview for setup and tool details, or trustlists.org for the full directory and Companion subscriptions.
Development
# Install dependencies
npm install
# Build the MCP server
npm run build
# Test locally
npm run test:local
See docs/development.md for the full development guide.
License
Apache 2.0. See LICENSE and NOTICE.
Links
Signals
- Last commit
- Oct 2026
- Weekly_downloads
- 33 weekly_downloads
Advanced
- Delivery
- trustlists MCP server → your Ahel connector (mcp.ahel.ai) → your AI.
- Item type
- mcp-server
- Key
io-github-trustlists-mcp- Source
- github.com/trustlists/trustlists-plugin
github.com/trustlists/trustlists-plugin