- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Documented (README)
- !No description
git clone https://github.com/trustlists/trustlists-pluginTools overview
<p align="center">
<img src="assets/logo.svg" alt="trustlists_" width="96" height="96" />
</p>
<h1 align="center">trustlists_ Plugin</h1>
<p align="center">
Public vendor trust center tools for Cursor and Claude Code.<br/>
Find trust centers, analyze SOC 2 reports, and request vendor access without leaving your editor.
</p>
<p align="center">
<a href="LICENSE"><img src="https://img.shields.io/badge/license-Apache%202.0-blue.svg" alt="License" /></a>
<a href="https://www.npmjs.com/package/@trustlists/mcp"><img src="https://img.shields.io/npm/v/@trustlists/mcp.svg" alt="npm" /></a>
</p>
## What it does
The trustlists_ plugin gives your AI assistant access to thousands of public company
trust center records, local SOC 2 analysis, and SafeBase/Vanta access requests.
### Tools
| Tool | What it does | Cost |
|------|--------------|------|
| `trustlists_search` | Search thousands of trust centers by name or domain | Free |
| `trustlists_lookup` | Look up a single vendor by exact domain | Free |
| `trustlists_browse` | Filter by platform, listed framework, or CSA STAR level | Free |
| `trustlists_audit_dependencies` | Audit `package.json`, `requirements.txt`, `go.mod`, etc. | Free |
| `trustlists_login` / `whoami` / `logout` | Device-code sign-in (`~/.trustlists/auth.json`) | Free |
| `trustlists_soc2_analyze` / `status` / `report` | Analyze local SOC 2 PDFs after a credit preview | Credits |
| `trustlists_requester_profile` | Identity used on vendor access forms | Free |
| `trustlists_access_request` / `status` / `continue` / `request_batch` | Request SafeBase or Vanta access (max 5 per batch) | Free (beta) |
The hosted HTTP endpoint stays the three public directory tools. Account tools
only run on the local stdio server (`npx -y @trustlists/mcp`).
### Skills
The plugin ships with skills your AI assistant uses automatically:
- **lookup-vendor** - Find a vendor's trust center and listed frameworks
- **audit-dependencies** - Map project dependencies to public trust center records
- **compliance-quick-check** - Check whether a directory record lists a requested framework
- **sign-in** - Connect a trustlists account with a device code
- **analyze-soc2** - Preview credits, then analyze a local SOC 2 PDF
- **request-trust-center-access** - Complete the requester profile and request access
## Example usage
In Cursor or Claude Code, just ask:
> "Look up Stripe's trust center"
> "Audit my package.json for vendor security"
> "Does Datadog's trust center list HIPAA information?"
The AI uses the plugin's tools to answer with current public trustlists data.
A directory record is a discovery aid, not an audit, certification, endorsement,
or security rating.
## Quick Install (Cursor, Claude Desktop, Claude Code)
Add this to your MCP config and restart:
```json
{
"mcpServers": {
"trustlists": {
"command": "npx",
"args": ["-y", "@trustlists/mcp"]
}
}
}
```
| App | Config location |
|-----|-----------------|
| **Cursor** | Settings → MCP → Edit config (or `~/.cursor/mcp.json`) |
| **Claude Desktop** | `~/Library/Application Support/Claude/claude_desktop_config.json` |
| **Claude Code** | `~/.claude/settings.json` or `.claude/settings.json` in your project |
**[Full installation guide →](docs/INSTALL.md)** (includes troubleshooting)
## Pricing
The directory and audit tools are free and require no trustlists account. SOC 2
analysis and access requests use a device-code login on the local MCP.
- **Free MCP tools** - Search, lookup, browse, and dependency mapping
- **Signed-in MCP tools** - SOC 2 analysis (credits) and trust-center access requests
- **Companion** - The same account workflows in the browser at app.trustlists.org
Visit the [MCP overview](https://trustlists.org/mcp/) for setup and tool details,
or [trustlists.org](https://trustlists.org) for the full directory and Companion subscriptions.
## Development
```bash
# Install dependencies
npm install
# Build the MCP server
npm run build
# Test locally
npm run test:local
```
See [docs/development.md](docs/development.md) for the full development guide.
## License
Apache 2.0. See [LICENSE](LICENSE) and [NOTICE](NOTICE).
## Links
- [trustlists directory](https://trustlists.org)
- [trustlists Companion](https://app.trustlists.org)
- [Issues](https://github.com/trustlists/trustlists-plugin/issues)
What people ask about trustlists-plugin
What is trustlists/trustlists-plugin?
+
trustlists/trustlists-plugin is tools for the Claude AI ecosystem with 0 GitHub stars.
How do I install trustlists-plugin?
+
You can install trustlists-plugin by cloning the repository (https://github.com/trustlists/trustlists-plugin) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is trustlists/trustlists-plugin safe to use?
+
Our security agent has analyzed trustlists/trustlists-plugin and assigned a Trust Score of 77/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains trustlists/trustlists-plugin?
+
trustlists/trustlists-plugin is maintained by trustlists. The last recorded GitHub activity is dated 2026-10-03, with 7 open issues.
Are there alternatives to trustlists-plugin?
+
Yes. On ClaudeWave you can browse similar tools at /categories/tools, sorted by popularity or recent activity.
Deploy trustlists-plugin to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/trustlists-trustlists-plugin)<a href="https://claudewave.com/repo/trustlists-trustlists-plugin"><img src="https://claudewave.com/api/badge/trustlists-trustlists-plugin" alt="Featured on ClaudeWave: trustlists/trustlists-plugin" width="320" height="64" /></a>More Tools
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
An AI skill that provides design intelligence for building professional UI/UX across multiple platforms.
🪨 why use many token when few token do trick. Viral skill + proxy for coding agents that cuts 65% of tokens by talking like a caveman.
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
The fastest, litest AI Gateway. Rust core with Python SDK. Call 100+ LLM APIs in OpenAI (or native) format with cost tracking, guardrails, load balancing, and logging [Bedrock, Azure, OpenAI, Anthropic, OpenAI, VertexAI, vLLM, Nvidia NIM]
Use Claude Code, Codex, VSCode, Pi, and OpenCode (and 6 other harnesses) for free (1.3B+ free tokens) from your terminal, app, IDE, or phone, and now from the browser with native browser sessions (multi-harness + multi-model) like OpenClaw (voice supported + ToS friendly)