1. Conduid
  2. Marketplace
  3. #supply-chain
Tag

MCP servers tagged supply-chain

15 live MCP servers tagged "supply-chain", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with supply-chain.

15
live servers
37
avg trust
1

Poutine

poutine, a supply chain vulnerability scanner for build pipelines

52
2

MCPScan

Security scanner for MCP (Model Context Protocol) servers configured in your IDE/agent clients — audits npm-sourced and remote MCP servers for supply-chain risk.

39
3

Security Scanner

55-tool MCP server for security scanning of MCP servers. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testi…

39
4

AI Trust

Trust verification CLI for AI packages — check MCP servers, A2A agents, and AI tools before you install

37
5

Decoy Scan

Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.

37
6

Mcpguard

Security scanner for MCP servers — detect tool poisoning, malicious code patterns, and supply-chain risks before your AI agents execute them.

37
7

Lock

npm ci for your MCP servers — integrity verification for AI coding tool packages

37
8

Toolprint

package-lock.json for MCP trust — scan MCP servers for tool poisoning, secret leaks, and silent tool rug-pulls, with a committed, reviewable lockfile.

37
9

Toolpin

A review gate and lockfile for MCP server installs: artifact integrity, tool-surface pinning, and a CI drift gate

37
10

Sealpin

A supply-chain and prompt-injection scanner for MCP (Model Context Protocol) servers.

37
11

Eslint Plugin MCP Security

ESLint security rules for MCP servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time

34
12

AI Surface

Find and govern the AI surfaces in your application code at PR time. Free, OSS, runs offline.

34
13

Agent Harness

Node.js TypeScript CLI for discovering, staging, activating, and wiring reusable AI-agent assets across VS Code/Copilot, OpenCode, Cursor, Zed, Claude Code, and Pi.

34
14

Pkgxray

Supply-chain security for AI agents, npm packages, and MCP servers. Analyze packages before you install them — zero-dep Node, runs locally, never executes untrusted code.

34
15

askalf/truecopy

mcp proxy exposes only pinned, unmodified tools from a live server.

34
← Previous Page 1 of 1 Next →