- Conduid
- Marketplace
- #supply-chain
MCP servers tagged supply-chain
15 live MCP servers tagged "supply-chain", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with supply-chain.
Poutine
poutine, a supply chain vulnerability scanner for build pipelines
MCPScan
Security scanner for MCP (Model Context Protocol) servers configured in your IDE/agent clients — audits npm-sourced and remote MCP servers for supply-chain risk.
Security Scanner
55-tool MCP server for security scanning of MCP servers. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testi…
AI Trust
Trust verification CLI for AI packages — check MCP servers, A2A agents, and AI tools before you install
Decoy Scan
Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.
Mcpguard
Security scanner for MCP servers — detect tool poisoning, malicious code patterns, and supply-chain risks before your AI agents execute them.
Lock
npm ci for your MCP servers — integrity verification for AI coding tool packages
Toolprint
package-lock.json for MCP trust — scan MCP servers for tool poisoning, secret leaks, and silent tool rug-pulls, with a committed, reviewable lockfile.
Toolpin
A review gate and lockfile for MCP server installs: artifact integrity, tool-surface pinning, and a CI drift gate
Sealpin
A supply-chain and prompt-injection scanner for MCP (Model Context Protocol) servers.
Eslint Plugin MCP Security
ESLint security rules for MCP servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time
AI Surface
Find and govern the AI surfaces in your application code at PR time. Free, OSS, runs offline.
Agent Harness
Node.js TypeScript CLI for discovering, staging, activating, and wiring reusable AI-agent assets across VS Code/Copilot, OpenCode, Cursor, Zed, Claude Code, and Pi.
Pkgxray
Supply-chain security for AI agents, npm packages, and MCP servers. Analyze packages before you install them — zero-dep Node, runs locally, never executes untrusted code.
askalf/truecopy
mcp proxy exposes only pinned, unmodified tools from a live server.