- Conduid
- Marketplace
- #supply-chain-security
MCP servers tagged supply-chain-security
26 live MCP servers tagged "supply-chain-security", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with supply-chain-security.
Nono
Sandbox any AI agent in seconds - zero setup, zero latency.
Heimdall
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
Bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
Poutine
poutine, a supply chain vulnerability scanner for build pipelines
Prismor
Runtime security for Agents. Blocks dangerous commands, prevent secret leaks, stop prompt injection, gate risky package installs and visibility and control over tool calls.
Brain0
The black box for AI-written code. Passive decision graph linking every commit to the agent prompts behind it: drift detection, DLP audit of what agents read, evidence-driven risk…
Veritensor
The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data Poisoning, PII, and Prompt Injections.…
Mcptrustchecker
MCP security scanner — offline, deterministic A–F Trust Score for Model Context Protocol servers. Detects tool poisoning, prompt injection & toxic flows.
Clawseccheck
🦞 Local, read-only security scanner for OpenClaw. Finds config, prompt-injection and supply-chain risks — A–F grade.
Cache Commander
Cache Commander — a TUI and MCP server to explore, audit, and clean developer cache directories. Scan for CVEs, find outdated packages, reclaim disk space. Supports pip, npm, Carg…
Vigile Scan
Security scanner for AI agent tools — detect tool poisoning, permission abuse, and supply chain attacks in MCP servers and agent skills
Transport Firewall
Fail-closed stdio firewall for risky local MCP JSON-RPC tool calls
Mcpaudit
Security scanner for your installed MCP servers. Finds shell-exec tools, plaintext secrets, and unpinned supply chains across Claude Desktop, Claude Code, Cursor, and Windsurf con…
Fabrica Star
Know what you're installing before you npx it. A security scanner for Model Context Protocol (MCP) servers and client configs.
Secure Code Skill
Install the secure-code security skills into a Claude Code project, and connect MCP servers (secure-code-mcp or any other).
Mcpie
Security scanner for MCP servers. Think `npm audit` for the Model Context Protocol.
Github Security MCP
GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control
Golf Scanner
Discover and audit MCP servers for security vulnerabilities across Claude Code, Cursor, VS Code, and more
AI Devops Actions
The CI/CD layer for AI-native development — 5 GitHub Actions for PR quality, cost tracking, MCP testing, supply chain security, and agent skill validation
VibeGuard
Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…
cuttalo/depscope
mcp`.
Sswp MCP
Deterministic software attestation for AI-augmented development — witness, probe, and seal any repo with SHA-256. Fleet registry across 131 VERITAS nodes. Agent-native, zero cloud.
Patient Zero
Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers…
Honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gat…
Pkgxray
Supply-chain security for AI agents, npm packages, and MCP servers. Analyze packages before you install them — zero-dep Node, runs locally, never executes untrusted code.
Mcpvessel
Cage untrusted MCP servers in containers, compose them into agents, and share them over any OCI registry. Signed, sandboxed, no Docker required.