1. Conduid
  2. Marketplace
  3. #supply-chain-security
Tag

MCP servers tagged supply-chain-security

26 live MCP servers tagged "supply-chain-security", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with supply-chain-security.

26
live servers
42
avg trust
662
most stars
1

Nono

always-further

Sandbox any AI agent in seconds - zero setup, zero latency.

★ 662updated 6 months agoApache-2.0
87
2

Heimdall

delta0-inc

Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.

★ 30updated 7 months agoMIT
64
3

Bumblebee

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.

64
4

Poutine

poutine, a supply chain vulnerability scanner for build pipelines

52
5

Prismor

Runtime security for Agents. Blocks dangerous commands, prevent secret leaks, stop prompt injection, gate risky package installs and visibility and control over tool calls.

52
6

Brain0

The black box for AI-written code. Passive decision graph linking every commit to the agent prompts behind it: drift detection, DLP audit of what agents read, evidence-driven risk…

52
7

Veritensor

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data Poisoning, PII, and Prompt Injections.…

44
8

Mcptrustchecker

MCP security scanner — offline, deterministic A–F Trust Score for Model Context Protocol servers. Detects tool poisoning, prompt injection & toxic flows.

44
9

Clawseccheck

🦞 Local, read-only security scanner for OpenClaw. Finds config, prompt-injection and supply-chain risks — A–F grade.

44
10

Cache Commander

Cache Commander — a TUI and MCP server to explore, audit, and clean developer cache directories. Scan for CVEs, find outdated packages, reclaim disk space. Supports pip, npm, Carg…

39
11

Vigile Scan

Security scanner for AI agent tools — detect tool poisoning, permission abuse, and supply chain attacks in MCP servers and agent skills

37
12

Transport Firewall

Fail-closed stdio firewall for risky local MCP JSON-RPC tool calls

37
13

Mcpaudit

Security scanner for your installed MCP servers. Finds shell-exec tools, plaintext secrets, and unpinned supply chains across Claude Desktop, Claude Code, Cursor, and Windsurf con…

37
14

Fabrica Star

Know what you're installing before you npx it. A security scanner for Model Context Protocol (MCP) servers and client configs.

37
15

Secure Code Skill

Install the secure-code security skills into a Claude Code project, and connect MCP servers (secure-code-mcp or any other).

37
16

Mcpie

Security scanner for MCP servers. Think `npm audit` for the Model Context Protocol.

37
17

Github Security MCP

GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control

34
18

Golf Scanner

Discover and audit MCP servers for security vulnerabilities across Claude Code, Cursor, VS Code, and more

34
19

AI Devops Actions

The CI/CD layer for AI-native development — 5 GitHub Actions for PR quality, cost tracking, MCP testing, supply chain security, and agent skill validation

34
20

VibeGuard

Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…

34
21

cuttalo/depscope

mcp`.

34
22

Sswp MCP

Deterministic software attestation for AI-augmented development — witness, probe, and seal any repo with SHA-256. Fleet registry across 131 VERITAS nodes. Agent-native, zero cloud.

34
23

Patient Zero

Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers…

34
24

Honeybadger

Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gat…

34
25

Pkgxray

Supply-chain security for AI agents, npm packages, and MCP servers. Analyze packages before you install them — zero-dep Node, runs locally, never executes untrusted code.

34
26

Mcpvessel

Cage untrusted MCP servers in containers, compose them into agents, and share them over any OCI registry. Signed, sandboxed, no Docker required.

34
← Previous Page 1 of 1 Next →