supply-chain

5 servers · 52★ total

Offensive MCP server auditor: detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.

The dependency bloodhound for AI coding agents. Free, no API keys.

Security for AI agents & MCP — map how MCP servers, skills, and memory chain into exposure paths. Toxic-flow detection, cross-surface graph, drift & policy-as-code. Local-only, no telemetry.

Cryptographic trust infrastructure for MCP servers — signed manifests, TOFU pinning, two-gate enforcement, and the "npm audit" scanner.

90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, npm, PyPI, crates.io, RubyGems, NuGet, Packagist, Go, deps.dev, Scorecard, Rekor, ClearlyDefined, Repology, typosquatting detection