supply-chain-security
24 servers · 535★ total
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
Security scanner for AI agent tool definitions
🛡️ The security firewall for AI agent tools & MCP servers (Claude, GPT-5.6, Gemini 3.7, Antigravity, Cursor, Codex, Hermes). Catch command injection, secret theft & toxic flows in <50ms. 100% offline Rust SAST + 1-click auto-fix + SARIF.
Multi-engine security scanner for AI agents, MCP servers & plugins — 13 engines, one report.
GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control
Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Open-source package registry for MCP (Model Context Protocol) servers with built-in security scanning, trust scoring (L1-L4), and CLI. Every bundle verified across 25 supply-chain controls.
Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Discover and audit MCP servers for security vulnerabilities across Claude Code, Cursor, VS Code, and more
Runtime security proxy for MCP: lockfile enforcement, drift detection, artifact pinning, Sigstore/Ed25519 signing, CEL policy, OpenTelemetry tracing. Works with Claude Desktop, LangChain, AutoGen, CrewAI.
Belay is an open-source, local-first security layer for AI coding agents (Claude Code, Codex, Cursor, OpenClaw, Hermes Agent and MCP) that blocks dangerous commands, secret leaks, and prompt injection at the tool-call boundary in under 100ms — no LLM in the decision path by default, no cloud, no phone-home.
Generate a local MVP, then catch hollow tests before review. Free, receipt-backed proof for AI-assisted code.
Sunglasses for AI agents. Protection layer + neighborhood watch.
Security scanner for Model Context Protocol servers. Catch tool poisoning, prompt injection, and supply-chain attacks before your AI agent runs them.
Cage untrusted MCP servers in containers, compose them into agents, and share them over any OCI registry. Signed, sandboxed, no Docker required.
Deterministic MCP Security Architecture. FrozenNamespace as Root of Trust for Model Context Protocol tool verification
Day-zero supply-chain checker for npm + PyPI, as a local MCP server for AI coding agents. Calls check_package before installs to surface contextual anomalies.
One MCP stdio endpoint for a whole toolchain — GitHub, GitLab, cloud, mail, browser and research tools — with capability-gated dispatch, a machine-checked ABI, and cartridges fetched on demand from boj-server-cartridges. Zero runtime dependencies.
90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, npm, PyPI, crates.io, RubyGems, NuGet, Packagist, Go, deps.dev, Scorecard, Rekor, ClearlyDefined, Repology, typosquatting detection
MCP server for AI security intelligence. Check any MCP server for supply-chain threats before installing -- from Claude, Cursor, or Windsurf.