Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Open-source supply-chain security scanner that runs locally and offline. It matches known-malicious packages, extensions, plugins, providers, container images and CI actions in 15 ecosystems, with tested matchers ready for more (see Ecosystem Coverage), reading manifests and lockfiles at any depth of a repository, including the transitive dependencies a lockfile pins; and it analyses what you install for malware behavior: GlassWorm, Vidar, Shai-Hulud, fake AI tool repos, account takeovers and 350+ threat indicators in all. It generates CycloneDX 1.6 SBOMs with real dependency inventories, grades SLSA provenance (parses and structurally validates in-toto/DSSE attestations), and correlates findings into attack-chain incidents. Supports EU Cyber Resilience Act SBOM and component-documentation work, and NIS2 supply chain risk-management measures.

Scan a project. No account, no configuration, and the scan itself makes no network request:
It exits 1 on a high finding or a scan that could not examine everything, and
2 on a critical finding, so it can gate a script as it is. To add the historical
package catalog, run npx supply-chain-guard feed refresh with network access in
the directory you scan from. The catalog is cached there in .scg-cache and
belongs to the installed version, so refresh again after an upgrade.
Gate every pull request:
Let your AI coding agent check a package before it installs it (MCP):
Every release is published to npm from this repository's CI with a signed
SLSA provenance attestation,
and the Action installs that exact version. Each GitHub Release also carries
the tarball with that provenance as a Sigstore bundle (.sigstore.json). To check
one yourself:
Everything else, from output formats to policies, is further down: Quickstart, GitHub Action, For AI Coding Agents (MCP).
For a deep dive into how GlassWorm infiltrates the software supply chain and the detection techniques behind this tool, read the blog post: How GlassWorm Gets In and How We Locked It Out.
Package, extension, plugin and image identities are matched against the threat feed. This list is generated from the indicators that actually ship, so an ecosystem is only named as covered once there is something to match:
src/App/ is covered, and a lockfile's transitive dependencies are matched, not only direct ones.import()FILE_TOO_LARGE_SKIPPED (info severity, never affects exit codes) instead of being silently skipped - padding a payload past the limit no longer hides it from the report#!/bin/sh, #!/usr/bin/env node, python3, ruby, perl and others), and an extensionless file named like a git hook (pre-commit, pre-push, ...) is read as shell even without one, so hooks under scripts/hooks/ or .husky/ and bin/ launchers in a directory scan or an npm tarball are content-scanned. *.bats suites are read as bash and, like *.test.ts, count as test files, and Perl source is read as .pl/.pm too. A file with no extension, no shebang and no hook name is still not readnpm <pkg> mode, corroborates a package's claimed repository against the repo's own package.json and flags a repo borrowed from an unrelated popular project to inherit its stars/trust (conservative: monorepos, forks, related names, and unfetchable repos are not flagged)No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/supply-chain-guard)<a href="https://allmcps.com/mcp/supply-chain-guard"><img src="https://allmcps.com/api/badge/supply-chain-guard?style=directory" alt="Supply Chain Guard on AllMCPs" /></a>