Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI → MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE ↗ (opens in a new tab)
  • llms.txt ↗ (opens in a new tab)
  • Catalog JSON ↗ (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub ↗ (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. 💻 Developer Tools
  3. Supply Chain Guard
S
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Supply Chain Guard

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time — check back soon.
View Repository

Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON â–¾
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself — its README, its docs, or a verified owner. We haven’t found those for supply-chain-guard, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing Alternatives💻 More in Developer Tools

Documentation Overview

supply-chain-guard

Open-source supply-chain security scanner that runs locally and offline. It matches known-malicious packages, extensions, plugins, providers, container images and CI actions in 15 ecosystems, with tested matchers ready for more (see Ecosystem Coverage), reading manifests and lockfiles at any depth of a repository, including the transitive dependencies a lockfile pins; and it analyses what you install for malware behavior: GlassWorm, Vidar, Shai-Hulud, fake AI tool repos, account takeovers and 350+ threat indicators in all. It generates CycloneDX 1.6 SBOMs with real dependency inventories, grades SLSA provenance (parses and structurally validates in-toto/DSSE attestations), and correlates findings into attack-chain incidents. Supports EU Cyber Resilience Act SBOM and component-documentation work, and NIS2 supply chain risk-management measures.

npm version npm downloads Node.js TypeScript CI OpenSSF Scorecard OpenSSF Best Practices AAHP Verify AAHP conformant Last commit scanned by supply-chain-guard License

supply-chain-guard scanning a malicious npm package: risk gauges, GlassWorm incident correlation, and a remediation plan

Start in 30 seconds

Scan a project. No account, no configuration, and the scan itself makes no network request:

Terminal
npx supply-chain-guard scan .

It exits 1 on a high finding or a scan that could not examine everything, and 2 on a critical finding, so it can gate a script as it is. To add the historical package catalog, run npx supply-chain-guard feed refresh with network access in the directory you scan from. The catalog is cached there in .scg-cache and belongs to the installed version, so refresh again after an upgrade.

Gate every pull request:

yaml
- uses: actions/checkout@v4
- uses: homeofe/supply-chain-guard@v6.3.2

Let your AI coding agent check a package before it installs it (MCP):

Terminal
npm install -g supply-chain-guard
claude mcp add supply-chain-guard supply-chain-guard mcp

Every release is published to npm from this repository's CI with a signed SLSA provenance attestation, and the Action installs that exact version. Each GitHub Release also carries the tarball with that provenance as a Sigstore bundle (.sigstore.json). To check one yourself:

bash
gh attestation verify supply-chain-guard-X.Y.Z.tgz \
  --bundle supply-chain-guard-X.Y.Z.tgz.sigstore.json \
  --repo homeofe/supply-chain-guard --digest-alg sha512

Everything else, from output formats to policies, is further down: Quickstart, GitHub Action, For AI Coding Agents (MCP).

Contents

  • Background
  • What It Detects
  • Installation
  • Quickstart
  • Output Formats
  • CI Exit Code Control
  • Filtering
  • Internal Disclosure
  • Policy Configuration
  • Baseline Diffing
  • Example Output
  • Ecosystem Coverage
  • How It Compares
  • GitHub Action
  • For AI Coding Agents (MCP)
  • Live Threat Feed
  • Install Guard
  • Adding Custom Patterns
  • Architecture
  • EU Compliance (CRA / NIS2)
  • Show that you scan
  • Contributing
  • Changelog
  • License

Background

For a deep dive into how GlassWorm infiltrates the software supply chain and the detection techniques behind this tool, read the blog post: How GlassWorm Gets In and How We Locked It Out.

What It Detects

Known-Malicious Packages and Components

Package, extension, plugin and image identities are matched against the threat feed. This list is generated from the indicators that actually ship, so an ecosystem is only named as covered once there is something to match:

  • Known-malicious indicators ship for 15 ecosystems: npm, PyPI, RubyGems, Composer (PHP), NuGet (.NET), Cargo (Rust), Go modules, Maven / Gradle / SBT / Bazel, Dart / Flutter (pub), Terraform / OpenTofu providers, Container images, GitHub Actions, VS Code / Open VSX extensions, Browser extensions (Chrome, Edge, Firefox) and JetBrains plugins.
  • Homebrew has a tested matcher and ships an indicator, but is not counted: its one indicator (the compromised Trivy tap release 0.69.4) needs a version, and only the legacy Brewfile.lock.json records one; current Homebrew writes no lock file, so a Brewfile alone cannot match it.
  • Matchers are built and tested, but no malicious package is publicly known yet, for 8 more: Swift Package Manager, CocoaPods, Hex (Elixir / Erlang), CRAN (R), Conan (C / C++), Terraform / OpenTofu modules, Helm charts and Ansible Galaxy. They report the day an indicator is published, through the importer or a curated entry.
  • The files read per ecosystem are in Ecosystem Coverage.
  • Manifests and lockfiles are read wherever they sit in the tree, so a monorepo service or a .NET project in src/App/ is covered, and a lockfile's transitive dependencies are matched, not only direct ones.
  • A version pin fires only on the exact malicious release; a hijacked legitimate package is never blocked by name. Registry-specific identities stay separate (Marketplace vs Open VSX, Chrome vs Edge, public vs private registries), and a commit SHA or image digest matches under any repository name.

Malware Campaigns

  • GlassWorm campaign markers and Solana blockchain C2
  • Vidar/GhostSocks infostealers (April 2026 Claude Code leak campaign)
  • Shai-Hulud self-replicating npm worm
  • XZ Utils backdoor (CVE-2024-3094), SolarWinds SUNBURST, Codecov, ua-parser-js, coa/rc
  • Fake AI tool repos (Claude Code, Copilot, Cursor, ChatGPT, OpenClaw lures)

Code-Level Threats

  • Obfuscated execution: eval+atob, eval+Buffer.from, template literal eval, dynamic import()
  • Invisible Unicode, RTL override, SVG script injection, steganography
  • Shannon entropy analysis for encoded payloads
  • Proxy handler traps, WebAssembly from external sources
  • Scan-coverage transparency: files above the 5 MB content-scan limit are surfaced as FILE_TOO_LARGE_SKIPPED (info severity, never affects exit codes) instead of being silently skipped - padding a payload past the limit no longer hides it from the report
  • Executable scripts without an extension are read in the language their shebang names (#!/bin/sh, #!/usr/bin/env node, python3, ruby, perl and others), and an extensionless file named like a git hook (pre-commit, pre-push, ...) is read as shell even without one, so hooks under scripts/hooks/ or .husky/ and bin/ launchers in a directory scan or an npm tarball are content-scanned. *.bats suites are read as bash and, like *.test.ts, count as test files, and Perl source is read as .pl/.pm too. A file with no extension, no shebang and no hook name is still not read

Supply Chain Attacks

  • Install hook deep analysis (secret harvesting, download-exec chains, binary blobs)
  • Levenshtein-based typosquatting detection against top 100 npm packages with known-safe whitelist
  • Dependency confusion and namespace squatting
  • Starjacking: in npm <pkg> mode, corroborates a package's claimed repository against the repo's own package.json and flags a repo borrowed from an unrelated popular project to inherit its stars/trust (conservative: monorepos, forks, related names, and unfetchable repos are not flagged)
  • Known-bad version blocklist (axios, ua-parser-js, coa, rc, event-stream, node-ipc, colors, faker)
  • Publishing anomaly detection (maintainer changes, version gaps, script additions)

Read the full README →View source on GitHub →

Related MCP Servers

View all in Developer Tools View all alternatives
  • O
    Openapi MCP Server

    Connect any HTTP/REST API server using an Open API spec (v3)

    💻 Developer Tools3 views
    Compare vs Openapi MCP Server →
  • C
    Claude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    💻 Developer Tools8 views
    Compare vs Claude Task Master →
  • M
    MCP Server Docker

    Integrate with Docker to manage containers, images, volumes, and networks.

    💻 Developer Tools3 views
    Compare vs MCP Server Docker →
  • A
    Andrea9293 MCP

    Local-first document management and semantic search for AI coding agents

    💻 Developer Tools2 views
    Compare vs Andrea9293 MCP →

Reviews

No reviews yet — be the first to share how this listing worked for you.

Frequently Asked Questions about Supply Chain Guard

We don't have a confirmed install command for supply-chain-guard yet, so we don't publish a generated one — a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/homeofe/supply-chain-guard) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSupply Chain Guard AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/supply-chain-guard?style=directory)](https://allmcps.com/mcp/supply-chain-guard)
HTML Embed
<a href="https://allmcps.com/mcp/supply-chain-guard"><img src="https://allmcps.com/api/badge/supply-chain-guard?style=directory" alt="Supply Chain Guard on AllMCPs" /></a>

Technical Specs & Signals

Category💻Developer Tools
More technical detailsExpand â–¾
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
28Quality signal: Emerging · 28/100How this signal is calculated ▾
Server availabilityNot measured

Not scored for repo-hosted servers — we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools12/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data — not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

★ Featured
A

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server →

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website — proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it — no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in 💻 Developer Tools →Best MCP servers for Developers →Alternatives to Supply Chain Guard →Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients