Local supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Local-first vulnerability scanner for project dependencies, developer tools, and IDE extensions.
Uses multi-source intelligence (OSV, NVD, GHSA, Sonatype) with KEV/EPSS prioritization.
No API key required for default usage.
Public repo: https://github.com/DevInder1/supply-chain-scanner-public
Agents & MCP (Claude, Cursor, VS Code, Windsurf, Zed):
Pick whichever install path fits:
What you can do: docs/CAPABILITIES.md
Full guide: docs/INSTALL_AND_USE.md
Cross-platform (macOS / Linux / Windows): docs/CROSS_PLATFORM.md
(PyPI: tridentchain-security Β· npm: @tridentchain/security-cli)
| Profile | Description |
|---|---|
full (default) | Project + system + extensions. OSV + NVD without keys. |
quick | Faster project-focused scan. |
offline | Local advisory DB only, no network. |
| Power-user | Add GITHUB_TOKEN, NVD_API_KEY, optional SONATYPE_TOKEN for best coverage. |
No repo clone required if the pip package is installed:
See apps/desktop/README.md and docs/DISTRIBUTION_VERIFICATION.md.
One install, every agent: pip install "tridentchain-security>=0.1.2" tridentchain-mcp
| Guide | Description |
|---|---|
| Agent integrations | Claude Β· OpenAI Β· Cursor Β· VS Code Β· Windsurf Β· Zed Β· MCP Β· CLI |
| Capabilities | Everything you can do today |
| Architecture | MCP + unified tools design |
Phase 2 β Claude MCP: pip install tridentchain-mcp Β· Setup guide Β· Plugin
Phase 3 β OpenAI + Cursor: examples/openai/ Β· Cursor setup Β· .cursor/mcp.json.example
Phase 4 β VS Code (Anthropic MCP): Open repo β MCP ready Β· VS Code setup Β· ./scripts/vscode-mcp-install-link.sh Β· extension
Phase 5 β Validate: tridentchain-security --validate Β· MCP validate_after_patch Β· CAPABILITIES.md
Unified tool layer: from scanner.integrations import execute_tool, get_tool_definitions, to_openai_tools
Install & use: docs/INSTALL_AND_USE.md
Cross-platform: docs/CROSS_PLATFORM.md
CLI contract: docs/cli-contract.md
Publishing: docs/PUBLISHING.md
| Variable | Purpose |
|---|---|
NVD_API_KEY | Higher NVD rate limits |
GITHUB_TOKEN | GHSA advisories |
SONATYPE_TOKEN | Sonatype Guide advisories |
Set in .env or environment variables.
MIT β see LICENSE
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/tridentchain-security)<a href="https://allmcps.com/mcp/tridentchain-security"><img src="https://allmcps.com/api/badge/tridentchain-security?style=directory" alt="TridentChain Security on AllMCPs" /></a>