Local supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Local-first vulnerability scanner for project dependencies, developer tools, and IDE extensions.
Uses multi-source intelligence (OSV, NVD, GHSA, Sonatype) with KEV/EPSS prioritization.
No API key required for default usage.
Public repo: https://github.com/DevInder1/supply-chain-scanner-public
Agents & MCP (Claude, Cursor, VS Code, Windsurf, Zed):
Pick whichever install path fits:
What you can do: docs/CAPABILITIES.md
Full guide: docs/INSTALL_AND_USE.md
Cross-platform (macOS / Linux / Windows): docs/CROSS_PLATFORM.md
(PyPI: tridentchain-security Β· npm: @tridentchain/security-cli)
| Profile | Description |
|---|---|
full (default) | Project + system + extensions. OSV + NVD without keys. |
quick | Faster project-focused scan. |
offline | Local advisory DB only, no network. |
| Power-user | Add GITHUB_TOKEN, NVD_API_KEY, optional SONATYPE_TOKEN for best coverage. |
No repo clone required if the pip package is installed:
See apps/desktop/README.md and docs/DISTRIBUTION_VERIFICATION.md.
One install, every agent: pip install "tridentchain-security>=0.1.2" tridentchain-mcp
| Guide | Description |
|---|---|
| Agent integrations | Claude Β· OpenAI Β· Cursor Β· VS Code Β· Windsurf Β· Zed Β· MCP Β· CLI |
| Capabilities | Everything you can do today |
| Architecture | MCP + unified tools design |
Phase 2 β Claude MCP: pip install tridentchain-mcp Β· Setup guide Β· Plugin
Phase 3 β OpenAI + Cursor: examples/openai/ Β· Cursor setup Β· .cursor/mcp.json.example
Phase 4 β VS Code (Anthropic MCP): Open repo β MCP ready Β· VS Code setup Β· ./scripts/vscode-mcp-install-link.sh Β· extension
Phase 5 β Validate: tridentchain-security --validate Β· MCP validate_after_patch Β· CAPABILITIES.md
Unified tool layer: from scanner.integrations import execute_tool, get_tool_definitions, to_openai_tools
Install & use: docs/INSTALL_AND_USE.md
Cross-platform: docs/CROSS_PLATFORM.md
CLI contract: docs/cli-contract.md
Publishing: docs/PUBLISHING.md
| Variable | Purpose |
|---|---|
NVD_API_KEY | Higher NVD rate limits |
GITHUB_TOKEN | GHSA advisories |
SONATYPE_TOKEN | Sonatype Guide advisories |
Set in .env or environment variables.
MIT β see LICENSE
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/tridentchain-security)<a href="https://allmcps.com/mcp/tridentchain-security"><img src="https://allmcps.com/api/badge/tridentchain-security?style=directory" alt="TridentChain Security on AllMCPs" /></a>