Skip to main content
Glama
badchars

supply-chain-mcp-server

by badchars

Related Servers

Alternatives to supply-chain-mcp-server

No user-submitted related servers found.

    Related Servers

    • A
      license
      A
      quality
      B
      maintenance
      Unifies NVD, EPSS, CISA KEV, GitHub Advisory, and OSV into a single MCP server, enabling AI agents to query vulnerability intelligence conversationally with 23 tools for incident response, prioritization, dependency audits, and threat monitoring.
      41
      245 npm
      28
      MIT
    • A
      license
      A
      quality
      A
      maintenance
      MCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.
      14
      9 npm
      15
      Apache 2.0
    • A
      license
      B
      quality
      C
      maintenance
      An MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.
      6
      MIT
    • A
      license
      Not graded
      quality
      F
      maintenance
      Enables unified security workflows with secret scanning, dependency CVE auditing, TLS/SSL inspection, and DNS/SPF/DMARC checks through a single MCP server.
      360 npm
      1
      MIT

    TDQS

    B3/5.0

    Scored across 90 tools

    Disambiguation4/5

    Most tools are clearly separated by ecosystem prefix and specific purpose, so an agent can usually tell them apart. There are a few boundary overlaps, such as npm_package vs npm_maintainers and npm_provenance vs npm_attestations, which could cause occasional misselection.

    Naming Consistency4/5

    Tool names follow a consistent ecosystem_prefix + noun pattern, with mostly snake_case throughout. Minor inconsistencies exist in verb choice (search/lookup/query/fetch) and a few odd names like epss_above_threshold and rekor_entries_search, but overall the pattern is predictable.

    Tool Count1/5

    With 90 tools, this server is far beyond the recommended scope for effective agent coherence. Even though the domain is broad, this many tools creates significant navigation and selection overhead for an agent.

    Completeness4/5

    The server covers an impressively wide range of supply-chain security data: package registries, vulnerability databases, dependency graphs, provenance, licenses, scorecards, and transparency logs. Some gaps exist, such as no direct Maven/Java support and no dedicated PyPI or crates.io search, but the core supply-chain investigation workflows are well covered.

    Maintenance

    ActivityStale
    ResponsivenessNo issues