supply-chain-mcp-server
Related Servers
Alternatives to supply-chain-mcp-server
No user-submitted related servers found.
Related Servers
- AlicenseAqualityBmaintenanceUnifies NVD, EPSS, CISA KEV, GitHub Advisory, and OSV into a single MCP server, enabling AI agents to query vulnerability intelligence conversationally with 23 tools for incident response, prioritization, dependency audits, and threat monitoring.41245 npm28MIT
- FlicenseNot gradedqualityBmaintenanceEnables AI agents and MCP-compliant clients to audit software bills of materials and quarantine supply-chain malicious package dependencies using Snyk and Socket.dev.8-
- AlicenseAqualityAmaintenanceMCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.149 npm15Apache 2.0
- AlicenseBqualityCmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MIT

@guardbee/security-suiteofficial
AlicenseNot gradedqualityFmaintenanceEnables unified security workflows with secret scanning, dependency CVE auditing, TLS/SSL inspection, and DNS/SPF/DMARC checks through a single MCP server.360 npm1MIT- FlicenseAqualityDmaintenancePackage intelligence MCP server. Stops AI agents from installing hallucinated/malicious packages across 17 ecosystems. 22 tools, free, no auth.221-
TDQS
Scored across 90 tools
Most tools are clearly separated by ecosystem prefix and specific purpose, so an agent can usually tell them apart. There are a few boundary overlaps, such as npm_package vs npm_maintainers and npm_provenance vs npm_attestations, which could cause occasional misselection.
Tool names follow a consistent ecosystem_prefix + noun pattern, with mostly snake_case throughout. Minor inconsistencies exist in verb choice (search/lookup/query/fetch) and a few odd names like epss_above_threshold and rekor_entries_search, but overall the pattern is predictable.
With 90 tools, this server is far beyond the recommended scope for effective agent coherence. Even though the domain is broad, this many tools creates significant navigation and selection overhead for an agent.
The server covers an impressively wide range of supply-chain security data: package registries, vulnerability databases, dependency graphs, provenance, licenses, scorecards, and transparency logs. Some gaps exist, such as no direct Maven/Java support and no dedicated PyPI or crates.io search, but the core supply-chain investigation workflows are well covered.