Skip to main content
Glama
eaglebooth

PatchProof MCP

by eaglebooth

Related Servers

Alternatives to PatchProof MCP

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      B
      maintenance
      Deterministic supply-chain provenance, SBOM/AI-BOM generation, and dependency risk analysis for npm and PyPI packages, with 14 security rules and verifiable reports.
      1
      MIT
    • A
      license
      A
      quality
      A
      maintenance
      Enables AI coding agents and CI to vet npm dependencies before they reach the lockfile, flagging hallucinated, slopsquatted, or otherwise risky packages with evidence-backed verdicts.
      3
      68 npm
      4
      MIT
    • A
      license
      B
      quality
      C
      maintenance
      Enables security scanning for npm dependencies by checking manifest and lockfiles against the OSV.dev and Socket.dev vulnerability databases. It provides tools to detect vulnerabilities in specific packages and retrieve detailed technical reports for identified security issues.
      3
      15 npm
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Audits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.
      MIT
    • A
      license
      A
      quality
      C
      maintenance
      Enables scanning of package.json and lockfiles to classify dependency licenses and flag GPL/AGPL/unknown ones for commercial awareness, optionally reading license metadata from the public npm registry. Advisory only, not legal advice.
      3
      MIT

    TDQS

    A3.8/5.0

    Scored across 4 tools

    Disambiguation4/5

    Tools have distinct purposes: audit_dependencies focuses on known vulnerabilities from OSV, scan_repository is broader (vulnerabilities, secrets, malformed inputs), generate_sbom creates SBOMs, and generate_evidence_report produces reports. Some overlap between audit and scan, but descriptions clarify differences.

    Naming Consistency5/5

    All tool names follow a consistent verb_noun pattern with snake_case: audit_dependencies, generate_evidence_report, generate_sbom, scan_repository. No deviations.

    Tool Count5/5

    4 tools is perfectly scoped for a security/audit server covering dependency auditing, SBOM generation, repository scanning, and evidence reporting. Neither too few nor too many.

    Completeness5/5

    The toolset covers the core lifecycle: scan repository, audit dependencies, generate SBOM, and assemble evidence report. No obvious missing operations for the stated domain of repository security and compliance.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues