brandguard
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@brandguardscan brand 'Acme' for typosquats"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
brandguard 🛡️
Brand impersonation & typosquat monitor for AI agents and brand owners.
Feed brandguard a brand or product name and it scans npm, PyPI and GitHub for packages and repos that typosquat or impersonate you — each risk-scored — plus a ready-to-review takedown / trademark-notice draft.
brandguard reports from public sources. It does not file claims on anyone's behalf and is not a law firm or your agent. The takedown notice is a draft for the rights-holder to review, complete and file themselves.
Live: https://brandguard.djrorrok.workers.dev
Why an agent can't do this alone (the moat)
An LLM coding/brand agent, on its own, doesn't know:
the typosquat surface of a name (omissions, doubling, homoglyphs
o→0 l→1, deceptive-js/-sdk/-officialaffixes);which listings across three registries actually exist right now;
how to separate the real brand / legit integrations (own npm scope, high adoption, third-party org scopes like
@types/*) from parked squats — without crying wolf.
brandguard does the cross-registry lookups and the calibrated scoring so the
verdict is trustworthy: LIKELY_ABUSE is only raised with a signal beyond
the name match (a "this is the official X" claim, or a parked-squat download
pattern). Bare name matches are SUSPECT → human review, never a false accusation.
Related MCP server: proof-of-commitment
Use it
Free HTTP API
GET /scan?brand=acme&official=acme-inc # top 5 findings, risk-scored (npm + PyPI)MCP (over HTTP)
POST /mcp — tools: scan_brand, draft_takedown.
Pay-per-call (x402) — full scan + takedown drafts
GET /pro/scan?brand=acme&official=acme-inc # 402 -> pay $0.15 USDC (Base) -> full report + draftsSettles in USDC on Base via x402. No sign-up, no API key.
Sources (all public / ToS-compliant)
npm public registry search + downloads API
PyPI JSON API
GitHub Search API (server-side token)
Develop / deploy
node src/test.mjs # unit + live tests
npx wrangler deploy # Cloudflare WorkerMIT. Not legal advice.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Live trust signals for domains & packages: age, registrar, typosquat resemblance.
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables users to scan software packages for data exfiltration and security threats directly within their IDE across npm, PyPI, Cargo, and Maven ecosystems. This tool helps ensure the safety of project dependencies by identifying potential risks before they are integrated.MIT
- AlicenseAqualityBmaintenanceSupply chain risk scoring for npm, PyPI, and GitHub repos8477MIT
- AlicenseNot gradedqualityCmaintenanceAudits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.MIT

EVIDIQ Lineageofficial
AlicenseNot gradedqualityBmaintenanceDeterministic supply-chain provenance, SBOM/AI-BOM generation, and dependency risk analysis for npm and PyPI packages, with 14 security rules and verifiable reports.1MIT