Skip to main content
Glama
wwb-bill

mcp-supply-guard

by wwb-bill

🧬 mcp-supply-guard

Python License CI No Dependencies

MCP tool-definition supply-chain integrity. 2026 security data point: 43% of MCP servers have command injection vulnerabilities, and tool definitions can mutate after approval — a rug-pull vector. This library locks a baseline of tool-definition content hashes after review, then verifies later loads: flagging added / removed / modified tools, plus a risk scan for command-execution danger signals.

Zero dependencies. Pure Python stdlib.

Quick Start

pip install mcp-supply-guard

Related MCP server: commit-check-mcp

Usage

from mcp_supply_guard import load_tools, fingerprint, verify, scan_risk

baseline = [fingerprint(t) for t in load_tools("approved.json")]  # lock after review
report = verify(load_tools("current.json"), baseline)
print(report.clean)          # False if any tool added/modified
for f in report.findings:
    print(f.kind, f.tool, f.message)

risks = scan_risk(load_tools("current.json"))

CLI

mcp-supply-guard lock approved.json baseline.json
mcp-supply-guard verify current.json baseline.json --json    # CI exit 1 on added/modified
mcp-supply-guard risk current.json --json

tools.json

{"tools": [{"name": "search", "description": "Search the index",
            "inputSchema": {"type": "object", "properties": {"q": {"type": "string"}}}}]}

Findings

Kind

Severity

Meaning

added

error

tool added after baseline locked

modified

error

definition hash changed (rug-pull vector)

removed

warning

baseline tool missing now

risky

error/warning

command-execution danger signals in description/schema

License

MIT © wwb-bill

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables users to define and run MCP tools using declarative YAML configs with built-in trust enforcement, credential brokering, and tamper-evident audit logging.
    14
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables validation of commit messages, branch names, author info, push safety, and repository state using commit-check rules, accessible as MCP tools.
    8
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A continuous, out-of-band trust and reliability layer for the MCP ecosystem. It fingerprints MCP server tool definitions, detects and classifies drift (e.g., rug pulls) via a severity taxonomy, maintains a hash-chained evidence ledger, and gates CI with SARIF—while also acting as an MCP server itself so agents can check a server's safety before binding.
    Apache 2.0
  • A
    license
    B
    quality
    B
    maintenance
    Enables design system governance over MCP, with tools to track component adoption, detect drift, assess change impact, and enforce recorded decisions.
    13
    149
    MIT