Skip to main content
Glama
wwb-bill

mcp-supply-guard

by wwb-bill

🧬 mcp-supply-guard

Python License CI No Dependencies

MCPツール定義サプライチェーンの整合性。 2026年のセキュリティデータポイント:MCPサーバーの43%がコマンドインジェクションの脆弱性を持っており、ツール定義は承認後に変化する可能性があります——ラグプルベクトルです。このライブラリは、レビュー後にツール定義のコンテンツハッシュのベースラインをロックし、その後読み込み時に検証します:追加/削除/変更されたツールをフラグ付けし、コマンド実行の危険信号のリスクスキャンを行います。

依存関係ゼロ。純粋なPython標準ライブラリ。

クイックスタート

pip install mcp-supply-guard

Related MCP server: commit-check-mcp

使用法

from mcp_supply_guard import load_tools, fingerprint, verify, scan_risk

baseline = [fingerprint(t) for t in load_tools("approved.json")]  # lock after review
report = verify(load_tools("current.json"), baseline)
print(report.clean)          # False if any tool added/modified
for f in report.findings:
    print(f.kind, f.tool, f.message)

risks = scan_risk(load_tools("current.json"))

CLI

mcp-supply-guard lock approved.json baseline.json
mcp-supply-guard verify current.json baseline.json --json    # CI exit 1 on added/modified
mcp-supply-guard risk current.json --json

tools.json

{"tools": [{"name": "search", "description": "Search the index",
            "inputSchema": {"type": "object", "properties": {"q": {"type": "string"}}}}]}

調査結果

種類

重大度

意味

added

error

ベースラインロック後に追加されたツール

modified

error

定義ハッシュが変更されました(ラグプルベクトル)

removed

warning

ベースラインのツールが現在存在しません

risky

error/warning

説明/スキーマ内のコマンド実行の危険信号

ライセンス

MIT © wwb-bill

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables users to define and run MCP tools using declarative YAML configs with built-in trust enforcement, credential brokering, and tamper-evident audit logging.
    13
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables validation of commit messages, branch names, author info, push safety, and repository state using commit-check rules, accessible as MCP tools.
    8
    31 PyPI
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A continuous, out-of-band trust and reliability layer for the MCP ecosystem. It fingerprints MCP server tool definitions, detects and classifies drift (e.g., rug pulls) via a severity taxonomy, maintains a hash-chained evidence ledger, and gates CI with SARIF—while also acting as an MCP server itself so agents can check a server's safety before binding.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to govern downstream tool servers by enforcing default-deny authority and attestation on every tool call, with live monitoring, approval, and mid-session revocation.
    3
    Apache 2.0