Skip to main content
Glama
wwb-bill

mcp-supply-guard

by wwb-bill

🧬 mcp-supply-guard

Python License CI No Dependencies

MCP 工具定义供应链完整性。 2026 年安全数据点:43% 的 MCP 服务器存在命令注入漏洞,且工具定义在批准后可能发生变异——这是一种拉地毯向量。该库在审查后锁定工具定义内容哈希的基线,然后在后续加载时进行验证:标记新增/移除/修改的工具,并对命令执行危险信号进行风险扫描。

零依赖。纯 Python 标准库。

快速开始

pip install mcp-supply-guard

Related MCP server: heddle

用法

from mcp_supply_guard import load_tools, fingerprint, verify, scan_risk

baseline = [fingerprint(t) for t in load_tools("approved.json")]  # lock after review
report = verify(load_tools("current.json"), baseline)
print(report.clean)          # False if any tool added/modified
for f in report.findings:
    print(f.kind, f.tool, f.message)

risks = scan_risk(load_tools("current.json"))

CLI

mcp-supply-guard lock approved.json baseline.json
mcp-supply-guard verify current.json baseline.json --json    # CI exit 1 on added/modified
mcp-supply-guard risk current.json --json

tools.json

{"tools": [{"name": "search", "description": "Search the index",
            "inputSchema": {"type": "object", "properties": {"q": {"type": "string"}}}}]}

发现结果

类型

严重性

含义

added

错误

基线锁定后新增了工具

modified

错误

定义哈希已更改(拉地毯向量)

removed

警告

基线工具现在缺失

risky

错误/警告

描述/模式中存在命令执行危险信号

许可证

MIT © wwb-bill

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    Enables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.
    4
    1
    MIT
  • A
    license
    -
    quality
    A
    maintenance
    Enables users to define and run MCP tools using declarative YAML configs with built-in trust enforcement, credential brokering, and tamper-evident audit logging.
    14
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables validation of commit messages, branch names, author info, push safety, and repository state using commit-check rules, accessible as MCP tools.
    8
    MIT

View all related MCP servers

Related MCP Connectors

  • Static MCP manifest and tool-policy security preflight with signed input-redacted receipts

  • Remote MCP for tool license checks, vendor policy review, alternatives, and license receipts.

  • Free MCP tools: the only MCP linter, health checks, cost estimation, and trust evaluation.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/wwb-bill/mcp-supply-guard'

If you have feedback or need assistance with the MCP directory API, please join our Discord server