A
licenseNot graded
qualityA
maintenanceEnables users to define and run MCP tools using declarative YAML configs with built-in trust enforcement, credential brokering, and tamper-evident audit logging.
13
MIT
MCP 工具定义供应链完整性。 2026 年安全数据点:43% 的 MCP 服务器存在命令注入漏洞,且工具定义在批准后可能发生变异——这是一种拉地毯向量。该库在审查后锁定工具定义内容哈希的基线,然后在后续加载时进行验证:标记新增/移除/修改的工具,并对命令执行危险信号进行风险扫描。
零依赖。纯 Python 标准库。
pip install mcp-supply-guardRelated MCP server: commit-check-mcp
from mcp_supply_guard import load_tools, fingerprint, verify, scan_risk
baseline = [fingerprint(t) for t in load_tools("approved.json")] # lock after review
report = verify(load_tools("current.json"), baseline)
print(report.clean) # False if any tool added/modified
for f in report.findings:
print(f.kind, f.tool, f.message)
risks = scan_risk(load_tools("current.json"))mcp-supply-guard lock approved.json baseline.json
mcp-supply-guard verify current.json baseline.json --json # CI exit 1 on added/modified
mcp-supply-guard risk current.json --json{"tools": [{"name": "search", "description": "Search the index",
"inputSchema": {"type": "object", "properties": {"q": {"type": "string"}}}}]}类型 | 严重性 | 含义 |
| 错误 | 基线锁定后新增了工具 |
| 错误 | 定义哈希已更改(拉地毯向量) |
| 警告 | 基线工具现在缺失 |
| 错误/警告 | 描述/模式中存在命令执行危险信号 |
MIT © wwb-bill
This server cannot be deployed
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
Trust checks for MCP servers: trust scores, tool-drift detection, signed diligence receipts. Free.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.