Commit — Supply Chain Risk Scoring
What this MCP does
Audits npm, PyPI, Cargo, and Go dependencies, repositories, and dependency trees for behavioral supply-chain risk signals.
Tools
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['packages'], 'properties': {'packages': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 20, 'minItems': 1, 'description': 'List of package names to score. Up to 20 at once. Examples: ["langchain", "litellm", "openai", "axios"] or ["@anthropic-ai/sdk", "zod", "express"] or ["github.com/gin-gonic/gin", "golang.org/x/net"] for Go modules.'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'golang', 'auto'], 'type': 'string', 'default': 'auto', 'description': 'Package ecosystem. "auto" detects by naming convention (Python-style = pypi, otherwise npm). Force "npm", "pypi", "cargo", or "golang" to override. Go modules require full path (host/owner/repo) â\x80\x94 use "golang".'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['package'], 'properties': {'depth': {'type': 'integer', 'default': 1, 'maximum': 2, 'minimum': 1, 'description': 'How deep to traverse. 1 = direct deps only (fast). 2 = also traverse deps of CRITICAL/HIGH packages (slower, reveals hidden risk). Default: 1'}, 'package': {'type': 'string', 'description': 'npm package name to map. Examples: "express", "langchain", "@anthropic-ai/sdk", "zod"'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repo'], 'properties': {'repo': {'type': 'string', 'description': 'GitHub repository to audit. Accepts: "owner/repo", "https://github.com/owner/repo", or any GitHub URL. Examples: "vercel/next.js", "https://github.com/langchain-ai/langchainjs"'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['email'], 'properties': {'email': {'type': 'string', 'format': 'email', 'pattern': "^(?!\\.)(?!.*\\.\\.)([A-Za-z0-9_'+\\-\\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$", 'description': 'Your email address â\x80\x94 used for alert delivery and key recovery. One key per email.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['query'], 'properties': {'query': {'type': 'string', 'description': "Business name to search for (e.g. 'Peppes Pizza', 'Equinor')"}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['orgNumber'], 'properties': {'orgNumber': {'type': 'string', 'description': "Norwegian organization number (9 digits, e.g. '984388659')"}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['crate'], 'properties': {'crate': {'type': 'string', 'description': 'Crate name on crates.io. Examples: "serde", "tokio", "reqwest", "clap". Case-insensitive.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repo'], 'properties': {'repo': {'type': 'string', 'description': 'GitHub repository in "owner/repo" format or full URL. Examples: "vercel/next.js", "https://github.com/facebook/react"'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['module'], 'properties': {'module': {'type': 'string', 'description': 'Full Go module path. Must include the host. Examples: "github.com/gin-gonic/gin", "golang.org/x/net", "k8s.io/client-go", "gopkg.in/yaml.v3". Case-sensitive (preserves capitalization in path).'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['package'], 'properties': {'package': {'type': 'string', 'description': 'npm package name. Examples: "langchain", "@anthropic-ai/sdk", "express". Scoped packages need the @ prefix.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['package'], 'properties': {'package': {'type': 'string', 'description': 'PyPI package name. Examples: "langchain", "openai", "requests", "fastapi". Case-insensitive.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': "The domain to query (e.g. 'example.com'). Will be normalized to lowercase without protocol or path."}}}
Recent tool changes
Similar MCP servers
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…