Install
$ agentstack add mcp-devinder1-supply-chain-scanner-public ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.2 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.2. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
TridentChain Security
[](https://pypi.org/project/tridentchain-security/) [](https://pypi.org/project/tridentchain-mcp/) [](https://pypi.org/project/tridentchain-mcp/) [](https://registry.modelcontextprotocol.io/v0.1/servers?search=tridentchain) [](https://www.python.org/downloads/) [](LICENSE) [](docs/AGENT_INTEGRATIONS.md)
Local-first vulnerability scanner for project dependencies, developer tools, and IDE extensions. Uses multi-source intelligence (OSV, NVD, GHSA, Sonatype) with KEV/EPSS prioritization.
No API key required for default usage.
Public repo: https://github.com/DevInder1/supply-chain-scanner-public
Install (plug and play)
pip3 install tridentchain-security
npm install -g @tridentchain/security-cli
tridentchain-security --help
Agents & MCP (Claude, Cursor, VS Code):
pip3 install "tridentchain-security>=0.1.1" tridentchain-mcp
What you can do: [docs/CAPABILITIES.md](docs/CAPABILITIES.md) Full guide: [docs/INSTALLANDUSE.md](docs/INSTALLANDUSE.md) Cross-platform (macOS / Linux / Windows): [docs/CROSSPLATFORM.md](docs/CROSSPLATFORM.md) (PyPI: tridentchain-security · npm: @tridentchain/security-cli)
tridentchain-security --scan all --project-path . --output-dir scanner-output
Use in your own Python app
from scanner import run_scan
summary = run_scan(
project_path=".",
scan="all",
run_profile="full", # no API key required
output_dir="scanner-output",
)
print(summary["summary"])
Scan profiles
| Profile | Description | |---------|-------------| | full (default) | Project + system + extensions. OSV + NVD without keys. | | quick | Faster project-focused scan. | | offline | Local advisory DB only, no network. | | Power-user | Add GITHUB_TOKEN, NVD_API_KEY, optional SONATYPE_TOKEN for best coverage. |
Desktop app (individual application)
No repo clone required if the pip package is installed:
pip3 install tridentchain-security
cd apps/desktop && npm install && npm run start
See [apps/desktop/README.md](apps/desktop/README.md) and [docs/DISTRIBUTIONVERIFICATION.md](docs/DISTRIBUTIONVERIFICATION.md).
AI / automation (Claude, OpenAI, Cursor, VS Code, Windsurf, …)
One install, every agent: pip install "tridentchain-security>=0.1.2" tridentchain-mcp
| Guide | Description | |-------|-------------| | [Agent integrations](docs/AGENTINTEGRATIONS.md) | Claude · OpenAI · Cursor · VS Code · Windsurf · Zed · MCP · CLI | | [Capabilities](docs/CAPABILITIES.md) | Everything you can do today | | [Architecture](docs/INTEGRATIONARCHITECTURE.md) | MCP + unified tools design |
./scripts/setup-agent-mcp.sh cursor # prints setup for your agent
Phase 2 — Claude MCP: pip install tridentchain-mcp · [Setup guide](docs/CLAUDEMCPSETUP.md) · [Plugin](plugins/tridentchain-security/)
Phase 3 — OpenAI + Cursor: [examples/openai/](examples/openai/) · [Cursor setup](docs/CURSOR_SETUP.md) · .cursor/mcp.json.example
Phase 4 — VS Code (Anthropic MCP): Open repo → MCP ready · [VS Code setup](docs/VSCODE_SETUP.md) · ./scripts/vscode-mcp-install-link.sh · [extension](extensions/vscode-tridentchain/)
Phase 5 — Validate: tridentchain-security --validate · MCP validate_after_patch · [CAPABILITIES.md](docs/CAPABILITIES.md)
Unified tool layer: from scanner.integrations import execute_tool, get_tool_definitions, to_openai_tools
Development
git clone https://github.com/DevInder1/supply-chain-scanner-public.git
cd supply-chain-scanner-public
python3 -m pip install -e .
tridentchain-security --help
python3 -m unittest scanner.tests.test_matcher_ranges -v
Install & use: docs/INSTALL_AND_USE.md Cross-platform: docs/CROSS_PLATFORM.md CLI contract: docs/cli-contract.md Publishing: docs/PUBLISHING.md
Optional API keys (power users)
| Variable | Purpose | |----------|---------| | NVD_API_KEY | Higher NVD rate limits | | GITHUB_TOKEN | GHSA advisories | | SONATYPE_TOKEN | Sonatype Guide advisories |
Set in .env or environment variables.
License
MIT — see [LICENSE](LICENSE)
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: DevInder1
- Source: DevInder1/supply-chain-scanner-public
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.2 Imported from the upstream source.