AgentStack
MCP verified MIT Self-run

Mcp Provenance Monitor

mcp-letmaik-mcp-provenance-monitor Β· by letmaik

πŸ”Ž Monitoring supply chain provenance of local MCP servers

β€” No reviews yet
0 installs
2 views
0.0% view→install

Install

$ agentstack add mcp-letmaik-mcp-provenance-monitor

βœ“ scanned Β· βœ“ verified β€” works with Claude Code, Cursor, and more.

Security review

βœ“ Passed

No issues found. Passed automated security review. Β· v0.1.0 How review works β†’

  • βœ“ Prompt-injection patterns
  • βœ“ Secret / credential exfiltration
  • βœ“ Dangerous shell & filesystem operations
  • βœ“ Untrusted network calls
  • βœ“ Known-malicious package signatures

What it can access

  • βœ“ Network access No
  • βœ“ Filesystem access No
  • βœ“ Shell / process execution No
  • βœ“ Environment & secrets No
  • βœ“ Dynamic code execution No

From automated source analysis of v0.1.0. β€œUsed” means the capability is present in the source β€” more access means more to trust, not that it’s unsafe.

Are you the author of Mcp Provenance Monitor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

MCP Provenance Monitor

πŸ‘‰ MCP Provenance Monitor Dashboard

A web dashboard for monitoring the software supply chain provenance of local MCP (Model Context Protocol) server packages.

[](https://letmaik.github.io/mcp-provenance-monitor)

[](https://letmaik.github.io/mcp-provenance-monitor)

FAQ

Why is MCP server xyz missing?

How can I add provenance to my MCP server?

How can I add provenance to dependencies?

  • Help improve the ecosystem by contributing to dependency packages: ensure they are built in CI and publish provenance. You can also consider submitting a pull request to those projects.

I just released a new version with provenance, but it still says provenance is missing. Why?

  • Data is refreshed daily. If you just published a new version, please allow up to one day for the update to appear.

Do MCP clients check provenance?

Development

pip install -r requirements.txt
python -m collector.main --dev
python -m http.server -d web

License

See the [LICENSE](LICENSE) file for details.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source β€” we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet β€” be the first.

Versions

  • v0.1.0 Imported from the upstream source.