Skip to main content

Browse the directory

Showing 19 resources for "supply-chain"
Saved
Active

3 trusted · 16 review in this set — compare to see which signals differ.

Trust snapshot

19 results in this view

Claimed
0%(0/19)

3 trust signals differ in this sample: Package trust, Source provenance, Submitter

Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (12/12)

Adoption queue

Browse adoption queue · balanced

1/19 visible results are in hold tier and need mitigation before adoption.

ready 0caution 18hold 1

MCP Server Security Hardening Skill

1 blockers: Metadata review

caution

70/100

Request metadata review from maintainers or internal owners.

skills/mcp-server-security-hardening · trust trusted · confidence 83%

Socket MCP Server for Claude

1 blockers: Metadata review

caution

70/100

Request metadata review from maintainers or internal owners.

mcp/socket-mcp-server · trust trusted · confidence 83%

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/claude-code-plugin-marketplace-authoring-capability-pack · trust review · confidence 67%

Dependency Update Review Rules

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/dependency-update-review-rules · trust review · confidence 67%

Dependency Update Triage Agent

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

agents/dependency-update-triage-agent · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

1/19 results are low-confidence and need review before adoption.

high 3medium 15low 1

Socket MCP Server for Claude

Confident candidate for staged adoption.

high

74/100

Missing: Metadata review

mcp/socket-mcp-server · trust trusted

Dependency Update Review Rules

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

rules/dependency-update-review-rules · trust review

Dependency Update Triage Agent

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

agents/dependency-update-triage-agent · trust review

Freshness distribution

Mostly fresh with a few aging entries

Median age 54 days; 10 fresh, 2 aging or stale of 12 scanned.

median 54d

Aging

91–180 days

8%

1 entry

Stale

> 180 days

8%

1 entry

Theme distribution

Results center on supply-chain

79% of this view shares the top theme. Leading themes: supply-chain, security, dependencies.

Focused

49 distinct themes across 19 scanned

Secure MCP servers with strict tool boundaries, auth controls, dependency hygiene, and abuse-resistant runtime policies.

Level:advancedType:generalVerified:draft
Safety ✓ Privacy ✓

Security scanner from Snyk for discovering local AI agent components, including MCP servers and Agent Skills, and checking them for prompt injection, tool poisoning, tool shadowing, toxic flows, malware payloads, credential handling, and hardcoded secrets.

Expert plugin marketplace authoring capability pack applying documented marketplace.json catalogs, /plugin marketplace add flows, private repo distribution, and supply-chain review from official plugin marketplace documentation.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.

Invocation:/dependency-risk-review [package]
Safety ✓ Privacy ✓

Source-backed rules for reviewing dependency update pull requests with supply-chain context, lockfile discipline, advisory checks, compatibility evidence, and privacy-safe metadata handling.

PostToolUse hook that flags risky package-lock.json, yarn.lock, and pnpm-lock.yaml edits: missing lockfile updates, unexpected registry hosts, and dependency count spikes before merge.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.

Invocation:/pr-security-review [pr-number]
Safety ✓ Privacy ✓
GitHub logo

Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

PreToolUse hook that reviews proposed Bash commands for package, installer, and archive downloads, then blocks curl or wget download commands that do not include an adjacent checksum or signature verification step.

Trigger:PreToolUse
Safety ✓ Privacy ✓

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓

PostToolUse hook that watches dependency manifest and lockfile edits, then prompts or runs an OSS Review Toolkit dependency license analysis.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Expert SLSA provenance review skill for checking source, build, artifact, and trust evidence before accepting content or package submissions.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Verify MCP server package provenance before Claude Code installation: registry publisher match, repository ownership, release artifact checksums, maintainer history, and rollback when supply-chain signals fail review.

Pin MCP server package versions before adding them to Claude Code: registry verification, lockfile discipline, npx package pins, supply-chain review, and rollback steps aligned to MCP quickstart and registry documentation.

Source-backed agent for triaging dependency update pull requests with SemVer risk, Dependabot context, GitHub dependency review, OSV advisories, OpenSSF Scorecard signals, lockfile changes, test evidence, and privacy-safe notes.

A defense-in-depth bundle for hardening an agentic Claude Code workstation: block secrets and sensitive data before they are written, verify dependency provenance and known vulnerabilities, review supply-chain risk and run code security audits, and harden MCP tool access against prompt injection.

GitHub logo

Expert GitHub Actions capability skill for secure workflow architecture, token minimization, supply-chain controls, and CI reliability.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓
Protect AI logo

AI security platform for securing machine learning and LLM supply chains, models, applications, and infrastructure.

Safety · Privacy ·