Run CVE and supply chain checks for MCP clients and packages.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "io.github.attestd-io/attestd-mcp" MCP server from askskill: Run: claude mcp add 'io-github-attestd-io-attestd-mcp' -- npx -y @attestd/mcp
Use attestd-mcp to check this npm package for CVEs and supply chain risks, then summarize the key findings: express
A security check result for the npm package, including known vulnerabilities or a summary of supply chain risks.
Use attestd-mcp to run CVE and supply chain checks on this PyPI package: requests
Results for vulnerability and supply chain checks on the Python package to help assess whether it is safe to use.
Use attestd-mcp to perform security checks on the following infrastructure components and list potential risk points.
Security check output for infrastructure components, highlighting possible CVEs or supply chain issues.
Developers can use it to check known CVEs and supply chain risks in npm or PyPI packages before adoption, reducing the chance of bringing in risky dependencies.
For teams using MCP clients, this tool adds vulnerability and supply chain checks to help identify potential security issues.
DevOps or security teams can use it to check known security risks in infrastructure as part of routine reviews or pre-release validation.
It performs CVE and supply chain checks for MCP clients, covering infrastructure, PyPI packages, and npm packages.
Based on the provided description, it supports security checks for infrastructure, PyPI packages, and npm packages. For more detailed scope, see the source repository.
The provided materials do not include installation or configuration steps. For prerequisites, runtime details, and authentication requirements, see the source repository.
Scan remote MCP servers for protocol, security, and TLS issues.
Scan firmware and verify hardware trust to identify security risks.
Verify and attest SHA-256 fingerprints of digital works remotely.
Search risk-classified MCP servers and verify their trust status.
Query vulnerability intelligence, risk scores, and attack-surface data for security decisions.
Explore and choose MCP clients for different workflows and integration needs.