Score supply chain risk for npm, PyPI, Cargo, and Go packages.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "Commit — Supply Chain Risk Scoring" MCP server from askskill: Run: claude mcp add 'io-github-piiiico-proof-of-commitment' -- npx -y proof-of-commitment
Use Commit to check the supply chain risk score for this npm package and summarize the main behavioral signals and potential risks: package-name
Returns the package's risk score and highlights notable behavioral signals and risk factors.
Compare the supply chain risk scores of the following packages and rank them from highest to lowest risk: one PyPI package, one Cargo package, and one Go package.
Provides a cross-ecosystem risk comparison and ranking to help choose safer dependencies.
Run a supply chain risk review on the key dependencies in the current project and list high-risk items that should be reviewed first.
Produces a prioritized list of high-risk dependencies for pre-release security review.
Developers can review supply chain risk scores and behavioral signals before choosing npm, PyPI, Cargo, or Go dependencies, reducing the chance of adopting risky packages.
DevOps or security owners can recheck key dependency risks before release and identify high-risk components that need manual review.
Researchers can compare package risk across language ecosystems and examine potential supply chain issues using scores and behavioral signals.
It provides supply chain risk scoring for packages in the npm, PyPI, Cargo, and Go ecosystems, using behavioral signals to help assess risk.
The provided information says it supports npm, PyPI, Cargo, and Go. For broader coverage details, see the source repository.
The original description mentions 9 tools, but it does not describe each one individually; see the source repository for details.
Review dependency changes to reduce supply chain attacks and token leakage.
Analyze repositories, packages, and dependency security insights in one place.
Scan local dependencies and IDE extensions for CVEs.
Assess open-source health, dependency risks, trends, and license differences.
Scan AI-generated code for security risks before shipping with ranked findings.
Scan npm dependencies for license risks and GPL contamination.