{"name":"io.github.DevInder1/tridentchain-security","slug":"devinder1-tridentchain-security","title":"TridentChain Security","description":"Local supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.","url":"https://mcp.market/server/devinder1-tridentchain-security","rating":null,"grade":"A","score":88,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":17,"stars":0,"forks":0,"downloads_week":25,"last_push_at":"2026-07-29T18:01:09.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"pypi","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/DevInder1/supply-chain-scanner-public","website":null,"version":"0.1.5","remotes":[],"packages":[{"registryType":"pypi","identifier":"tridentchain-mcp","version":"0.1.5","transport":{"type":"stdio"}}],"tools":[{"name":"scan_full","description":"Comprehensive scan covering THREE surfaces in one call that project-only scanners cannot reach: (1) project dependencies (npm, PyPI), (2) OS/system packages (Homebrew on macOS, apt/dnf on Linux), and (3) installed IDE extensions (VS Code marketplace + JetBrains plugins). Use this whenever the user asks for \"complete coverage\", a \"full audit\", scanning their \"whole machine\" or \"system\", or wants to","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_project","description":"Scan project dependencies for CVEs and rank findings by REAL-WORLD EXPLOITATION RISK using EPSS (exploit probability) and the CISA KEV (Known Exploited Vulnerabilities) catalog — not just CVSS severity. Best for: when the user wants to know which CVEs to fix FIRST, asks about supply-chain risk in an IDE/conversational context, or wants to pair with validate_after_patch for a confirmed-fix workflow","write_action":false,"price_micros":0,"input_schema":null},{"name":"validate_after_patch","description":"Confirm that dependency upgrades actually resolved the CVEs they were supposed to fix. Use this whenever the user says they ran `npm update`, `pip install -U`, or applied a patch and wants verification — chain it with two scan_project calls (before/after) or pass two saved scan JSON results. This is unique to TridentChain; most other supply-chain scanners only report findings without a verifiable","write_action":true,"price_micros":0,"input_schema":null}],"scan":{"score":88,"grade":"A","scanned_at":"2026-09-24T17:25:20.478Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-24T17:25:20.405Z","components":{"code":{"score":25,"max":25,"notes":["4 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":12,"max":15,"notes":["last push 57 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[{"registryType":"pypi","identifier":"tridentchain-mcp","version":"0.1.5","found":true,"weeklyDownloads":25,"license":"MIT","dependencyCount":2,"publishedAt":"2026-07-29T16:48:20.623750Z","repositoryUrl":"https://github.com/DevInder1/supply-chain-scanner-public"}],"repo":{"found":true,"owner":"DevInder1","repo":"supply-chain-scanner-public","archived":false,"pushedAt":"2026-07-29T18:01:09Z","stars":0,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/24380787?v=4","ownerCreatedAt":"2016-12-05T05:01:07Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/24380787?v=4&s=128","source":"github"},"presence":{"stars":0,"forks":0,"downloadsWeek":25,"license":"MIT","lastPushAt":"2026-07-29T18:01:09.000Z","score":17}}}},"grade_history":[],"reviews":[]}