Skip to main content

bastionsupply

MCP supply-chain security scanner. Point it at an MCP server's tool definitions and it flags the supply-chain attacks before you install: tool-poisoning, tool-shadowing, hidden unicode, secret solicitation, dangerous capabilities, and rug-pull drift.

The pre-flight leg of the bastion family:

tool job
bastionsupply scan an MCP server before you trust it
agentbastion prevent — firewall around a running agent
bastionprobe attack — pentest your agent with injections
bastiontrace investigate — forensics on an agent trace

No network, no LLM, no dependencies — pure static analysis of what a server claims about itself, which is exactly where the attack hides.

Install

pip install bastionsupply

Use

# offline: scan a tools/list JSON dump
bastionsupply scan tools.json

# live: spawn a stdio MCP server and scan the tools it advertises
bastionsupply scan --stdio "npx -y @some/mcp-server" --live

# live: scan every server in an MCP client config
bastionsupply scan --config ~/.config/mcp.json --live

# rug-pull: pin tool hashes now, detect silent changes later
bastionsupply lock tools.json -o supply.lock
bastionsupply verify tools.json --lock supply.lock

# bridge: emit an agentbastion tool policy (default-deny, risky tools blocked)
bastionsupply harden tools.json -o policy.yaml

scan exits non-zero when anything critical or high is found — drop it in CI to fail a build that pulls in a poisoned server.

What it catches

check severity what it means
tool-poisoning critical tool description carries instructions aimed at the model, not a description of the tool
hidden-unicode critical zero-width / bidi-override / tag chars hiding text in a name or description
tool-shadowing high a tool's description talks about other tools — hijacking their behavior
secret-solicitation high a parameter asks the model to hand over an api_key / token / password
sensitive-capability high/med tool exposes exec, delete, network, secret-read, or privilege escalation
rug-pull (verify) — tool definitions changed since you pinned them

Library

from bastionsupply import load_json_file, scan, to_text, to_policy_yaml

report = scan(load_json_file("tools.json"))
print(to_text(report))
print("safe" if report.ok else "risky", report.risk)

Live fetch note

--stdio / --config --live spawn the server process to call tools/list. Only run them on servers you intend to execute. Offline scan tools.json never runs anything.

HTTP/SSE transport isn't implemented yet — stdio covers the common locally-installed case.

MIT.

Metadata

Release files for bastionsupply 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bastionsupply 0.1.0
File Size Uploaded
bastionsupply-0.1.0.tar.gz 15.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for bastionsupply 0.1.0
File Interpreter ABI Platform
bastionsupply-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 32.5 kB

Release files / bastionsupply-0.1.0.tar.gz

Download URL bastionsupply-0.1.0.tar.gz
Size 15.8 kB
Tags Source
SHA-256 checksum
How to use checksums
cc483b225037883fa632c9230d64f1042f3c17d4b5280267d93f07cd00b9cbd8
BLAKE2b-256 checksum
How to use checksums
00359b684f81646c34941bb9010fdf0c7382589d66d203dbb55a0e90908b4bc4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / bastionsupply-0.1.0-py3-none-any.whl

Download URL bastionsupply-0.1.0-py3-none-any.whl
Size 16.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e0d370a7804a71b7c228615339b31aff4ae55311956824340b5eb122d8d7d4c2
BLAKE2b-256 checksum
How to use checksums
2f22a20bc98569d4aff9b4ccdfd57438de96b51325b2869ddca3eefb15c70d62
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release history Release notifications | RSS feed

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page