Skip to main content

AI Supply Chain Security scanner — scan MCP servers, skill files, and agent configs for security risks

Project description

tanav

AI Supply Chain Security scanner. Scan MCP servers, skill files, Kiro specs, cursor rules, and agent configs for security risks — no account required, fully local.

29% of 2,500+ public MCP repos carry CRITICAL findings.

Install

# Run immediately with uvx (no install needed):
uvx tanav scan

# Or install permanently:
pip install tanav

Usage

# Scan all local AI client configs (Claude, Cursor, Windsurf)
uvx tanav scan

# Scan a specific GitHub repo
uvx tanav scan --repo https://github.com/Significant-Gravitas/AutoGPT

# Scan an npm package
uvx tanav scan --repo @upstash/context7-mcp

# JSON output for piping
uvx tanav scan --repo https://github.com/org/repo --json | jq .

# SARIF output for GitHub Security tab
uvx tanav scan --repo https://github.com/org/repo --sarif > results.sarif

# CI gate — exit 1 if CRITICAL found
uvx tanav scan --repo https://github.com/org/repo --fail-on-critical

What it scans

  • MCP server source code and dependencies
  • SKILL.md files and Claude skill configurations
  • Kiro steering files (.kiro/steering/)
  • Cursor rules (.cursorrules, .cursor/rules/)
  • Copilot instructions (.github/copilot-instructions.md)
  • Claude hooks, agent configs, plugin manifests
  • Local configs: ~/.claude/, ~/.cursor/, ~/.config/windsurf/

Risk levels

Verdict Score Meaning
✗ BLOCK ≥ 80 Critical findings — do not connect
⚠ REVIEW 55–79 High findings — investigate before use
✓ SAFE < 55 No significant findings

Registry

2,500+ public MCP repos pre-scored at aiss.dev/registry

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

tanav-0.1.2.tar.gz (175.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

tanav-0.1.2-py3-none-any.whl (195.5 kB view details)

Uploaded Python 3

File details

Details for the file tanav-0.1.2.tar.gz.

File metadata

  • Download URL: tanav-0.1.2.tar.gz
  • Upload date:
  • Size: 175.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for tanav-0.1.2.tar.gz
Algorithm Hash digest
SHA256 71be89093ecb5ba57b43646ff45b090767d6da03f7fbe46d090e71c2f5b7730e
MD5 1ee2a0b0e88232eac3a7b6136b4895aa
BLAKE2b-256 2bcc299dc54adc108c6b6d56ffe814560a330a709214b508bf12c0b9946ca5d0

See more details on using hashes here.

File details

Details for the file tanav-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: tanav-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 195.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for tanav-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 cb482ae46ed4d0e045619657adf1160cb7706643e6b52f84605392186a3cc38c
MD5 6f1f6798938dec5c398ffcc48ece2f04
BLAKE2b-256 455cf928ef3ae57dfdcbcd33ffccc60312263782862dc1d0e9c8f0611c4a2dd2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page