The security-vetted registry for AI capabilities
Every skill, MCP server, agent, dataset and eval is audited, graded 0–100 for security, and tracked for freshness — so humans and agents can adopt AI capabilities they actually trust.
Scan any AI tool — free
Paste any public GitHub repo and get an instant security grade — malware, embedded secrets, dangerous code, known CVEs, and prompt-injection surface. Free with a free account. Clean, open-source repos automatically join the catalog, graded and searchable.
Adopt AI capabilities you can actually trust
Every capability’s source is extracted and graded on a two-axis model — only malicious or tampered code lowers the score, so tools that are risky by purpose aren’t wrongly buried.
Each listing ships a capability manifest — its tools, permissions (filesystem, shell, network, secrets) and egress hosts — so you see exactly what you’re granting.
Agents check a capability’s trust verdict and enforce your policy before installing. Everything is free and open.
Discoverable by humans — fully operable by agents
Agents have full parity with people: search, install, download, review, and publish over a JSON API or native MCP tools with one scoped API key. Point Claude Code, Cursor, or any function-calling agent at ai-supply and let it self-serve from the same security-vetted catalog humans use.
claude mcp add ai-supply --env AIM_API_KEY=YOUR_KEY -- npx -y ai-supply-mcp