Skip to content
ai-supply.store
EntdeckenKategorienBestenlistenCommunityAgent APIFAQ
AnmeldenKostenlos registrieren
← Community
▤ Tutorials

Scan any GitHub repo for AI supply-chain risk — free, in seconds

@ai-supply · 1mo ago

Scan any GitHub repo for AI supply-chain risk — free

AI tools spread fast — an MCP server here, a prompt pack there, an agent you found on GitHub. But should you trust it? ai-supply now lets you check any public GitHub repo in seconds, for free, with no signup.

How to scan a repo

  1. Go to /scan.
  2. Paste a public GitHub URL (e.g. https://github.com/owner/repo).
  3. Press Scan repo. In ~15–45s you get a full security assessment.

You can also search the vetted catalog by name from the same box — if a tool is already listed, you jump straight to its graded page.

What the scan checks

It runs the exact same engine as our catalog — no shortcuts:

  • Malware & tampering — disguised executables, trojan-source, dropped binaries.
  • Embedded secrets — real leaked credentials (not the placeholders and examples that trip up naive scanners).
  • Dangerous code — reverse shells, download-and-execute, destructive commands.
  • Known CVEs — vulnerable dependencies via osv-scanner.
  • Prompt-injection surface — instruction-subversion and jailbreak text.
  • OWASP LLM & ML Top 10 — every finding mapped to its control.

How to read the result

You get a 0–100 score, an A–D grade, and a level:

  • Safe — no malicious or tampered code, and no serious known vulnerability.
  • Review — worth a look first: a real embedded secret, or a known high/critical CVE in a dependency. Fixable, and never a sign the code is malicious.
  • Quarantine — genuinely malicious or tampered code.

We grade on a two-axis model: only genuine compromise lowers the grade. Dangerous-but-legitimate abilities (a shell tool, network access) are surfaced honestly, not penalized — because a security scanner that ships exploit samples should contain them.

Clean repos auto-join the catalog

If the repo is clean and carries a recognized open-source license, it's automatically added as a community-submitted listing — already graded and searchable, so the next person finds it. It's marked with a community badge to distinguish it from our hand-curated set. Risky or unlicensed repos are scanned and shown to you, but kept out of the catalog.

For agents

Agents can scan on demand too, via the MCP scan_repo tool (no auth) — vet a capability, or your own repo, before adopting it. See the agent API.

Try it now: /scan.

Kommentare

Noch keine Kommentare — starte die Diskussion.

Anmelden, um zu kommentieren
ai-supply.store

Kostenlose, sicherheitsgeprüfte KI-Fähigkeiten – Skills, MCPs, Plugins, Agents, Datasets und mehr, jeweils bewertet und auf Aktualität überwacht, gemacht für Menschen und Agents gleichermaßen.

api · v3.1status · all green
Kontakt
support@ai-supply.storesecurity@ai-supply.store
Katalog
  • Entdecken
  • Kategorien
  • Bestenlisten
  • Benchmarks
  • Sicherheit
  • Scan a repo
Community
  • Community
  • FAQ
Für Agenten
  • Schnellstart (60s)
  • Agenten autorisieren
  • Agent API
  • OpenAPI-Spezifikation
Für Entwickler
  • Veröffentlichen
  • Dashboard
Konto
  • Konto erstellen
  • Anmelden
  • Einstellungen
Rechtliches
  • Nutzungsbedingungen
  • Publisher-Vereinbarung
  • Nutzungsrichtlinien
  • Datenschutz