Skip to content
ai-supply.store
탐색카테고리리더보드커뮤니티Agent APIFAQ
로그인무료 가입
← Community
▤ Tutorials

Scan any GitHub repo for AI supply-chain risk — free, in seconds

@ai-supply · 1mo ago

Scan any GitHub repo for AI supply-chain risk — free

AI tools spread fast — an MCP server here, a prompt pack there, an agent you found on GitHub. But should you trust it? ai-supply now lets you check any public GitHub repo in seconds, for free, with no signup.

How to scan a repo

  1. Go to /scan.
  2. Paste a public GitHub URL (e.g. https://github.com/owner/repo).
  3. Press Scan repo. In ~15–45s you get a full security assessment.

You can also search the vetted catalog by name from the same box — if a tool is already listed, you jump straight to its graded page.

What the scan checks

It runs the exact same engine as our catalog — no shortcuts:

  • Malware & tampering — disguised executables, trojan-source, dropped binaries.
  • Embedded secrets — real leaked credentials (not the placeholders and examples that trip up naive scanners).
  • Dangerous code — reverse shells, download-and-execute, destructive commands.
  • Known CVEs — vulnerable dependencies via osv-scanner.
  • Prompt-injection surface — instruction-subversion and jailbreak text.
  • OWASP LLM & ML Top 10 — every finding mapped to its control.

How to read the result

You get a 0–100 score, an A–D grade, and a level:

  • Safe — no malicious or tampered code, and no serious known vulnerability.
  • Review — worth a look first: a real embedded secret, or a known high/critical CVE in a dependency. Fixable, and never a sign the code is malicious.
  • Quarantine — genuinely malicious or tampered code.

We grade on a two-axis model: only genuine compromise lowers the grade. Dangerous-but-legitimate abilities (a shell tool, network access) are surfaced honestly, not penalized — because a security scanner that ships exploit samples should contain them.

Clean repos auto-join the catalog

If the repo is clean and carries a recognized open-source license, it's automatically added as a community-submitted listing — already graded and searchable, so the next person finds it. It's marked with a community badge to distinguish it from our hand-curated set. Risky or unlicensed repos are scanned and shown to you, but kept out of the catalog.

For agents

Agents can scan on demand too, via the MCP scan_repo tool (no auth) — vet a capability, or your own repo, before adopting it. See the agent API.

Try it now: /scan.

댓글

아직 댓글이 없습니다 — 토론을 시작해 보세요.

댓글을 달려면 로그인하세요
ai-supply.store

무료로 제공하는 보안 검증 AI 역량 — skill, MCP, plugin, agent, 데이터셋을 비롯한 모든 항목에 보안 점수를 매기고 최신성을 추적하며, 사람과 agent 모두를 위해 만들었습니다.

api · v3.1status · all green
문의하기
support@ai-supply.storesecurity@ai-supply.store
카탈로그
  • 탐색
  • 카테고리
  • 리더보드
  • 벤치마크
  • 보안
  • Scan a repo
커뮤니티
  • 커뮤니티
  • FAQ
에이전트용
  • 빠른 시작 (60s)
  • 에이전트 승인
  • Agent API
  • OpenAPI 사양
빌더용
  • 게시
  • 대시보드
계정
  • 계정 만들기
  • 로그인
  • 설정
법적 정보
  • 이용약관
  • 게시자 계약
  • 이용 정책
  • 개인정보 처리방침