Skip to content
ai-supply.store
探索分类排行榜社区Agent APIFAQ
登录免费注册
← Community
▤ Tutorials

Scan any GitHub repo for AI supply-chain risk — free, in seconds

@ai-supply · 1mo ago

Scan any GitHub repo for AI supply-chain risk — free

AI tools spread fast — an MCP server here, a prompt pack there, an agent you found on GitHub. But should you trust it? ai-supply now lets you check any public GitHub repo in seconds, for free, with no signup.

How to scan a repo

  1. Go to /scan.
  2. Paste a public GitHub URL (e.g. https://github.com/owner/repo).
  3. Press Scan repo. In ~15–45s you get a full security assessment.

You can also search the vetted catalog by name from the same box — if a tool is already listed, you jump straight to its graded page.

What the scan checks

It runs the exact same engine as our catalog — no shortcuts:

  • Malware & tampering — disguised executables, trojan-source, dropped binaries.
  • Embedded secrets — real leaked credentials (not the placeholders and examples that trip up naive scanners).
  • Dangerous code — reverse shells, download-and-execute, destructive commands.
  • Known CVEs — vulnerable dependencies via osv-scanner.
  • Prompt-injection surface — instruction-subversion and jailbreak text.
  • OWASP LLM & ML Top 10 — every finding mapped to its control.

How to read the result

You get a 0–100 score, an A–D grade, and a level:

  • Safe — no malicious or tampered code, and no serious known vulnerability.
  • Review — worth a look first: a real embedded secret, or a known high/critical CVE in a dependency. Fixable, and never a sign the code is malicious.
  • Quarantine — genuinely malicious or tampered code.

We grade on a two-axis model: only genuine compromise lowers the grade. Dangerous-but-legitimate abilities (a shell tool, network access) are surfaced honestly, not penalized — because a security scanner that ships exploit samples should contain them.

Clean repos auto-join the catalog

If the repo is clean and carries a recognized open-source license, it's automatically added as a community-submitted listing — already graded and searchable, so the next person finds it. It's marked with a community badge to distinguish it from our hand-curated set. Risky or unlicensed repos are scanned and shown to you, but kept out of the catalog.

For agents

Agents can scan on demand too, via the MCP scan_repo tool (no auth) — vet a capability, or your own repo, before adopting it. See the agent API.

Try it now: /scan.

评论

暂无评论——开启讨论吧。

登录后评论
ai-supply.store

免费、经过安全审核的 AI 能力——技能、MCP、插件、agent、数据集等一应俱全,每一项都经过安全评级与时效追踪,为人类与 agent 共同打造。

api · v3.1status · all green
联系
support@ai-supply.storesecurity@ai-supply.store
目录
  • 探索
  • 分类
  • 排行榜
  • 基准测试
  • 安全
  • Scan a repo
社区
  • 社区
  • FAQ
面向智能体
  • 快速入门 (60s)
  • 授权智能体
  • Agent API
  • OpenAPI 规范
面向开发者
  • 发布
  • 控制台
账户
  • 创建账户
  • 登录
  • 设置
法律条款
  • 条款
  • 发布者协议
  • 可接受使用政策
  • 隐私政策