mcp supply chain gate

    1

    Operationalize MCP server security with version-pinned registries, typosquat detection, and automated CI/CD gates.

    $14

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    mcp supply chain gate

    Example session with this skill installed

    Design a registry manifest for our approved MCP servers and generate a GitHub Actions config to block builds if the content hash for 'weather-provider-mcp' changes without a fresh audit.

    • Read your context and instructions
    • Compiled the mcp supply chain

    I have generated the mcp-registry.json schema including the content_hash and renewal_due fields. I also produced a GitHub Action .yml that runs a sha256sum check against your installed MCP servers and fails the build on any diff or lapsed audit date.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Design a cryptographically pinned registry for third-party MCP servers.Automate typosquatting and homoglyph detection for new server candidates.Implement CI/CD gates that block unvetted or stale MCP server updates.Sync internal approval states with live CVE and security advisory feeds.

    About this skill

    The problem

    One-time security audits of MCP servers expire the moment a new version ships or a new vulnerability is discovered. Manual tracking of approved server versions across a fleet is prone to human error, leaving orgs vulnerable to "MCPoison" style content swaps and typosquatting.

    What it does

    • Generates a registry manifest to track approved MCP servers by exact content hash, not just version strings.
    • Runs typosquatting and Unicode homoglyph checks on candidate servers to detect impersonation before auditing.
    • Builds CI/CD gates that block builds if an MCP server is unapproved, has a hash mismatch, or has a lapsed audit window.
    • Configures automated CVE feed subscriptions (OSV/GHSA/NVD) to trigger immediate re-audits when new vulnerabilities land.
    • Establishes a formal bypass protocol with second-party approval and grant-time alerting for emergency overrides.

    Frameworks & tools

    GitHub Actions, GitLab CI, MCP (Model Context Protocol), OSV.dev, GHSA, NVD, and agent-skill-security-scanner.

    Why this beats prompting it yourself

    Standard prompts often overlook that version strings can be spoofed without a version bump. This skill enforces a cryptographic content-hash registry and a dual-signal typosquat check that balances edit distance with popularity disparity, preventing the "theatrical security" of simple name matches.

    Use cases

    • Enforcing a "no unvetted code" policy for third-party MCP servers in production CI.
    • Detecting malicious homoglyph clones of popular MCP tools during developer intake.
    • Automating the re-audit cycle for a fleet of 50+ third-party agent skills.
    • Hardening agent environments against CVE-2025-54136 style trust-binding attacks.

    Known limitations

    This skill manages the registry and gate process but does not perform the code-level audit itself. It requires a content hash for exact pinning; name-only checks cannot detect novel malicious packages.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago
    Updated13 days ago

    What's inside

    Frequently Asked Questions