# supership-scan

> Use this tool when you need to identify security vulnerabilities in AI-generated code before deployment. The supership-scan tool scans for 80+ vulnerability patterns, including secrets, auth, and injection issues, and runs locally to ensure code privacy. It provides optional x402 witnessed attestation and supports various platforms, including Supabase, to help you secure your code and prevent potential threats.

Canonical page: https://skillsregistry.net/skills/andysalvo-supership-scan  
JSON: https://api.skillsregistry.net/v1/skills/andysalvo-supership-scan

## Description

Predeploy security scanner for AI-generated code. 80+ vulnerability patterns across secrets, auth, injection, config, Supabase, and logging. Runs locally, code never leaves your machine. Optional x402 witnessed attestation.

## Trust

- **Trust score (0–1):** 0.60
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-06-12

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/wfkshpy7xb)
- **Repository:** <https://github.com/andysalvo/supership-scan>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "andysalvo-supership-scan"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/andysalvo-supership-scan` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/andysalvo-supership-scan/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
