# PatchProof MCP

> Use this tool when you need to inspect and secure your local npm supply chain, identifying potential vulnerabilities and generating reports to ensure the integrity of your dependencies. It solves problems related to dependency management, vulnerability auditing, and compliance reporting through repository scanning and SBOM generation. The tool takes in local npm repositories as input and outputs detailed reports and evidence, making it ideal for use cases where offline, deterministic analysis is required.

Canonical page: https://skillsregistry.net/skills/eaglebooth-patchproof-mcp  
JSON: https://api.skillsregistry.net/v1/skills/eaglebooth-patchproof-mcp

## Description

Enables local npm supply-chain inspection through tools for repository scanning, SBOM generation, dependency audit, and evidence reporting. Uses deterministic mock data and does not query live APIs.

## Trust

- **Trust score (0–1):** 0.68
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** data-analytics
- **Updated:** 2026-09-01

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/tm62k4tclj)
- **Repository:** <https://github.com/eaglebooth/patchproof-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "eaglebooth-patchproof-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/eaglebooth-patchproof-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/eaglebooth-patchproof-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
