Secure Chain
Secure Chain MCP server provides tools for checking software supply chain security status by integrating with vulnerability databases and dependency graphs. Built with FastAPI and Python, it offers five core tools: package and version status checking across multiple package managers (PyPI, NPM, Maven, Cargo, RubyGems, NuGet), vulnerability lookup by ID, exploit information retrieval, and CWE (Common Weakness Enumeration) details. The implementation uses MongoDB for vulnerability data storage, Neo4j for dependency graph analysis, and includes session management with JWT authentication for secure access to the Secure Chain platform. Designed for developers and security teams who need programmatic access to supply chain risk assessment, enabling use cases like automated vulnerability scanning, dependency analysis, and security reporting without manual platform interaction.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve Secure Chain from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.