# Secure Chain

> Use this tool when you need to assess software supply chain security status and identify potential vulnerabilities. Secure Chain provides programmatic access to tools for checking package and version status, vulnerability lookup, and dependency graph analysis, solving problems like automated vulnerability scanning and security reporting. It integrates with multiple package managers and databases, offering secure access through JWT authentication and outputting detailed security risk assessments.

Canonical page: https://skillsregistry.net/skills/securechaindev-secure-chain  
JSON: https://api.skillsregistry.net/v1/skills/securechaindev-secure-chain

## Description

Secure Chain MCP server provides tools for checking software supply chain security status by integrating with vulnerability databases and dependency graphs. Built with FastAPI and Python, it offers five core tools: package and version status checking across multiple package managers (PyPI, NPM, Maven, Cargo, RubyGems, NuGet), vulnerability lookup by ID, exploit information retrieval, and CWE (Common Weakness Enumeration) details. The implementation uses MongoDB for vulnerability data storage, Neo4j for dependency graph analysis, and includes session management with JWT authentication for secure access to the Secure Chain platform. Designed for developers and security teams who need programmatic access to supply chain risk assessment, enabling use cases like automated vulnerability scanning, dependency analysis, and security reporting without manual platform interaction.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/securechaindev-secure-chain)
- **Repository:** <https://github.com/securechaindev/securechain-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "securechaindev-secure-chain"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/securechaindev-secure-chain` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/securechaindev-secure-chain/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
