# mcp-supply-guard

> mcp-supply-guard — wwb-bill-mcp-supply-guard. Use this tool when you need to ensure supply-chain integrity for MCP tools by locking and monitoring tool definitions. It solves problems related to unauthorized or malicious changes to tool definitions by detecting added, removed, modified, or risky definitions. It takes tool definitions as input and outputs alerts and notifications for any detected changes or risks.

Canonical page: https://skillsregistry.net/skills/wwb-bill-mcp-supply-guard  
JSON: https://api.skillsregistry.net/v1/skills/wwb-bill-mcp-supply-guard

## Description

Enables supply-chain integrity for MCP tools by locking tool-definition hashes after review and detecting added, removed, modified, or risky tool definitions.

## Trust

- **Trust score (0–1):** 0.70
- **Verification tier:** verified
- **Last scanned:** 2026-09-03

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-09-03

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/osz7z10f4o)
- **Repository:** <https://github.com/wwb-bill/mcp-supply-guard>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "wwb-bill-mcp-supply-guard"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/wwb-bill-mcp-supply-guard` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/wwb-bill-mcp-supply-guard/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
