Browse
→ Infrastructure
→ bastionsupply
bastionsupply
Offline MCP supply-chain security scanner for preflight inspection of MCP servers. It scans tool definitions for tool poisoning, tool shadowing, hidden Unicode, secret solicitation, dangerous capabilities, and rug-pull drift, can live-scan stdio servers or client configs, and emits hardened agentbastion policy. Public GitHub repository created September 14, 2026.
MCP unverified
Integration
| Transport | stdio |
| Auth | none |
| Endpoint | bastionsupply scan --stdio |
| Install | pip install bastionsupply |
Use Cases
| 01 | Scan a tools/list JSON dump before trusting an MCP server |
| 02 | Spawn a stdio MCP server and inspect the live tool descriptions it advertises before installation |
| 03 | Pin tool definition hashes and detect rug-pull drift or generate a default-deny tool policy |
Tags
mcp-security supply-chain tool-poisoning hidden-unicode secret-solicitation policy offline python
Machine-readable: /api/servers.json
· JSON-LD schema embedded in <head>