Local-first supply-chain CVE scanner. Scans project deps, system packages (Homebrew/apt), and IDE extensions (VS Code, JetBrains) via OSV, NVD, GHSA, EPSS, and CISA KEV. Listed in the official MCP Registry as io.github.DevInder1/tridentchain-security.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.NVD_API_KEY— Power-user Add GITHUB_TOKEN, , optional SONATYPE_TOKEN for best coverage.GITHUB_TOKEN— Power-user Add , NVD_API_KEY, optional SONATYPE_TOKEN for best coverage.SONATYPE_TOKEN— Power-user Add GITHUB_TOKEN, NVD_API_KEY, optional for best coverage.[](https://m8ven.ai/mcp/devinder1-supply-chain-scanner-public-2htrn2)