PluginBench
MCP Server

Repo Security Scanner — Malicious Code & Supply Chain MCP Server

io.github.eltociear/repo-security-scanner

What is the Repo Security Scanner — Malicious Code & Supply Chain MCP server?

Audit GitHub repos for malicious and supply-chain code before you depend on them.

How to install Repo Security Scanner — Malicious Code & Supply Chain

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • Authorization
    required
    secret

    Apify API token, sent as `Bearer <token>`. The endpoint answers 401 without one. Runs are billed to YOUR Apify account at this Actor's pay-per-event price — there is no free tier here and no charge to us.

~/.cursor/mcp.json
{
  "mcpServers": {
    "repo-security-scanner": {
      "url": "https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner"
    }
  }
}

Related MCP servers

Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.

1
Python
MIT
View repository →

MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.

4
Python
View repository →

Real-world data for agents: air quality, geocoding, quakes, holidays, web search

1
JavaScript
View repository →

Fetch URLs and return clean Markdown for RAG — nav, ads and boilerplate stripped.

View repository →

Zero-dependency verifiable-claims MCP: validate safely, verify with allow_execution, self-test.

0
HTML
MIT
View repository →

MCP server for the Fail Modes taxonomy — a knowledge base of AI system failure modes

0
JavaScript
MIT
View repository →