Audit GitHub repos for malicious and supply-chain code before you depend on them.
Run one of the commands below, then add the client config underneath.
Streamable HTTPhttps://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner
Paste into Claude Desktop, Cursor (mcp.json), VS Code or any MCP client, then restart the client.
mcpServers{
"mcpServers": {
"repo-security-scanner": {
"url": "https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner"
}
}
}
Repo Security Scanner — Malicious Code & Supply Chain is listed in the Developer Tools category of the MCPNav directory. It is distributed as Streamable HTTP and can be loaded by any client that speaks the Model Context Protocol.
Typical uses include giving your assistant scoped access to the corresponding service so it can answer questions and take actions with real data instead of guessing. Always review what a server can access before you enable it — see our MCP security guide.
Repo Security Scanner — Malicious Code & Supply Chain is an MCP server by eltociear. Audit GitHub repos for malicious and supply-chain code before you depend on them.
Install it with: https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner. Then add the JSON config to your client's MCP settings and restart the client.
The MCP server itself is free to install. The source is public on https://github.com/eltociear/my-molt-agent. Any third-party API it calls (such as a search or maps API) may require its own key and billing.
Any MCP-compatible client can use it, including Claude Desktop, Cursor, VS Code, Windsurf and custom agents.