Developer · Remote MCP server
Repo Security Scanner — Malicious Code & Supply Chain
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Visit Repo Security Scanner — Malicious Code & Supply Chain's website
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.eltociear/repo-security-scanner- Version
- 0.1.0
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP
- Published
- 2026-08-15
- Updated
- 2026-08-15
- Publisher
- eltociear (GitHub) · 6 servers with pages here
- Listed under
- GitHub MCP servers
- Website
- apify.com/eltociear/mcp-server-security-scanner
- Repository
- github.com/eltociear/my-molt-agent
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner | Authorization (required, secret) |
How to connect Repo Security Scanner — Malicious Code & Supply Chain
Repo Security Scanner — Malicious Code & Supply Chain is a remote MCP server: there is nothing to install. Its endpoint is https://mcp.apify.com/?actors=eltociear/mcp-server-security-scanner, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
The registry entry declares an HTTP header for the connection: Authorization (required, secret). A secret header usually carries an API key or token issued by the service; clients that accept custom headers set it with the server's URL.
Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from eltociear (GitHub)
| Server | Runs |
|---|---|
| Contract Guard MCPEVM contract/token risk check + ERC20 approval (proxy, EIP-7702, unlimited-allowance). Zero deps. | Local · stdio |
| Secrets Audit MCPDetects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps. | Local · stdio |
| Skill Audit MCPMCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns. | Remote & Local · HTTP, stdio |
| Tokenguard MCPReal-world data for agents: air quality, geocoding, quakes, holidays, web search. | Remote · HTTP |
| URL to Clean Markdown for LLMs & RAGFetch URLs and return clean Markdown for RAG — nav, ads and boilerplate stripped. | Remote · HTTP |
More developer servers
| Server | Runs |
|---|---|
| Replit SSHRead, write, list, and check files on Replit projects over SSH/SFTP, plus SSH key setup. | Local · stdio |
| Repo Forensics MCPLocal read-only MCP tools for Git repository archaeology, churn, hotspots, and hygiene. Tools... | Local · stdio |
| Repo MemoryShared, git-tracked working memory for AI agents on the same codebase. | Local · stdio |
| Repo Release ToolsConfig-driven branch and release helpers for Git repositories. | Local · stdio |
| repo-memory-mcpPersistent local memory for MCP-compatible AI coding agents, stored per repository in SQLite. | Local · stdio |
| RepoContextRead-only, commit-pinned repository context for coding agents. | Local · stdio |
| repoctxLocal-first code context, impact analysis, and merge-readiness verdicts for AI agents. | Local · stdio |
| RepoFuseDiscover and scaffold new apps by reusing code from your GitHub repositories. | Remote · HTTP |