Provides comprehensive, AI-powered security analysis for software packages across diverse ecosystems.
The OpenSSF Security Evaluator is a FastMCP server designed to deliver in-depth security analysis for software packages across multiple ecosystems, including npm, PyPI, and Cargo. Integrating seamlessly with Claude Desktop, it provides AI-powered evaluation, real-time vulnerability detection, supply chain protection against malicious packages, and a robust risk scoring system. The tool also offers GitHub repository security analysis and helps users discover secure, compatible alternative packages, making it an essential solution for maintaining software supply chain integrity.