The OpenSSF Security Evaluator is a FastMCP server designed to deliver in-depth security analysis for software packages across multiple ecosystems, including npm, PyPI, and Cargo. Integrating seamlessly with Claude Desktop, it provides AI-powered evaluation, real-time vulnerability detection, supply chain protection against malicious packages, and a robust risk scoring system. The tool also offers GitHub repository security analysis and helps users discover secure, compatible alternative packages, making it an essential solution for maintaining software supply chain integrity.
Key Features
010 GitHub stars
02AI-powered discovery of alternative packages with license compatibility
03Real-time vulnerability detection via OSV.dev
04Supply chain protection against typosquatting and malicious packages
05Comprehensive 0-100 security risk scoring
06GitHub repository health and maintenance metrics