Enter a repo URL or paste a dependency file. Scores every dependency on behavioral signals — publisher depth, release consistency, project longevity. Flags the packages that match real supply chain attack profiles.
Prefers lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) for transitive deps;
falls back to package.json, requirements.txt, Cargo.toml, go.mod.
Monorepos: paste the subdirectory URL. Public repos only. How scores work →
Scanning packages…
| Package | Score | Risk | Maintainers | Weekly DL | Age | Trend |
|---|
Get this in your AI assistant
{
"mcpServers": {
"commit": {
"type": "streamable-http",
"url": "https://poc-backend.amdal-dev.workers.dev/mcp"
}
}
} Add to Claude Desktop or Cursor. Then: "Audit my package.json for supply chain risk"