piiiico/proof-of-commitment
Behavioral supply chain risk scoring for npm, PyPI, Cargo, and Go. Scores packages 0–100 on publisher concentration, release consistency, longevity, and OpenSSF Scorecard. Flags sole-publisher packages with high download counts — the attack profile behind LiteLLM and axios compromises. 11 MCP tools via remote Streamable HTTP. Also: CLI (`npx proof-of-commitment`), REST API, GitHub Action, Cursor + Claude Code hooks.
Browse this MCP server in the TensorBlock MCP Index.