Supply chain security risk scorer for npm, PyPI, Cargo, and Go packages — behavioral signals that can't be faked. Exposes commitment data to AI models via the Model Context Protocol.
The server defines 8 tools with generally good naming (verb-noun structure) and comprehensive descriptions. However, there are significant gaps in schema completeness, parameter descriptions, and error handling guidance. All tool descriptions are substantive (100+ chars), exceeding baselines. Naming is clear and actionable. However, critical schema details are missing or inferred, most tools lack explicit parameter type declarations visible in the provided source, and output schemas are undocumented. Error handling provides no recovery guidance. The 'audit_dependencies' tool's input schema is vague (array items not specified). This is a C-range server: solid definitions with noticeable gaps in schema rigor and error patterns.
Batch risk audit for multiple npm/PyPI packages. Submit a list of package names and ecosystems to get commitment profiles and risk scores for all of them in a single request. Returns aggregated security risk signals across your dependency tree.
Search for a Norwegian business and get its commitment profile from public data (Brønnøysund Register Centre). Returns real commitment signals that can't be faked: Temporal commitment (how long the business has operated), Financial commitment (revenue, profitability, equity health), Operational commitment (employee count, active status), Overall commitment score (0-100). Data source: Norwegian government registers (Brreg). No user-contributed data needed — immediate trust verification for any Norwegian business.
Look up a specific Norwegian business by organization number and get its commitment profile from public data (Brønnøysund Register Centre). Returns real commitment signals: longevity, financial health, operational activity, and overall commitment score.
Get a behavioral commitment profile for any public GitHub repository. Returns real signals: how long the project has existed, recent commit frequency, contributor community size, release cadence, and social proof. These are behavioral commitments — harder to fake than README claims. Useful for: vetting open-source dependencies, evaluating AI tools/frameworks, assessing vendor reliability.
Input schemas lack explicit type declarations and detailed field descriptions. For example, 'lookup_business' shows maxResults with type 'number' and constraints (min/max), which is good, but other tools' parameters lack visible schema rigor. The 'audit_dependencies' tool's 'packages' parameter is declared as an array but the schema for array items (name, ecosystem) is not visible in the source snippet, preventing validation of structure.
No output schemas are documented. Tools return 'commitment profiles', 'commitment signals', and 'aggregated signals', but LLMs cannot plan downstream actions without knowing the exact structure (field names, types, nesting). For example, what fields does a 'commitment profile' contain? Is there a score field? How are results paginated?
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 66 | 2026-07-28+ | v2 |
Get a behavioral commitment profile for any public Go module. Returns real signals: how long the module has been maintained, recent commit frequency, contributor activity, release cadence, and GitHub repository health. Scoring is GitHub-primary (most Go modules live on GitHub).
Get a behavioral commitment profile for any public npm package. Returns real signals: how long the package has existed, recent release frequency, maintainer activity, download trends, and security history. These signals are harder to fake than package README claims.
Get a behavioral commitment profile for any public PyPI package. Returns real signals: how long the package has existed, recent release frequency, maintainer activity, download trends, and security history. These signals are harder to fake than package README claims.
Query verified behavioral commitment data for a domain. Returns aggregated signals: unique verified visitors, repeat visit rate, and average time spent. These prove real human engagement — harder to fake than reviews or content.
Error handling provides no recovery guidance. Descriptions mention 'commitment signals' and 'real engagement', but nowhere do they explain what happens on failure (e.g., domain not found, API timeout, business not in register). Errors should be actionable: 'Domain not found. Try searching with a different domain or check the domain exists.' Currently, an LLM hitting a 404 receives no guidance.
'audit_dependencies' tool combines batch evaluation across multiple ecosystems (npm/PyPI). While batching is good for efficiency, the input schema is underspecified. The 'packages' array should document the structure of each item (e.g., {name: string, ecosystem: 'npm'|'pypi'}) with enums and constraints. LLMs cannot infer valid structures from 'array of packages'.
Pagination and result limits are not mentioned. Tools like 'lookup_business' accept 'maxResults' (default 3), but other tools (e.g., 'query_commitment', 'lookup_github_repo') have no documented limit. Large result sets could blow context windows. Baseline best practice: cap results at 20-50 and support pagination.