Commit — Supply Chain Risk Scoring MCP Server
by piiiicoio.github.piiiico/proof-of-commitmentv1.36.0
Supply chain risk scoring for npm, PyPI, Cargo and Go packages from behavioral signals: publisher depth, release consistency and maintenance patterns.
context tax
queued
security
queued
cold start
queued
freshness
Active4d ago
Install Commit — Supply Chain Risk Scoring MCP server
Install in Claude Code
claude mcp add proof-of-commitment -- npx -y proof-of-commitmentInstall in Cursor
{
"mcpServers": {
"proof-of-commitment": {
"command": "npx",
"args": [
"-y",
"proof-of-commitment"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"proof-of-commitment": {
"command": "npx",
"args": [
"-y",
"proof-of-commitment"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"proof-of-commitment": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"proof-of-commitment"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"proof-of-commitment": {
"command": "npx",
"args": [
"-y",
"proof-of-commitment"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Remote endpoints
- streamable-http
https://poc-backend.amdal-dev.workers.dev/mcp
Freshness
Active — last maintenance signal 4d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-06 · 4d ago · GitHub
Latest release
2026-06-13 · 4mo ago · GitHub · v1.31.1
Package published
no data · npm/PyPI
Registry entry updated
2026-06-20 · 4mo ago · official registry · v1.36.0
FAQ
›How do I install the Commit — Supply Chain Risk Scoring MCP server in Claude Code?
Run: claude mcp add proof-of-commitment -- npx -y proof-of-commitment. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Commit — Supply Chain Risk Scoring require an API key?
No required environment variables are declared in its published metadata.
›Can I use Commit — Supply Chain Risk Scoring as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Commit — Supply Chain Risk Scoring in the official MCP registry?
Yes, as io.github.piiiico/proof-of-commitment.
Alternatives to Commit — Supply Chain Risk Scoring
Other security MCP servers.