{"uid":"cap_uGH855ZvJAJlA5KXMgfsV","slug":"agentaegis-mcp-plugin-supply-chain-trust-scanner-fa23c23b","name":"AgentAegis MCP Plugin Supply-Chain Trust Scanner","description":"AgentAegis scan_mcp_plugin — supply-chain trust scan of an MCP server or agent skill BEFORE you install/trust it. Clones a git repo (or takes a code snippet) and flags exfiltration (secrets/env to the network), prompt-injection sinks (hijack phrases + hidden unicode), dangerous capabilities (eval/shell/dynamic exec), npm install hooks, and obfuscation → one PROCEED/CAUTION/BLOCK verdict with findings.","url":"https://agentaegis-mcp-production.up.railway.app/x402/scan-mcp-plugin","method":"POST","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"5","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$5/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"5","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Cy-uZ2-ktBTtyzN9wcaVc","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"5","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a supply-chain security scan of an MCP server or agent skill (via git repo or code snippet) and returns a PROCEED/CAUTION/BLOCK verdict with categorized findings.","exampleAgentPrompt":"Before I install this MCP server from https://github.com/someuser/some-mcp-plugin, run an AgentAegis supply-chain scan on it and tell me whether I should PROCEED, use with CAUTION, or BLOCK it — and flag any exfiltration, prompt injection, or dangerous capabilities you find.","exampleUseCases":null,"resultDescription":"Returns a verdict string (PROCEED, CAUTION, or BLOCK), a numeric trust score (0–100), a summary object with counts of exfiltration, prompt_injection, and dangerous_capabilities findings, and an array of human-readable reason strings explaining each flagged issue.","failureModes":["Git repo clone fails due to invalid URL or private repo without credentials — likely returns error with no verdict","Code snippet too large or malformed — may return parse error","Rate limit or payment verification failure for the $5 USDC x402 charge — returns 402 or payment error","Scan timeout on very large repositories — may return partial results or timeout error","Unsupported language or package manager — findings may be incomplete"],"whenToPreferThis":"Use this endpoint when an AI agent or developer needs to vet an MCP plugin or agent skill for supply-chain risks before installation or trust delegation — especially when you need a single authoritative PROCEED/CAUTION/BLOCK verdict covering exfiltration, prompt injection, dangerous capabilities, and obfuscation in one call. Prefer this over generic code scanners because it is purpose-built for the MCP/agent-skill threat model including hidden unicode and prompt-hijack detection.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:39:44.939Z","isFirstParty":false}