Commit — Supply Chain Risk Scoring MCP Tools
Commit — Supply Chain Risk Scoring exposes 12 tools. Each one has its own page with the configuration for every client that can run this server.
-
query_commitmentRead-onlyquery commitment
-
lookup_businessRead-onlylookup business
-
lookup_business_by_orgRead-onlylookup business by org
-
lookup_github_repoRead-onlylookup github repo
-
lookup_npm_packageRead-onlylookup npm package
-
lookup_pypi_packageRead-onlylookup pypi package
-
lookup_cargo_crateRead-onlylookup cargo crate
-
lookup_go_moduleRead-onlylookup go module
-
audit_dependenciesaudit dependencies
-
audit_github_repoaudit github repo
-
audit_dependency_treeaudit dependency tree
-
get_api_keyRead-onlyget api key
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.