Tripwire Scans AI Skills and MCP Servers in a Sandboxed Security Platform
Summary
Tripwire is an early-adopter security platform for assessing AI skills and MCP servers before teams use or share them. Its Node.js CLI discovers targets, then runs enabled scanner adapters in an isolated Modal sandbox and stores scan runs and findings in Supabase for a Live or Mock dashboard. The project integrates Cisco Skill/MCP Scanner, Snyk agent scanning, Tessl quality and security checks, DepShield dependency auditing through OSV.dev, and Ossprey malware scanning. Missing credentials cause supported scanners to report skipped or setup-required states rather than presenting an apparently complete scan; DepShield can run without credentials, while Ossprey requires its API key. An optional routing stage sends findings through Superlinked SIE and can escalate cases to Alibaba Cloud Model Studio when coverage is incomplete or scanners disagree. Live use requires Supabase, Modal, the CLI, and configuration for the desired scanners; the project describes setup as hands-on and expects users to interpret findings. A hosted or local Mock dashboard provides sample data without cloud accounts, and a dry-discover command can validate target discovery locally without running a scan.