Back to Directory/Security & Auth

io.github.ai-supply-store/ai-supply

Search, install, publish & review security-scanned AI capabilities from ai-supply.store.

Security & Authv1.0.0

ai-supply — Claude Code plugin & MCP server

The marketplace for AI capabilities — discoverable by humans, operable by agents. Search, install, publish and review security-scanned skills, MCP servers, plugins, agents, datasets, guardrails and evals — without leaving your editor.

ai-supply.store · Browse the catalog · Agent API · listed on the MCP Registry as io.github.ai-supply-store/ai-supply


What is this?

ai-supply.store is a marketplace where AI capabilities are published, discovered, and installed — by people and by agents through a full API. Every uploaded or inline artifact is security-scanned, scored, and graded (heuristics + Opengrep/picklescan/gitleaks/osv, plus an OWASP-AI checklist) before it goes live, so what you install is vetted.

This repo gives your agent native access to all of it, two ways:

  1. Claude Code plugin — a slash-command + skill bundle wired to the MCP server.
  2. MCP server (ai-supply-mcp on npm) — works in any MCP client: Claude Desktop, VS Code / GitHub Copilot, Cursor.

Quick start

1. Get an API key

Create one at ai-supply.store/dashboard/api-keys and pick the scopes you want (read, install, publish, review, manage, account).

2a. Claude Code (this plugin)

/plugin marketplace add ai-supply-store/ai-supply-plugin
/plugin install ai-supply@ai-supply

Then set AIM_API_KEY in your environment. New commands: /ai-supply:search, /ai-supply:publish.

2b. Any MCP client (Claude Desktop · VS Code/Copilot · Cursor)

No install needed — npx runs it:

{
  "mcpServers": {
    "ai-supply": {
      "command": "npx",
      "args": ["-y", "ai-supply-mcp"],
      "env": { "AIM_API_KEY": "aim_your_key_here" }
    }
  }
}

VS Code / Copilot also surface it from the MCP Registry — search @mcp ai-supply in the Extensions view.

What your agent can do (19 tools)

whoami · list_categories · list_kinds · search_listings · get_listing · install_listing · purchase_listing · download_listing · review_listing · upload_artifact · publish_listing · update_listing · delete_listing · add_version · my_listings · list_community · post_community · accept_agreements · my_revenue

Full parity with the website — discover, install, download, publish, version, and review, all gated by your credential's scopes (and spend cap for purchases).

Why ai-supply

  • 🔒 Security-first — every listing is scanned, scored (0–100) and graded (A–D); critical findings quarantine a listing until fixed.
  • 🤖 Agent-native — a complete Agent API + MCP, not a scraped UI. The human verifies once; their agents inherit it.
  • 🌍 Open & free — a broad catalog of permissively-licensed OSS, free during launch.

Links

License

MIT

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y ai-supply-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-ai-supply-store-ai-supply": {
      "command": "npx",
      "args": [
        "-y",
        "ai-supply-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

ai-supply-mcpnpm

Compatible MCP Clients

io.github.ai-supply-store/ai-supply works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More