Supply-Chain Audit
Intro
Use /pk-supply-chain when you need a release-facing supply-chain view.
The MCP server exposes three tools:
discover_manifestsrun_supply_chain_auditexport_supply_chain_sbom
Network-dependent security and quality probes are intentionally off by default. Enable them only when explicitly requested.
Overview
- Discover dependency manifests and supported lockfiles.
- Run
run_supply_chain_auditwith explicitrun_security_checks/run_quality_checkswhen required. - Export SBOM when release evidence is needed.
Gotchas
- Offline default. Missing network adapters must be explicit, not implicit.
- Discover-only checks are not guarantees. Discovery does not confirm policy.
- Export output. Persist SBOM/report output only when
write_output=True.
Full reference
discover_manifests
project_root: str | None = Nonemanifest_globs: list[str] | None = Noneinclude_vendor_dir: bool = Trueinclude_ci_manifests: bool = False
run_supply_chain_audit
project_root: str | None = Nonemanifest_paths: list[str] | None = Nonerun_security_checks: bool = Falserun_quality_checks: bool = Falsenetwork_enabled: bool = Falsewrite_output: bool = Falseoutput_path: str | None = None
export_supply_chain_sbom
project_root: str | None = Nonemanifest_paths: list[str] | None = Noneformat: str = "json"write_output: bool = Falseoutput_path: str | None = None