
Research
/Security News
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.
@complyedge/mcp
Advanced tools
Offline MCP compliance checks for EU AI Act and related rules: prompt scans, rule discovery, and article-cited findings.
Run offline TrustLint checks from any MCP host with Node.js:
{
"complyedge": {
"command": "npx",
"args": ["-y", "@complyedge/mcp"]
}
}
The server exposes three read-only tools.
| Tool | Returns | Notes |
|---|---|---|
check_compliance | PASS / FAIL with cited findings | Checks already-produced text. Optional jurisdiction: EU, US, GLOBAL |
scan_prompt | SAFE / RISK_DETECTED | Checks a candidate prompt before it is sent to a model |
list_rules | Rule inventory | Discovery only — does not evaluate text |
@complyedge/sdk for
POST /v1/check and the Article 12 audit trail.@complyedge/sdk — hosted runtime enforcement and the Article 12 audit trailtrustlint — the same offline engine as a CLIcomplyedge on PyPI — Python MCP server, published under this same registry entrytrustlint on PyPI — Python linterFAQs
Offline MCP compliance checks for EU AI Act and related rules: prompt scans, rule discovery, and article-cited findings.
The npm package @complyedge/mcp receives a total of 298 weekly downloads. As such, @complyedge/mcp popularity was classified as not popular.
We found that @complyedge/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.