Skip to main content
Glama

brandguard 🛡️

Brand impersonation & typosquat monitor for AI agents and brand owners.

Feed brandguard a brand or product name and it scans npm, PyPI and GitHub for packages and repos that typosquat or impersonate you — each risk-scored — plus a ready-to-review takedown / trademark-notice draft.

brandguard reports from public sources. It does not file claims on anyone's behalf and is not a law firm or your agent. The takedown notice is a draft for the rights-holder to review, complete and file themselves.

Live: https://brandguard.djrorrok.workers.dev

Why an agent can't do this alone (the moat)

An LLM coding/brand agent, on its own, doesn't know:

  • the typosquat surface of a name (omissions, doubling, homoglyphs o→0 l→1, deceptive -js/-sdk/-official affixes);

  • which listings across three registries actually exist right now;

  • how to separate the real brand / legit integrations (own npm scope, high adoption, third-party org scopes like @types/*) from parked squats — without crying wolf.

brandguard does the cross-registry lookups and the calibrated scoring so the verdict is trustworthy: LIKELY_ABUSE is only raised with a signal beyond the name match (a "this is the official X" claim, or a parked-squat download pattern). Bare name matches are SUSPECT → human review, never a false accusation.

Related MCP server: DepShield MCP

Use it

Free HTTP API

GET /scan?brand=acme&official=acme-inc        # top 5 findings, risk-scored (npm + PyPI)

MCP (over HTTP)

POST /mcp — tools: scan_brand, draft_takedown.

Pay-per-call (x402) — full scan + takedown drafts

GET /pro/scan?brand=acme&official=acme-inc    # 402 -> pay $0.15 USDC (Base) -> full report + drafts

Settles in USDC on Base via x402. No sign-up, no API key.

Sources (all public / ToS-compliant)

  • npm public registry search + downloads API

  • PyPI JSON API

  • GitHub Search API (server-side token)

Develop / deploy

node src/test.mjs            # unit + live tests
npx wrangler deploy          # Cloudflare Worker

MIT. Not legal advice.

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    Enables users to scan software packages for data exfiltration and security threats directly within their IDE across npm, PyPI, Cargo, and Maven ecosystems. This tool helps ensure the safety of project dependencies by identifying potential risks before they are integrated.
    Last updated
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Acts as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.
    Last updated
    7
    2
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.
    Last updated
    8
    98
    1
    MIT

View all related MCP servers

Related MCP Connectors

  • Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.

  • Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.

  • Check if a brand name is free across domains, GitHub, npm and PyPI, and suggest available names.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Baneado98/brandguard'

If you have feedback or need assistance with the MCP directory API, please join our Discord server