MCP-Server

DepScope

dev.depscope/mcp
Entwicklertools Sicherheit Nicht verfügbar MCP 2025-11-25

Was dieses MCP kann

Evaluates software packages for existence, compatibility, vulnerabilities, malware, typosquatting, maintenance health, migrations, and dependency risks.

check_bulk
Fast pre-flight filter for a batch of (ecosystem, package) pairs. DB-only, <100ms for 100 items. USE WHEN: about to emit `npm install a b c …` or `pip install a b c …` — catches hallucinated names, stdlib, typos, and known-bad in ONE call. NOT a dep-tree audit (use scan_project for that). RETURNS: per-item {status: exists|stdlib|malicious|typosquat_suspect|historical_incident|unknown}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['items'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}, 'maxItems': 100}}}
check_compatibility
Is this specific multi-package version combo verified to work together? USE WHEN: pinning a stack (next@15 + react@19 + node@22); before recommending a version matrix. RETURNS: {compatible, conflicts[], notes}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['packages'], 'properties': {'packages': {'type': 'object', 'description': 'Package -> version map, e.g. {"next":"15","react":"19"}.', 'additionalProperties': {'type': 'string'}}}}
check_malicious
Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
check_package
Full machine-readable JSON report (~2k tokens). USE WHEN: you need to programmatically parse specific fields (CI gating, UI, sub-field extraction). Otherwise prefer get_package_prompt. RETURNS: {package, health:{score}, vulnerabilities[], latest, deprecated, maintainers, recommendation}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': "Package name (e.g. 'express', 'fastapi', 'serde')."}, 'version': {'type': 'string', 'description': 'Specific version (optional; default = latest).'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
check_typosquat
Typosquat detector. USE WHEN: name differs from a well-known package by 1-2 chars (`lodsh`, `reqeusts`); copy-paste from unreliable source; downloads near zero but name looks familiar. RETURNS: {is_typosquat, likely_target, confidence}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
compare_packages
Side-by-side comparison (health, vulns, downloads, maintainers, last release) of 2-10 packages in the same ecosystem. USE WHEN: 'X vs Y' / 'should I pick X or Y'. RETURNS: table-shaped JSON, one row per package.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'packages'], 'properties': {'packages': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 10, 'minItems': 2, 'description': "Package names to compare, e.g. ['express','fastify','hono']."}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
contact_depscope
Inbound ticket: bug/listing/security/anomaly/partnership. USE WHEN: reporting wrong data (`bug`), requesting a new pkg/ecosystem index (`listing`), disclosing a DepScope security issue (`security`), flagging a concrete mismatch in another tool's output vs. authoritative source (`anomaly` — provide tool_called+observed+expected), or partnership/press (`partnership`). RETURNS: {ticket_id} or {anomaly_id}.
Externer Zugriff
Eingabeschema
{'type': 'object', 'properties': {'body': {'type': 'string', 'description': 'Message body (10-8000 chars). Be specific: include package name, ecosystem, error trace, repro steps when applicable.'}, 'kind': {'enum': ['bug', 'listing', 'security', 'anomaly', 'partnership'], 'type': 'string', 'description': 'Ticket category. `anomaly` routes to structured anomaly triage (requires tool_called/observed/expected).'}, 'name': {'type': 'string', 'description': 'Sender display name (optional).'}, 'email': {'type': 'string', 'description': 'Reply-to email of the requester (required for bug/listing/security/partnership).'}, 'company': {'type': 'string', 'description': 'Company / organization (optional).'}, 'package': {'type': 'string', 'description': 'For kind=anomaly: package name involved, if any.'}, 'subject': {'type': 'string', 'description': 'Short subject line (3-200 chars).'}, 'version': {'type': 'string', 'description': 'For kind=anomaly: package version involved, if any.'}, 'expected': {'type': 'string', 'description': 'For kind=anomaly: what you expected to see (1-1500 chars). Be concrete.'}, 'observed': {'type': 'string', 'description': 'For kind=anomaly: what DepScope returned (1-1500 chars).'}, 'ecosystem': {'type': 'string', 'description': 'For kind=anomaly: ecosystem of the involved package, if any.'}, 'tool_called': {'type': 'string', 'description': 'For kind=anomaly: DepScope tool that produced the anomaly (e.g. check_package, get_migration_path).'}, 'evidence_url': {'type': 'string', 'description': 'For kind=anomaly: URL to authoritative source (registry page, GHSA, CVE, repo, ...) supporting your expectation.'}}}
find_alternatives
Curated replacements for deprecated/unhealthy packages, including stdlib built-ins (e.g. `fs.rm` for rimraf). USE WHEN: pkg flagged AVOID/URGENT; 'what to use instead of X'; before guessing a replacement name. RETURNS: {alternatives[]: {name, reason, is_stdlib}}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_breaking_changes
Breaking changes between two majors of the SAME package (`next@14`→`15`). USE WHEN: user is bumping a major; before recommending a major upgrade. Different from get_migration_path (same pkg vs. different pkg). RETURNS: {breaking_changes[]: {area, description, hint}}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}, 'to_version': {'type': 'string'}, 'from_version': {'type': 'string'}}}
get_health_score
Single 0-100 health score — cheapest go/no-go gate (>=70 safe). USE WHEN: CI gating or pkg already screened for malware/typos. NOT a first screen — run check_malicious + check_typosquat first. For a verbal verdict use get_package_prompt. RETURNS: {score, verdict}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_known_bugs
Non-CVE known bugs for a specific package version. USE WHEN: unexpected behavior that is NOT a security issue; a pinned version misbehaves. RETURNS: {bugs[]: {title, fixed_in, workaround}}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'version': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_latest_version
Latest published version + deprecation flag — the cheapest call. USE WHEN: only a version string matters (pinning a dep, answering 'what version of X'). If you also need health/vulns use check_package. RETURNS: {latest, deprecated, published_at}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_migration_path
Prescriptive migration plan between DIFFERENT packages — rationale + literal code diff + breaking changes + effort minutes. USE WHEN: replacing `request`→`axios`, `moment`→`dayjs`, `flask`→`fastapi`, etc.; both endpoints known. RETURNS: {rationale, diff, breaking_changes[], estimated_minutes}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'from_package', 'to_package'], 'properties': {'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}, 'to_package': {'type': 'string', 'description': 'Modern replacement package.'}, 'from_package': {'type': 'string', 'description': 'Deprecated/legacy package to migrate away from.'}}}
get_package_prompt
LLM-optimised package brief — plain text ~300 tokens (~75% cheaper than JSON). Verdict (SAFE/AVOID/URGENT/MALICIOUS) + health + vulns + alternatives + maintainer alerts. USE WHEN: you want to reason over a package and drop the output directly in context; 'is X safe'. PREFER THIS over check_package in 95% of LLM cases. RETURNS: plain-text brief.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_trending
Live trending packages with rank-delta and weekly growth %. USE WHEN: 'what is rising in npm/PyPI/Cargo right now'; recommendation not biased by training-data cutoff. RETURNS: {items[]: {name, rank, rank_delta, weekly_growth_pct}}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'description': 'Max results, 1-50. Default 20.'}, 'scope': {'enum': ['all', 'week', 'day'], 'type': 'string', 'description': 'Time window. Defaults to week.'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string', 'description': 'Optional. If omitted returns cross-ecosystem trending.'}}}
get_trust_signals
One-call aggregate of ALL non-CVE supply-chain trust signals: maintainer trust (bus factor, ownership changes), OpenSSF Scorecard, quality (criticality, release velocity, publish security), and SLSA/Sigstore provenance. USE WHEN: deep-vetting a package beyond CVEs (hardened/regulated env, SBOM/compliance, small-pkg ownership review, choosing between healthy candidates). Runs 4 backend endpoints in parallel. RETURNS: {maintainer, scorecard, quality, provenance} — each may be null if its backend call failed.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
get_vulnerabilities
CVE/OSV advisories affecting the latest (or specified) version. USE WHEN: security-sensitive project; user asks 'any CVEs in X'; you already know the pkg exists. RETURNS: {vulnerability_count, vulnerabilities[]: {id, severity, cvss, fixed_in}}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
install_command
Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, …). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'version': {'type': 'string', 'description': 'Optional explicit version; defaults to latest.'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
package_exists
Boolean registry existence check. USE WHEN: about to emit a package name in an install command but unsure it exists; verifying a name generated from training data. RETURNS: {exists}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}}}
pin_safe
Highest version below the chosen CVE severity tier, respecting a semver constraint. USE WHEN: writing a package.json/requirements.txt line; resolving dependabot by lowest-risk patched version. RETURNS: {recommended_version, walk_log[]}.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string'}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string'}, 'constraint': {'type': 'string', 'description': 'npm-style constraint: ^X.Y.Z, ~X.Y.Z, >=X.Y.Z, or exact X.Y.Z.'}, 'min_severity': {'enum': ['critical', 'high', 'medium', 'low'], 'type': 'string', 'description': 'Lowest severity to exclude. Default: high (excludes critical+high).'}, 'include_prerelease': {'type': 'boolean', 'default': False}}}
resolve_error
Map error OR free-text query to a verified fix. USE WHEN: user pastes a concrete error/stack (ENOENT, ImportError, build failure) — pass `error`. OR user describes a symptom ('webpack slow', 'pip stuck') — pass `query`. Always prefer this over guessing a fix. RETURNS: exact-match {status, solution, confidence, source_url} or search results [{title, summary, source_url}].
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'properties': {'error': {'type': 'string', 'description': 'Concrete error message / stack trace. Triggers exact-match lookup.'}, 'limit': {'type': 'integer', 'default': 10, 'maximum': 20, 'minimum': 1, 'description': 'Max search results (query mode only).'}, 'query': {'type': 'string', 'description': 'Free-text symptom description. Triggers KB search.'}, 'context': {'type': 'object', 'description': 'Optional context for error-mode calls (ecosystem, package, version).'}}}
scan_project
Audit a project's dependencies in one shot. Returns a single-sentence `verdict` (e.g. "DO NOT INSTALL — 1 hallucinated: fastapi-turbo") that an agent can paste into its reply, plus per-package health/vulns/recommendation. Detects hallucinated packages, deprecated, typosquats, critical vulnerabilities. Accepts EITHER {ecosystem, packages:[name@ver, …]} (up to 100, returns JSON) OR {packages:[{ecosystem, package}, …]} (up to 50, mixed ecosystems, returns text brief). USE WHEN: user pastes package.json/requirements.txt/Cargo.toml; agent generated install command; 'is my stack OK'. RETURNS: JSON with `verdict`, `project_risk`, `summary.hallucinated_packages`, `summary.deprecated_packages`, per-package health.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', 'required': ['packages'], 'properties': {'packages': {'description': "Either ['express','lodash@4.17.0'] (single ecosystem, up to 100) or [{ecosystem, package}, â\x80¦] (mixed, up to 50)."}, 'ecosystem': {'enum': ['npm', 'pypi', 'cargo', 'go', 'composer', 'maven', 'nuget', 'rubygems', 'pub', 'hex', 'swift', 'cocoapods', 'cpan', 'hackage', 'cran', 'conda', 'homebrew', 'jsr', 'julia'], 'type': 'string', 'description': 'Required when packages is a string array.'}}}
Hinzugefügt
contact_depscope
17. September 2026 12:39
Hinzugefügt
get_trending
17. September 2026 12:39
Hinzugefügt
get_trust_signals
17. September 2026 12:39
Hinzugefügt
get_known_bugs
17. September 2026 12:39
Hinzugefügt
resolve_error
17. September 2026 12:39
Hinzugefügt
check_compatibility
17. September 2026 12:39
Hinzugefügt
compare_packages
17. September 2026 12:39
Hinzugefügt
scan_project
17. September 2026 12:39
Hinzugefügt
pin_safe
17. September 2026 12:39
Hinzugefügt
get_breaking_changes
17. September 2026 12:39
Hinzugefügt
get_migration_path
17. September 2026 12:39
Hinzugefügt
find_alternatives
17. September 2026 12:39
Hinzugefügt
get_vulnerabilities
17. September 2026 12:39
Hinzugefügt
check_package
17. September 2026 12:39
Hinzugefügt
get_package_prompt
17. September 2026 12:39
Hinzugefügt
install_command
17. September 2026 12:39
Hinzugefügt
get_health_score
17. September 2026 12:39
Hinzugefügt
get_latest_version
17. September 2026 12:39
Hinzugefügt
package_exists
17. September 2026 12:39
Hinzugefügt
check_bulk
17. September 2026 12:39
Hinzugefügt
check_typosquat
17. September 2026 12:39
Hinzugefügt
check_malicious
17. September 2026 12:39

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…