MCP-Server

devstack-mcp

io.github.IsaiahDupree/devstack-mcp
Entwicklertools Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Searches package registries and provides package metadata, versions, dependency graphs, downloads, project health signals, and vulnerability scans across many ecosystems.

get_dependency_graph
Get resolved dependency graph
The fully resolved dependency graph for one exact package version, via deps.dev. Returns a flat nodes[] array plus integer-index edges[] (walk from/to to rebuild the tree). Each node carries relation (self | direct | indirect) and a direct boolean; node[0] is always the queried root (relation: self). Node order is NOT stable — look nodes up by name/relation, never by positional index. system is case-insensitive and lowercased (npm, pypi, cargo, go, maven, nuget). version is REQUIRED (a graph is resolved for one exact version).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['system', 'name', 'version'], 'properties': {'name': {'type': 'string', 'description': 'Package name / id.'}, 'system': {'enum': ['npm', 'pypi', 'cargo', 'go', 'maven', 'nuget'], 'type': 'string', 'description': 'Package system / ecosystem for deps.dev. Case-insensitive, lowercased server-side.'}, 'version': {'type': 'string', 'description': 'Exact version to resolve (e.g. 18.2.0). Required.'}}}
get_downloads
Get download / pull statistics
Download statistics for a package. Only npm (via api.npmjs.org) and PyPI (via pypistats.org) support this; any other registry returns 400 not_supported. npm returns a period window with downloads, start, and end; PyPI returns last_day, last_week, and last_month totals.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['registry', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name.'}, 'registry': {'enum': ['npm', 'pypi'], 'type': 'string', 'description': 'Target registry. Only npm and pypi expose download stats.'}}}
get_ecosystems_package
Get one package on one registry (with reverse-dep counts)
Full normalized metadata for one package on one of 50+ registries, via ecosyste.ms — including the fields v1 registries can't give you: dependentReposCount and dependentPackagesCount (reverse dependencies), ecosystem, and vulnerabilityCount. Scoped/namespaced names are handled automatically. Returns 404 if the package does not exist on that ecosystem.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['ecosystem', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name / id.'}, 'ecosystem': {'type': 'string', 'description': 'Target ecosyste.ms ecosystem slug (e.g. npm, pypi, cargo, rubygems).'}}}
get_insights
Get project insights — OSSF Scorecard + repo signal
Health and security insights for a package's source project, via deps.dev. Returns the linked source repository, GitHub stars/forks/openIssues, licenses, resolved dependencyCount, security advisories, and the full OSSF Scorecard (ossfScore 0..10 plus the per-check breakdown). Omit version to use the registry default version — note deps.dev's default is a MOVING target and an unverified default mirror may have no computed scorecard (ossfScore: null); pin version for a stable, scorecard-backed result. system is lowercased (npm, pypi, cargo, go, maven, …).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['system', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name / id.'}, 'system': {'enum': ['npm', 'pypi', 'cargo', 'go', 'maven', 'nuget'], 'type': 'string', 'description': 'Package system / ecosystem for deps.dev. Case-insensitive, lowercased server-side.'}, 'version': {'type': 'string', 'description': 'Exact version. Omit for the (moving) registry default version.'}}}
get_package
Get normalized package details
Full normalized details for one package by registry + name, in a single unified Package shape across npm, PyPI, Docker Hub, and the VS Code Marketplace. name handles scoped npm ids (e.g. @types/node), Docker namespaces (e.g. library/nginx or a bare nginx for official images), and VS Code publisher.extension ids. With registry=all the request fans out to every registry in parallel and returns a packages array (missing registries are silently dropped); otherwise a single package is returned.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['registry', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name / id. Supports scoped npm ids (@scope/pkg), Docker namespaces (ns/name or a bare name for official images), and VS Code publisher.extension ids.'}, 'registry': {'enum': ['npm', 'pypi', 'docker', 'vscode', 'all'], 'type': 'string', 'description': 'Target registry. "all" fans out to every registry and merges results.'}}}
get_versions
Get published versions / tags
List published versions (npm/PyPI), image tags (Docker Hub, most recent 25), or extension versions (VS Code) for a package. registry=all is NOT supported here — pick a single registry. Each item carries version and released, plus registry-specific extras (files for PyPI, size for Docker tags).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['registry', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name / id (scoped npm ids, Docker namespaces, and VS Code publisher.extension ids supported).'}, 'registry': {'enum': ['npm', 'pypi', 'docker', 'vscode'], 'type': 'string', 'description': 'Target registry. "all" is not supported here â\x80\x94 pick one.'}}}
get_vulnerabilities
Get vulnerabilities for a package
Known vulnerabilities (CVE / GHSA / PYSEC / GO advisories) for a package, via OSV.dev. Pass version to filter to advisories affecting that exact version, or omit it for the package's full advisory history. Each result carries the OSV id, cross-id aliases, a severity word grade (LOW|MODERATE|HIGH|CRITICAL), the cvss vector string, affectedRanges with fixed-version events, references, and cwes. A clean package returns count: 0 with an empty list (not an error). ecosystem is CASE-SENSITIVE — use OSV's spelling (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, …). Use scan_vulnerabilities_batch for lockfile batch scans.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['ecosystem', 'name'], 'properties': {'name': {'type': 'string', 'description': 'Package name.'}, 'version': {'type': 'string', 'description': 'Exact version to filter advisories to. Omit for full history.'}, 'ecosystem': {'type': 'string', 'description': 'OSV ecosystem, CASE-SENSITIVE (e.g. npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems).'}}}
scan_vulnerabilities_batch
Batch vulnerability scan (lockfile)
Scan many packages in one call — ideal for a whole lockfile. Pass a queries[] array (max 100) of { ecosystem, name, version? }; results are returned positionally aligned, one row per query, each with a count and a hydrated vulns[] array. Advisories are de-duplicated and hydrated across the batch. ecosystem is CASE-SENSITIVE (OSV spelling).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['queries'], 'properties': {'queries': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Package name (required).'}, 'version': {'type': 'string', 'description': 'Exact version. Omit for full history.'}, 'ecosystem': {'type': 'string', 'description': 'OSV ecosystem (case-sensitive). e.g. npm, PyPI, Go.'}}}, 'maxItems': 100, 'minItems': 1, 'description': 'Up to 100 { ecosystem, name, version? } queries, ideal for a whole lockfile.'}}}
search_ecosystems
Cross-registry package lookup (50+ ecosystems)
Look a package name up across 50+ registries at once, via ecosyste.ms. This is an EXACT-name lookup (not fuzzy full-text): q=react returns the react package everywhere it exists (npm, cargo, nuget, pub, bower, …), each as a normalized ecosystemsPackage with reverse-dependency counts. Pass ecosystem to narrow to one registry. Results carry dependentReposCount, dependentPackagesCount, and vulnerabilityCount.
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['q'], 'properties': {'q': {'type': 'string', 'description': 'Exact package name to look up across registries.'}, 'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Max results. Clamped to 1-50. Default 20.'}, 'ecosystem': {'type': 'string', 'description': 'Narrow to one ecosystem (e.g. pypi, npm, cargo). Omit to search all.'}}}
search_packages
Search packages across registries
Search a registry for packages matching q. registry=all fans out to npm, Docker Hub, and the VS Code Marketplace and merges the results. PyPI has no public search API, so registry=pypi returns 400 not_supported — look a PyPI package up by name via get_package instead. Results are normalized PackageSummary items (npm adds a relevance score; Docker adds isOfficial).
Nur Lesen Externer Zugriff Idempotent
Eingabeschema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['registry', 'q'], 'properties': {'q': {'type': 'string', 'description': 'Search query.'}, 'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Max results per registry. Clamped to 1-50. Default 20.'}, 'registry': {'enum': ['npm', 'pypi', 'docker', 'vscode', 'all'], 'type': 'string', 'description': 'Target registry. "all" fans out to npm, Docker, and VS Code and merges results. pypi returns not_supported.'}}}
Hinzugefügt
get_ecosystems_package
17. September 2026 12:42
Hinzugefügt
search_ecosystems
17. September 2026 12:42
Hinzugefügt
get_insights
17. September 2026 12:42
Hinzugefügt
scan_vulnerabilities_batch
17. September 2026 12:42
Hinzugefügt
get_vulnerabilities
17. September 2026 12:42
Hinzugefügt
get_dependency_graph
17. September 2026 12:42
Hinzugefügt
get_downloads
17. September 2026 12:42
Hinzugefügt
get_versions
17. September 2026 12:42
Hinzugefügt
search_packages
17. September 2026 12:42
Hinzugefügt
get_package
17. September 2026 12:42

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…