Serveur MCP

dependency-trust

ai.kaiv/dependency-trust
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Checks software dependencies using OpenSSF Scorecard data, license information, CVEs, and dependency details across seven ecosystems.

get_advisory
Get Advisory
Get a security advisory (vulnerability) by its key. Returns a security advisory by key, for example a GHSA id taken from a version's advisoryKeys, including the title, CVE aliases, CVSS v3 score and vector, and a link to the full record on osv.dev. Use this only when you already have an advisory ID from get_package_version's advisoryKeys. There is no search here. To find out whether a version has vulnerabilities at all, call get_package_version first; this tool explains one advisory in depth.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['advisoryKey'], 'properties': {'advisoryKey': {'type': 'string', 'x-in': 'path', 'description': "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys)."}}}
Schéma de sortie
{'type': 'object'}
get_dependencies
Get Dependencies
Get the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version. Each node has the dependency's exact version and its relation (SELF / DIRECT / INDIRECT). Use it to reason about transitive dependencies and supply chain.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['system', 'package', 'version'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}, 'version': {'type': 'string', 'x-in': 'path', 'description': "Exact version string, e.g. '18.2.0'."}}}
Schéma de sortie
{'type': 'object'}
get_package
Get Package
List every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-version flag, and deprecation status. Use it to find the latest version or check if a package is deprecated. Coding agents should call this before recommending a package or version.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['system', 'package'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}}}
Schéma de sortie
{'type': 'object'}
get_package_version
Get Package Version
Get license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses, security advisoryKeys (known vulnerabilities), homepage/issue-tracker/source-repo links, registries, publish date, and deprecation status. Pass any advisoryKey returned here to get_advisory for the vulnerability details.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['system', 'package', 'version'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}, 'version': {'type': 'string', 'x-in': 'path', 'description': "Exact version string, e.g. '18.2.0'."}}}
Schéma de sortie
{'type': 'object'}
get_project_health
Get Project Health
Get a project's OpenSSF Scorecard security posture and maintenance signals. THE trust check. Returns supply-chain trust signals for a package's source repository: the OpenSSF Scorecard overall score (0-10) and per-check results (Maintained, Code-Review, Signed-Releases, Branch-Protection, Pinned-Dependencies, Dangerous-Workflow, Token-Permissions, Security-Policy, Vulnerabilities, ...), plus stars, forks, open-issue count, and license. Use it to judge whether a dependency is actively maintained and securely operated, not just whether it has a known CVE. Get the projectKey from a version's SOURCE_REPO link (call get_package_version first), e.g. 'github.com/facebook/react'.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['projectKey'], 'properties': {'projectKey': {'type': 'string', 'x-in': 'path', 'description': "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version)."}}}
Schéma de sortie
{'type': 'object'}
Ajouté
get_project_health
17 September 2026 07:57
Ajouté
get_package_version
17 September 2026 07:57
Ajouté
get_package
17 September 2026 07:57
Ajouté
get_dependencies
17 September 2026 07:57
Ajouté
get_advisory
17 September 2026 07:57

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…