dependency-trust
What this MCP does
Checks software dependencies using OpenSSF Scorecard data, license information, CVEs, and dependency details across seven ecosystems.
Tools
Input schema
{'type': 'object', 'required': ['advisoryKey'], 'properties': {'advisoryKey': {'type': 'string', 'x-in': 'path', 'description': "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys)."}}}
Output schema
{'type': 'object'}
Input schema
{'type': 'object', 'required': ['system', 'package', 'version'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}, 'version': {'type': 'string', 'x-in': 'path', 'description': "Exact version string, e.g. '18.2.0'."}}}
Output schema
{'type': 'object'}
Input schema
{'type': 'object', 'required': ['system', 'package'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}}}
Output schema
{'type': 'object'}
Input schema
{'type': 'object', 'required': ['system', 'package', 'version'], 'properties': {'system': {'enum': ['npm', 'pypi', 'go', 'maven', 'cargo', 'nuget', 'rubygems'], 'type': 'string', 'x-in': 'path', 'description': 'Package ecosystem.'}, 'package': {'type': 'string', 'x-in': 'path', 'description': "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."}, 'version': {'type': 'string', 'x-in': 'path', 'description': "Exact version string, e.g. '18.2.0'."}}}
Output schema
{'type': 'object'}
Input schema
{'type': 'object', 'required': ['projectKey'], 'properties': {'projectKey': {'type': 'string', 'x-in': 'path', 'description': "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version)."}}}
Output schema
{'type': 'object'}
Recent tool changes
Similar MCP servers
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…
validoria-mcp
Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…
HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data
Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…
developer-tools
Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…
Qiniso
Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…
ContrastAPI
Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…