depscope-mcp

depscope-mcp

Validates and checks packages across 19 ecosystems to prevent AI agents from installing hallucinated, deprecated, or malicious packages.

Category
Visit Server

README

DepScope MCP Server

npm version License: AGPL-3.0 MCP Compatible

Package intelligence MCP server for AI agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.

→ Backed by depscope.dev — 1.2M+ packages indexed, 19,000+ vulnerabilities tracked, real-time.

What's new in v0.9.0

The MCP server now sends a system-prompt directive to your AI client at handshake (server.instructions). Claude Code, Cursor, Windsurf and other MCP clients receive a proactive-invocation brief automatically — manual rule files (CLAUDE.md, .cursorrules, .windsurfrules) are now optional. Existing rules still work; they're just redundant.

What the model sees at every session start:

  • The 19-ecosystem coverage list
  • An "INVOKE PROACTIVELY" directive with explicit triggers (install, version bump, lockfile change, "module not found" errors, library comparison)
  • Three pillars: token-saving, energy-saving, security
  • Standard invocation flow: check_maliciouscheck_typosquatcheck_packageinstall_command

For Claude Code there is also a companion plugin that bundles the MCP server with a skill carrying rich frontmatter triggers:

git clone https://github.com/cuttalo/depscope-claude-plugin ~/.claude/plugins/depscope

All npm versions <0.9.0 are now deprecated. Run npm update -g depscope-mcp if you installed globally.


Why this exists

LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it might hit an attacker's typosquat. DepScope verifies every package before install.

Quick start

Claude Desktop / Cursor / Windsurf (remote MCP)

Add to your MCP config:

{
  "mcpServers": {
    "depscope": {
      "url": "https://mcp.depscope.dev/mcp"
    }
  }
}

Local (stdio via npx)

{
  "mcpServers": {
    "depscope": {
      "command": "npx",
      "args": ["-y", "depscope-mcp"]
    }
  }
}

Tools (22)

Tool Purpose
check_package Full package check: deprecated/CVE/health/recommendation
get_health_score 0-100 score with breakdown (maintenance/popularity/security/maturity/community)
get_vulnerabilities Open CVEs from OSV + KEV/EPSS
package_exists Hallucination detector (404 = LLM invented it)
find_alternatives Curated alternatives for deprecated/abandoned packages
get_typosquat Suspicious name similarity check
get_breaking_changes Migration plan between versions
get_bugs Known bugs from GitHub issues
compare_packages Side-by-side health/license/vuln comparison
resolve_error Map error message → likely cause + fix
search_errors Find similar error reports across ecosystems
check_compat Stack compatibility check
get_latest_version Latest stable + maturity signal
... and 9 more full list in tools.js

Ecosystems (19)

npm · pypi · cargo · go · composer · maven · nuget · rubygems · pub · hex · swift · cocoapods · cpan · hackage · cran · conda · homebrew · jsr · julia

Pricing

Free. No auth required. Generous rate limits. The MCP server is open-source (AGPL-3.0); the backend (depscope.dev API) is proprietary.

License

AGPL-3.0-or-later. Backend is proprietary; this client is open.

Links

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured
E2B

E2B

Using MCP to run code via e2b.

Official
Featured