DependencyMCP Server
Analyzes JavaScript codebases to generate dependency graphs, extract file metadata, and evaluate architectural patterns and dependencies.
Analyzes Python codebases to generate dependency graphs, extract file metadata, and evaluate architectural patterns and dependencies.
Analyzes TypeScript codebases to generate dependency graphs, extract imports/exports, and evaluate code against architectural rules and patterns.
Uses Zod for schema validation as part of the dependency analysis process when evaluating codebases.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@DependencyMCP Serveranalyze dependencies in my TypeScript project and show me the architectural violations"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
DependencyMCP Server
A Model Context Protocol (MCP) server that analyzes codebases to generate dependency graphs and architectural insights. This server helps understand code structure, dependencies, and architectural patterns across multiple programming languages.
Features
Multi-Language Support: Analyzes dependencies in TypeScript, JavaScript, C#, Python, and more
Dependency Graph Generation: Creates detailed dependency graphs in JSON or DOT format
Architectural Analysis: Infers architectural layers and validates against rules
File Metadata: Extracts imports, exports, and other metadata from source files
Scoring System: Evaluates codebase against architectural rules and patterns
Related MCP server: OrgBrain MCP Server
Installation
Clone the repository
Install dependencies:
npm installBuild the project:
npm run buildConfiguration
Add to your MCP settings file (usually located at ~/.config/cline/mcp_settings.json or equivalent):
json { mcpServers: { \DependencyMCP: { \command: \node, \args: [\path/to/dependency-mcp/dist/index.js], \env: { \MAX_LINES_TO_READ: \1000, \CACHE_DIR: \path/to/dependency-mcp/.dependency-cache, \CACHE_TTL: \3600000 } } }Environment Variables:
MAX_LINES_TO_READ: Maximum number of lines to read from each file (default: 1000)
CACHE_DIR: Directory to store dependency cache files (default: .dependency-cache)
CACHE_TTL: Cache time-to-live in milliseconds (default: 1 hour = 3600000)
Available Tools
analyze_dependencies
Analyzes dependencies in a codebase and generates a dependency graph.
const result = await client.callTool("DependencyMCP", "analyze_dependencies", {
path: "/path/to/project",
excludePatterns: ["node_modules", "dist"], // optional
maxDepth: 10, // optional
fileTypes: [".ts", ".js", ".cs"] // optional
});get_dependency_graph
Gets the dependency graph for a codebase in JSON or DOT format.
const result = await client.callTool("DependencyMCP", "get_dependency_graph", {
path: "/path/to/project",
format: "dot" // or "json" (default)
});get_file_metadata
Gets detailed metadata about a specific file.
const result = await client.callTool("DependencyMCP", "get_file_metadata", {
path: "/path/to/file.ts"
});get_architectural_score
Scores the codebase against architectural rules and patterns.
const result = await client.callTool("DependencyMCP", "get_architectural_score", {
path: "/path/to/project",
rules: [
{
pattern: "src/domain/**/*",
allowed: ["src/domain/**/*"],
forbidden: ["src/infrastructure/**/*"]
}
]
});Example Output
Dependency Graph (JSON)
{
"src/index.ts": {
"path": "src/index.ts",
"imports": ["./utils", "./services/parser"],
"exports": ["analyze", "generateGraph"],
"namespaces": [],
"architecturalLayer": "Infrastructure",
"dependencies": ["src/utils.ts", "src/services/parser.ts"],
"dependents": []
}
}Architectural Score
{
"score": 85,
"violations": [
"src/domain/user.ts -> src/infrastructure/database.ts violates architectural rules"
],
"details": "Score starts at 100 and deducts 5 points per violation"
}Development
The server is built with TypeScript and uses:
Zod for schema validation
diff for file comparison
minimatch for glob pattern matching
Project Structure
dependency-mcp/
├── src/
│ └── index.mts # Main server implementation
├── package.json
├── tsconfig.json
└── README.mdAdding Support for New Languages
To add support for a new programming language:
Add file extensions to the default
fileTypesarrayImplement language-specific regex patterns in
parseFileImportsandparseFileExportsAdd any language-specific architectural patterns to
inferArchitecturalLayer
License
MIT
Available Tools
6 toolscheck_version_existsA
Check if a specific version exists. Use for dependency validation, CI/CD checks, or ensuring version compatibility. Returns whether the version exists with package details and timestamp.
| Name | Required | Description | Default |
|---|---|---|---|
| package_name | Yes | Name of the package to check | |
| version | Yes | Version to check for existence | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool returns 'whether the version exists with package details and timestamp,' which adds useful context about output content. However, it lacks details on error handling, rate limits, authentication needs, or performance characteristics, leaving gaps for a tool with no annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is highly concise and well-structured: two sentences that efficiently cover purpose, usage contexts, and return value. Every sentence earns its place with no wasted words, and it's front-loaded with the core functionality.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (3 required parameters, no output schema, no annotations), the description is adequate but incomplete. It explains purpose and usage well but lacks details on behavioral aspects like error cases or output structure. With no output schema, more information on return values would be helpful, though the mention of 'package details and timestamp' provides some context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents all three parameters. The description doesn't add any parameter-specific information beyond what's in the schema (e.g., it doesn't explain format constraints or examples). This meets the baseline of 3, as the schema handles the heavy lifting, but no extra value is provided.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Check if a specific version exists.' It specifies the resource (version) and verb (check), and distinguishes it from siblings like 'get_latest_version' by focusing on existence verification rather than retrieval. However, it doesn't explicitly differentiate from 'check_versions_exist' (plural vs. singular), leaving minor ambiguity.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear usage contexts: 'Use for dependency validation, CI/CD checks, or ensuring version compatibility.' This gives practical scenarios for when to invoke the tool. It doesn't explicitly state when not to use it or name alternatives (e.g., 'get_package_info' for more details), but the context is sufficient for informed usage.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
check_versions_existA
Check if specific versions exist for multiple packages. Use for bulk dependency validation, CI/CD pipeline checks, or ensuring multiple package version compatibility. Processes up to 100 packages in parallel with individual error handling.
| Name | Required | Description | Default |
|---|---|---|---|
| packages | Yes | Array of package objects with name and version | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden and does well by disclosing key behavioral traits: it processes 'up to 100 packages in parallel' and has 'individual error handling.' However, it doesn't specify the return format or what happens when packages exceed the limit, leaving some gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is highly concise and front-loaded, with two sentences that efficiently cover purpose, usage guidelines, and behavioral traits. Every sentence adds value without redundancy, making it easy for an agent to parse quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (bulk processing with error handling), no annotations, and no output schema, the description is mostly complete but lacks details on return values or error formats. It compensates well with clear purpose and behavioral context, though output specifics are missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents the two parameters. The description adds no additional parameter semantics beyond what's in the schema, such as format details or constraints. Baseline 3 is appropriate when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('check if specific versions exist') and resources ('multiple packages'), distinguishing it from siblings like 'check_version_exists' (singular) and 'get_latest_version' (latest vs. specific). It explicitly mentions bulk processing for dependency validation, CI/CD, and compatibility checks.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage scenarios: 'bulk dependency validation, CI/CD pipeline checks, or ensuring multiple package version compatibility.' It implicitly distinguishes from siblings by emphasizing bulk processing (vs. single-package tools) and specific version checking (vs. latest version tools).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_latest_versionA
Get the latest version of a package. Use for dependency updates, version checks, or when you need the most recent stable release. Returns package name, latest version, description, and timestamp.
| Name | Required | Description | Default |
|---|---|---|---|
| package_name | Yes | Name of the package to check | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions the return values (package name, latest version, description, timestamp), which is helpful, but lacks details on error handling, rate limits, authentication needs, or whether it returns stable vs. prerelease versions. It adequately describes the core behavior but misses operational traits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core purpose in the first sentence, followed by usage contexts and return values in a second sentence. Every sentence adds value without redundancy, making it efficient and well-structured for quick comprehension by an agent.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (2 parameters, no nested objects), 100% schema coverage, and no output schema, the description is reasonably complete. It covers purpose, usage, and return values, though it could benefit from more behavioral details (e.g., error cases) to fully compensate for the lack of annotations and output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters ('package_name' and 'registry') with descriptions and enum values. The description does not add any parameter-specific details beyond what the schema provides, such as format examples or constraints, meeting the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action ('Get the latest version of a package') and resource ('a package'), distinguishing it from siblings like 'check_version_exists' (which verifies existence) or 'get_package_info' (which may return broader metadata). The verb 'Get' combined with 'latest version' precisely defines the tool's function.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear usage contexts ('dependency updates, version checks, or when you need the most recent stable release'), helping an agent understand when to invoke this tool. However, it does not explicitly state when NOT to use it or name alternatives among the sibling tools (e.g., 'get_latest_versions' for multiple packages), which would be needed for a score of 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_latest_versionsA
Get latest versions for multiple packages simultaneously. Use when checking 3+ dependencies - processes up to 100 packages in parallel. Returns individual results for each package with error isolation. Much faster than individual calls for multiple packages.
| Name | Required | Description | Default |
|---|---|---|---|
| packages | Yes | Array of package names to check | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key traits: parallel processing capability, error isolation (individual results per package), performance advantage for bulk operations, and a package limit (up to 100). However, it doesn't mention potential rate limits, authentication requirements, or error handling specifics, leaving some behavioral aspects uncovered.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded: the first sentence states the core purpose, followed by usage guidelines and behavioral details. Every sentence adds value—explaining when to use, constraints, and benefits—with zero redundant or vague information. The structure efficiently guides the agent from general purpose to specific application.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (2 parameters, no output schema, no annotations), the description is largely complete. It covers purpose, usage, key behaviors (parallel processing, error isolation), and performance context. However, without an output schema, it doesn't detail return values (e.g., format of 'individual results'), leaving a minor gap in full contextual understanding.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters ('packages' as an array of package names, 'registry' as an enum of package managers). The description adds minimal parameter semantics beyond this, only implying that 'packages' accepts multiple items and 'registry' specifies where to check. This meets the baseline for high schema coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('Get latest versions') and resources ('multiple packages simultaneously'), distinguishing it from sibling tools like 'get_latest_version' (singular) and 'check_version_exists' (existence check rather than version retrieval). It explicitly mentions parallel processing and error isolation, which are unique functional aspects.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit usage guidance: 'Use when checking 3+ dependencies' specifies a quantitative threshold, 'processes up to 100 packages in parallel' sets a limit, and 'Much faster than individual calls for multiple packages' contrasts with alternatives like 'get_latest_version' (singular). This clearly indicates when to prefer this tool over siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_package_infoA
Get detailed package information including all versions. Use for dependency audits, security reviews, or when you need comprehensive package metadata. Returns versions list, homepage, repository, and full package details.
| Name | Required | Description | Default |
|---|---|---|---|
| package_name | Yes | Name of the package to get info for | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses that the tool returns 'versions list, homepage, repository, and full package details', which adds useful context about the output. However, it lacks details on behavioral traits like error handling, rate limits, authentication needs, or whether it's a read-only operation, leaving gaps in transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded, with the first sentence stating the core purpose and the second providing usage context and return details. Every sentence earns its place by adding value without redundancy, making it efficient and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (2 parameters, no output schema, no annotations), the description is fairly complete. It explains the purpose, usage, and return values, which compensates for the lack of output schema. However, it could be more complete by addressing potential errors or limitations, such as handling of non-existent packages, but it's adequate for most use cases.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters ('package_name' and 'registry') with descriptions and an enum for 'registry'. The description does not add any meaning beyond what the schema provides, such as explaining parameter interactions or constraints, so it meets the baseline of 3 without compensating further.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('Get') and resource ('detailed package information including all versions'), making the purpose specific. It distinguishes from siblings like 'get_latest_version' by emphasizing 'all versions' rather than just the latest, and from 'check_version_exists' by providing comprehensive metadata rather than just existence checks.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context for when to use this tool ('for dependency audits, security reviews, or when you need comprehensive package metadata'), which helps guide usage. However, it does not explicitly state when not to use it or name specific alternatives among the siblings, such as using 'get_latest_version' for just the latest version instead.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_packages_infoA
Get comprehensive package details for multiple packages. Use for dependency audits, security reviews, or bulk package analysis. Processes up to 100 packages in parallel. Returns detailed info for each package with error isolation - failed packages don't break the batch.
| Name | Required | Description | Default |
|---|---|---|---|
| packages | Yes | Array of package names to get info for | |
| registry | Yes | Package registry/manager to check |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden and adds valuable behavioral context: it discloses the batch processing capability ('Processes up to 100 packages in parallel') and error handling behavior ('error isolation - failed packages don't break the batch'). However, it doesn't mention rate limits, authentication needs, or response format details.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded: the first sentence states the core purpose, followed by usage guidelines and behavioral details. Every sentence earns its place by adding value without redundancy, making it efficient and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (batch processing with error handling), no annotations, and no output schema, the description is mostly complete: it covers purpose, usage, and key behaviors. However, it lacks details on output format (e.g., what 'detailed info' includes) and any rate limits or permissions, leaving some gaps for a tool with no structured output.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both parameters ('packages' as an array of package names and 'registry' with an enum). The description adds no additional parameter semantics beyond what the schema provides, such as format examples or constraints, so it meets the baseline of 3.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('Get comprehensive package details') and resource ('for multiple packages'), distinguishing it from sibling tools like 'get_package_info' (singular) and 'check_version_exists' (version checking). It specifies the scope of 'multiple packages' and the comprehensive nature of the details.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use this tool: 'for dependency audits, security reviews, or bulk package analysis.' It distinguishes from siblings by implying this is for bulk operations, unlike 'get_package_info' (likely single-package) or version-checking tools, though it doesn't name specific alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
Each tool has a clearly distinct purpose with no overlap: single vs. multi-package operations, version existence checks vs. latest version retrieval vs. detailed package info. The descriptions reinforce these distinctions, making misselection unlikely.
Tool names follow a consistent verb_noun pattern throughout (e.g., check_version_exists, get_latest_version). All use snake_case and maintain parallel naming for singular and plural variants, making the set predictable and readable.
Six tools are well-scoped for a dependency management server, covering core operations like validation, updates, and audits. Each tool earns its place by addressing distinct use cases without redundancy or bloat.
The toolset provides strong coverage for dependency checking, version retrieval, and package info, with efficient bulk operations. A minor gap exists in update or install actions, but agents can work around this for most dependency management workflows.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
AI-powered codebase analysis — call graphs, security, dead code, complexity. 150+ tools.
Ground-truth code graph for your codebase: exact callers, callees, symbols & dependencies.
Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.
AI Agent with Architectural Memory. Impact analysis (free), tests and code from the graph (pro).
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceProvides comprehensive codebase analysis including project structure evaluation, cross-language duplicate detection, microservices validation, and configuration optimization with AI-powered pattern learning that generates actionable improvement reports.MIT
- AlicenseNot gradedqualityDmaintenanceProvides knowledge extraction and cross-repo analysis tools for multi-repository organizations. It enables users to query type definitions, service dependencies, and infrastructure configurations across an entire organization's codebase.MIT
- AlicenseAqualityDmaintenanceAnalyzes software projects to extract architecture, build dependency graphs, and predict the impact of code changes.241MIT
- AlicenseNot gradedqualityCmaintenanceProvides semantic code search and code insights via a knowledge graph, enabling AI to understand, navigate, and modify complex projects with deep dependency and architecture analysis.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mkearl/dependency-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server