DepsGuard MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DEPSGUARD_PROXY | No | Proxy URL for internal network | |
| ANTHROPIC_API_KEY | No | API key for Anthropic (required if using anthropic provider) | |
| DEPSGUARD_LLM_PROVIDER | No | LLM provider to use (anthropic, openai, gemini, ollama) | anthropic |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_dependenciesA | 의존성 파일을 스캔하여 취약점을 탐지하고 AI로 실제 영향을 분석합니다. |
| analyze_upgradeA | 패키지 버전 업그레이드 시 breaking change를 AI가 분석하고 영향 파일·수정 방법을 제시합니다. |
| list_packagesB | 의존성 파일에서 패키지 목록을 파싱하여 반환합니다. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool serves a clearly distinct purpose: scanning for vulnerabilities, listing packages, and analyzing upgrades. There is no overlap in their primary functions.
All tool names follow a consistent verb_noun pattern: scan_dependencies, list_packages, analyze_upgrade. This makes the API predictable and easy to navigate.
Three tools is well-scoped for a dependency management server, covering essential workflows without unnecessary bloat. Each tool earns its place.
The tool set covers listing, vulnerability scanning, and upgrade analysis, but lacks tools for direct remediation or detailed package-level inspection. Minor gap, but core workflows are covered.