Deps MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DEPS_ROOT | No | Project root directory to use when not passed by the chat | |
| GITHUB_TOKEN | No | GitHub token for higher advisory rate limits |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| deps_detectB | Detect npm, Maven, and Python manifests in a project directory. |
| deps_npm_auditA | Run npm audit --json and return severity counts plus the first 40 packages. |
| deps_maven_treeC | Run mvn dependency:tree for a pom.xml in this directory or one level down. |
| deps_python_packagesC | List declared Python packages from requirements.txt or show pyproject.toml. |
| deps_github_advisoryC | Look up GitHub security advisories. ecosystem is npm, maven, pip, or nuget. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool targets a distinct purpose: manifest detection, npm audit, Maven dependency tree, Python package listing, and GitHub advisory lookup. No overlap or ambiguity between tools.
All tools use a consistent 'deps_' prefix followed by a verb_noun pattern (e.g., deps_npm_audit, deps_maven_tree). Naming is uniform and predictable.
With 5 tools covering detection, language-specific inspection, and advisory lookup, the count is well-scoped for a dependency scanning server—neither sparse nor bloated.
The surface covers detection and some language-specific commands, but lacks unified vulnerability scanning across all ecosystems (e.g., no Python audit, no Maven audit) and no update/fix operations. Advisory lookup partially fills this, but gaps remain.