Skip to main content
Glama
ProduktEntdecker

PatchPilot MCP

README.md
# PatchPilot MCP

Security scanner for vibe coders. Checks npm packages for known vulnerabilities before you install them.

## What it does

PatchPilot is an MCP server that integrates with Claude Code, Cursor, and other AI coding tools. When you're about to install a package, you can ask Claude to check if it's safe first.

**Example:**
```
You: "Check if lodash@4.17.0 is safe to use"
Claude: 🚨 lodash@4.17.0 has 4 known vulnerabilities!
        ...
        💡 Recommendation: Update to lodash@4.17.21 or later
```

## Installation

### Prerequisites
- Node.js 18+
- Claude Code or another MCP-compatible client

### Setup

1. Clone this repository:
```bash
git clone https://github.com/YOUR_USERNAME/patchpilot-mcp.git
cd patchpilot-mcp
```

2. Install dependencies:
```bash
npm install
```

3. Build:
```bash
npm run build
```

### Add to Claude Code

Add to your Claude Code config (`~/.claude/settings.json`):

```json
{
  "mcpServers": {
    "patchpilot": {
      "command": "node",
      "args": ["/path/to/patchpilot-mcp/dist/index.js"]
    }
  }
}
```

Or for development (without building):

```json
{
  "mcpServers": {
    "patchpilot": {
      "command": "npx",
      "args": ["tsx", "/path/to/patchpilot-mcp/src/index.ts"]
    }
  }
}
```

Restart Claude Code after adding the config.

## Usage

Once installed, ask Claude to check packages:

- "Check if express@4.17.0 is safe"
- "Is next@14.1.0 secure?"
- "Check lodash 4.17.0 for vulnerabilities"

## How it works

PatchPilot uses the [OSV API](https://osv.dev/) (Google's Open Source Vulnerabilities database) to check packages. The API is:
- Free (no API key needed)
- Fast
- Comprehensive (aggregates data from npm, GitHub, NVD, and more)

## Available Tools

### `check_package`

Check a single npm package for known vulnerabilities.

**Input:**
- `name`: Package name (e.g., "lodash")
- `version`: Package version (e.g., "4.17.0")

**Output:**
- Vulnerability count and severity breakdown
- Details of each vulnerability
- Recommended fix version

## License

MIT

TDQS

A3.6/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no possibility of confusing it with other tools. The tool's purpose is clearly and unambiguously defined.

Naming Consistency5/5

With a single tool, naming consistency is trivially satisfied. The name 'check_package' follows a clear verb_noun style that would be consistent if extended.

Tool Count2/5

The server has only one tool, which feels too thin for the implied scope of 'PatchPilot'—a name suggesting broader patching and management workflows. One tool is insufficient to provide a meaningful set of operations.

Completeness2/5

The tool only checks for the presence of known vulnerabilities but provides no ability to list details, assess multiple packages at once, or suggest remediation. This creates significant gaps for agents needing comprehensive security information.

Maintenance

ActivityInactive
ResponsivenessNo issues