Skip to main content
Glama
ProduktEntdecker

PatchPilot MCP

PatchPilot MCP

Security scanner for vibe coders. Checks npm packages for known vulnerabilities before you install them.

What it does

PatchPilot is an MCP server that integrates with Claude Code, Cursor, and other AI coding tools. When you're about to install a package, you can ask Claude to check if it's safe first.

Example:

You: "Check if lodash@4.17.0 is safe to use"
Claude: 🚨 lodash@4.17.0 has 4 known vulnerabilities!
        ...
        💡 Recommendation: Update to lodash@4.17.21 or later

Related MCP server: DepShield MCP

Installation

Prerequisites

  • Node.js 18+

  • Claude Code or another MCP-compatible client

Setup

  1. Clone this repository:

git clone https://github.com/YOUR_USERNAME/patchpilot-mcp.git
cd patchpilot-mcp
  1. Install dependencies:

npm install
  1. Build:

npm run build

Add to Claude Code

Add to your Claude Code config (~/.claude/settings.json):

{
  "mcpServers": {
    "patchpilot": {
      "command": "node",
      "args": ["/path/to/patchpilot-mcp/dist/index.js"]
    }
  }
}

Or for development (without building):

{
  "mcpServers": {
    "patchpilot": {
      "command": "npx",
      "args": ["tsx", "/path/to/patchpilot-mcp/src/index.ts"]
    }
  }
}

Restart Claude Code after adding the config.

Usage

Once installed, ask Claude to check packages:

How it works

PatchPilot uses the OSV API (Google's Open Source Vulnerabilities database) to check packages. The API is:

  • Free (no API key needed)

  • Fast

  • Comprehensive (aggregates data from npm, GitHub, NVD, and more)

Available Tools

check_package

Check a single npm package for known vulnerabilities.

Input:

  • name: Package name (e.g., "lodash")

  • version: Package version (e.g., "4.17.0")

Output:

  • Vulnerability count and severity breakdown

  • Details of each vulnerability

  • Recommended fix version

License

MIT

Install Server
F
license - not found
A
quality
D
maintenance

Maintenance

–Maintainers
–Response time
–Release cycle
–Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    An AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.
    2
    6
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Acts as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.
    7
    11
    4
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    AI-powered dependency vulnerability and breaking change analyzer that scans dependencies, identifies vulnerabilities via OSV.dev, and uses AI to assess real impact and suggest fixes.
    Apache 2.0

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ProduktEntdecker/patchpilot-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server