DepShield MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_dependencyA | Check a package for known vulnerabilities and verify it exists on the registry. MUST be called before installing any dependency. |
| audit_projectB | Scan a package.json or requirements.txt for all dependency vulnerabilities. Returns a full audit report. |
| find_safe_versionB | Find the newest version of a package with zero known vulnerabilities. |
| get_advisory_detailC | Get full details about a specific security advisory (CVE, GHSA, etc). |
| check_npm_healthB | Assess package health and trustworthiness: downloads, maintenance, license, deprecation status. Scored 0-100. |
| suggest_alternativeA | Find alternative packages when one is vulnerable, deprecated, or unmaintained. |
| deep_scanA | Scan a package's transitive dependency tree for vulnerabilities and suspicious patterns (newly added deps, typosquats, low-download packages). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| security_review | Guided full-project security review using all DepShield tools |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| status | DepShield server status and cache statistics |