Skip to main content
Glama

DepScope

Package Intelligence for AI Agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot, Cline) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.

Live at depscope.dev · 8.4M+ packages · 42K+ vulnerabilities (99% EPSS-enriched) · zero auth · free


Quick start (MCP)

Claude Desktop / Cursor / Windsurf — remote

{
  "mcpServers": {
    "depscope": {
      "url": "https://mcp.depscope.dev/mcp"
    }
  }
}

Claude Code / local — stdio

{
  "mcpServers": {
    "depscope": {
      "command": "npx",
      "args": ["-y", "depscope-mcp"]
    }
  }
}

The MCP server source is at cuttalo/depscope-mcp (AGPL-3.0).


Related MCP server: mcp-package-health

What it does

22 MCP tools across 19 package ecosystems:

npm · pypi · cargo · go · composer · maven · nuget · rubygems · pub · hex · swift · cocoapods · cpan · hackage · cran · conda · homebrew · jsr · julia

Tool

Purpose

check_package

Full safety check: deprecation · vulnerabilities · health · recommendation

check_malicious

Malicious-package detector

check_typosquat

Typosquat detection vs popular names

package_exists

Hallucination detector (404 = LLM invented it)

get_health_score

0–100 health score with breakdown

get_vulnerabilities

Vulnerabilities + severity scoring

find_alternatives

Suggested alternatives for deprecated/abandoned packages

get_breaking_changes

Major-version migration notes

get_known_bugs

Known issues for a package

compare_packages

Side-by-side comparison

check_compatibility

Stack-level compatibility check

resolve_error

Error message → likely cause + fix

install_command

Verified install command for the target ecosystem

get_latest_version

Latest stable version + maturity signal

pin_safe

Suggested safe version pin

get_trust_signals

Multi-signal trust score

get_migration_path

Step-by-step upgrade plan

scan_project

Bulk scan of dependency manifests

check_bulk

Fast pre-flight filter for batches

get_trending

Trending packages by ecosystem

get_package_prompt

Compact LLM-friendly summary

contact_depscope

Report a missing package or false positive


REST API

Same data, plain HTTPS — no MCP client needed.

curl https://depscope.dev/api/check/npm/lodash
curl https://depscope.dev/api/check/pypi/requests
curl https://depscope.dev/api/check/cargo/serde

Full reference: depscope.dev/integrate


Why

LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it can hit an attacker's typosquat. DepScope verifies every package before install.

Read more: depscope.dev/why


Pricing

Free. No auth required. Generous rate limits.

If you need higher quotas, SLA, or on-prem deployment, contact us at depscope@cuttalo.com.


Open source vs proprietary

This repository is a landing page with documentation only.

This split lets us keep the client free, auditable, and community-extensible while sustaining the infrastructure that powers it.



License

This README and accompanying landing files: CC-BY-4.0. MCP client SDK: AGPL-3.0 (see cuttalo/depscope-mcp). Backend service: proprietary.


Built by Cuttalo srl · Italy 🇮🇹

Install Server
F
license - not found
A
quality
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    MCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.
    Last updated
    14
    65
    15
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    MCP server providing dependency and package management tools for AI agents. Analyze licenses, find outdated packages, visualize dependency trees, estimate bundle sizes, and audit security vulnerabilities.
    Last updated
    5
    61
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.
    Last updated
    485
    7
    Business Source 1.1

View all related MCP servers

Related MCP Connectors

  • Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.

  • npm, PyPI & crates.io intel for AI agents: versions, popularity, deps, health. No API keys.

  • Free public MCP for AI agents — 193 tools, 44 workflows. No API key.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/cuttalo/depscope'

If you have feedback or need assistance with the MCP directory API, please join our Discord server