Depfender MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Depfender MCP Serverscan the npm package express for security threats"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Installation
Cursor
Add to your Cursor MCP settings:
{
"mcpServers": {
"depfender": {
"command": "npx",
"args": ["@depfenderdev/mcp"]
}
}
}Claude Code
claude mcp add depfender -- npx @depfenderdev/mcpVS Code
Add to your VS Code MCP settings (.vscode/mcp.json):
{
"mcpServers": {
"depfender": {
"command": "npx",
"args": ["@depfenderdev/mcp"]
}
}
}Related MCP server: GuardianMCP
Tools
scan_package
Scans a package for data exfiltration and security threats.
Parameters:
package(required) — package name (e.g.,lodash)version(optional) — version to scan (defaults to latest)ecosystem(optional) — package ecosystem:npm,pypi,cargo,maven(default:npm)
Development
Setup
npm install
npm run buildEnvironment Variables
Variable | Required | Description |
| Yes | Backend API URL (e.g., |
| Yes | Backend API secret ( |
Local IDE Configuration
Add to your MCP settings (e.g., Claude Desktop claude_desktop_config.json):
{
"mcpServers": {
"depfender": {
"command": "node",
"args": ["/path/to/mcp/dist/index.js"],
"env": {
"DEPFENDER_API_URL": "http://localhost:3000",
"DEPFENDER_API_KEY": "your-api-secret"
}
}
}
}Testing
npm test # Run all tests
npm run test:watch # Watch modeE2E tests require DEPFENDER_API_KEY and a running backend:
DEPFENDER_API_KEY=your-secret DEPFENDER_API_URL=http://localhost:3000 npm testScripts
npm run dev # Run with tsx (no build needed)
npm run build # Compile TypeScriptCommunity
GitHub Discussions — Questions and ideas
Twitter/X — Updates and announcements
Website — Full documentation
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.
Protects AI coding agents from installing malicious open source packages. Every npm and PyPI package is checked against SafeDep’s real-time threat intelligence before installation.
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables security scanning of code projects to identify common vulnerabilities like XSS, injections, SSRF, and path traversal issues. Provides local, offline scanning with severity-grouped results and actionable fix suggestions for improving code security.38 npm-
- AlicenseAqualityCmaintenanceAutomatically scans project dependencies (npm, Composer) for security vulnerabilities using the OSV.dev database, providing real-time alerts and detailed remediation guidance directly in your IDE.19 npm1MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to scan project dependencies and Infrastructure as Code files for security vulnerabilities and misconfigurations. It also provides automated fixing capabilities to remediate identified security issues.183MIT
- AlicenseNot gradedqualityAmaintenanceEnables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.4MIT