depscope-mcp
Provides package verification and security analysis for CocoaPods packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for Composer packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for Homebrew packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for JSR packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for Julia packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for npm packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for NuGet packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for PyPI packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for RubyGems packages, including checks for malicious, deprecated, or hallucinated packages.
Provides package verification and security analysis for Swift packages, including checks for malicious, deprecated, or hallucinated packages.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@depscope-mcpis lodahs a real npm package?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
DepScope MCP Server
Package intelligence MCP server for AI agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.
→ Backed by depscope.dev — 1.2M+ packages indexed, 19,000+ vulnerabilities tracked, real-time.
What's new in v0.9.0
The MCP server now sends a system-prompt directive to your AI client at handshake (server.instructions). Claude Code, Cursor, Windsurf and other MCP clients receive a proactive-invocation brief automatically — manual rule files (CLAUDE.md, .cursorrules, .windsurfrules) are now optional. Existing rules still work; they're just redundant.
What the model sees at every session start:
The 19-ecosystem coverage list
An "INVOKE PROACTIVELY" directive with explicit triggers (install, version bump, lockfile change, "module not found" errors, library comparison)
Three pillars: token-saving, energy-saving, security
Standard invocation flow:
check_malicious→check_typosquat→check_package→install_command
For Claude Code there is also a companion plugin that bundles the MCP server with a skill carrying rich frontmatter triggers:
git clone https://github.com/cuttalo/depscope-claude-plugin ~/.claude/plugins/depscopeAll npm versions <0.9.0 are now deprecated. Run npm update -g depscope-mcp if you installed globally.
Related MCP server: DepScope
Why this exists
LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it might hit an attacker's typosquat. DepScope verifies every package before install.
Quick start
Claude Desktop / Cursor / Windsurf (remote MCP)
Add to your MCP config:
{
"mcpServers": {
"depscope": {
"url": "https://mcp.depscope.dev/mcp"
}
}
}Local (stdio via npx)
{
"mcpServers": {
"depscope": {
"command": "npx",
"args": ["-y", "depscope-mcp"]
}
}
}Tools (22)
Tool | Purpose |
| Full package check: deprecated/CVE/health/recommendation |
| 0-100 score with breakdown (maintenance/popularity/security/maturity/community) |
| Open CVEs from OSV + KEV/EPSS |
| Hallucination detector (404 = LLM invented it) |
| Curated alternatives for deprecated/abandoned packages |
| Suspicious name similarity check |
| Migration plan between versions |
| Known bugs from GitHub issues |
| Side-by-side health/license/vuln comparison |
| Map error message → likely cause + fix |
| Find similar error reports across ecosystems |
| Stack compatibility check |
| Latest stable + maturity signal |
... and 9 more | full list in |
Ecosystems (19)
npm · pypi · cargo · go · composer · maven · nuget · rubygems · pub · hex · swift · cocoapods · cpan · hackage · cran · conda · homebrew · jsr · julia
Pricing
Free. No auth required. Generous rate limits. The MCP server is open-source (AGPL-3.0); the backend (depscope.dev API) is proprietary.
License
AGPL-3.0-or-later. Backend is proprietary; this client is open.
Links
depscope.dev — homepage
docs — integration guide
This server cannot be deployed
Maintenance
Related MCP Connectors
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
Protects AI coding agents from installing malicious open source packages. Every npm and PyPI package is checked against SafeDep’s real-time threat intelligence before installation.
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Related MCP Servers
- AlicenseAqualityFmaintenanceActs as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.746 npm4MIT
- FlicenseAqualityDmaintenancePackage intelligence MCP server. Stops AI agents from installing hallucinated/malicious packages across 17 ecosystems. 22 tools, free, no auth.221-
- AlicenseAqualityDmaintenanceDependency security & health auditing for AI agents with no account or API key required.22MIT
- FlicenseAqualityCmaintenancePackage intelligence for AI coding agents that checks npm and PyPI package health, deprecation, vulnerabilities, bundle size, and compares alternatives.5-