mcp-dep-tools
# mcp-dep-tools
MCP server providing dependency and package management tools for AI agents. Analyze licenses, find outdated packages, visualize dependency trees, estimate bundle sizes, and audit security vulnerabilities — all from your AI assistant.
## Tools
### dep_check_licenses
Analyze licenses of all dependencies in a project. Lists each dependency's license type, flags copyleft (GPL) and unknown licenses, and checks for compatibility issues.
### dep_find_outdated
Check which dependencies are outdated. Compares installed or specified versions against the latest on npm, categorizes updates as major/minor/patch, and shows how many days since the latest version was published.
### dep_analyze_tree
Build and display the dependency tree. Shows direct dependencies and their transitive sub-dependencies, calculates maximum depth, detects circular dependencies, and counts total transitive packages.
### dep_analyze_size
Estimate total bundle size from package.json without installing node_modules. Queries the Bundlephobia API for each production dependency to get minified and gzipped sizes.
### dep_security_audit
Check dependencies for known security vulnerabilities. Runs `npm audit` when a lockfile is present, otherwise queries the npm registry advisory API directly. Reports severity levels, affected version ranges, and fix recommendations.
## Setup
```bash
npm install
npm run build
```
## Usage with Claude Desktop
Add to your Claude Desktop config:
```json
{
"mcpServers": {
"dep-tools": {
"command": "node",
"args": ["path/to/mcp-dep-tools/dist/index.js"]
}
}
}
```
## All tools accept a single parameter
- **project_dir** (string, required): Absolute path to the project directory containing a `package.json`.
## License
MIT
TDQS
Scored across 5 tools
Each tool clearly targets a distinct aspect of dependency management: size estimation, tree visualization, license checking, outdated detection, and security audit. There is no overlap in functionality.
All tools follow a consistent 'dep_<verb>_<object>' pattern with snake_case. The only slight deviation is 'dep_find_outdated' using 'find' instead of 'check' or 'analyze', but the pattern remains clear and predictable.
With 5 tools, the server covers the main concerns of dependency analysis (size, tree, licenses, outdated, security) without being too sparse or bloated. The count is well-scoped for the domain.
The tools provide comprehensive coverage for inspecting dependencies. Minor gaps exist, such as the absence of a tool to automatically update or fix issues, but the analysis functionality is complete for typical workflows.