MCP Hub
Back to servers

mcp

Saves tokens, energy & blocks unsafe packages — 22 tools, 19 ecosystems, 1.2M+ pkgs, MIT.

Registrynpm237/wk
Updated
May 2, 2026

Quick Install

npx -y depscope-mcp

DepScope MCP Server

npm version License: AGPL-3.0 MCP Compatible

Package intelligence MCP server for AI agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.

→ Backed by depscope.dev — 1.2M+ packages indexed, 19,000+ vulnerabilities tracked, real-time.

Why this exists

LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it might hit an attacker's typosquat. DepScope verifies every package before install.

Quick start

Claude Desktop / Cursor / Windsurf (remote MCP)

Add to your MCP config:

{
  "mcpServers": {
    "depscope": {
      "url": "https://mcp.depscope.dev/mcp"
    }
  }
}

Local (stdio via npx)

{
  "mcpServers": {
    "depscope": {
      "command": "npx",
      "args": ["-y", "depscope-mcp"]
    }
  }
}

Tools (22)

ToolPurpose
check_packageFull package check: deprecated/CVE/health/recommendation
get_health_score0-100 score with breakdown (maintenance/popularity/security/maturity/community)
get_vulnerabilitiesOpen CVEs from OSV + KEV/EPSS
package_existsHallucination detector (404 = LLM invented it)
find_alternativesCurated alternatives for deprecated/abandoned packages
get_typosquatSuspicious name similarity check
get_breaking_changesMigration plan between versions
get_bugsKnown bugs from GitHub issues
compare_packagesSide-by-side health/license/vuln comparison
resolve_errorMap error message → likely cause + fix
search_errorsFind similar error reports across ecosystems
check_compatStack compatibility check
get_latest_versionLatest stable + maturity signal
... and 9 morefull list in tools.js

Ecosystems (19)

npm · pypi · cargo · go · composer · maven · nuget · rubygems · pub · hex · swift · cocoapods · cpan · hackage · cran · conda · homebrew · jsr · julia

Pricing

Free. No auth required. Generous rate limits. The MCP server is open-source (AGPL-3.0); the backend (depscope.dev API) is proprietary.

License

AGPL-3.0-or-later. Backend is proprietary; this client is open.

Links

Reviews

No reviews yet

Sign in to write a review