cuttalo/depscope

๐Ÿ”’ Security๐ŸŸข Verified Active
0 Views
0 Installs

๐Ÿ“‡ โ˜๏ธ ๐Ÿ  - Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) โ€” check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote URL https://mcp.depscope.dev/mcp or stdio npx depscope-mcp.

Quick Install

One-Click IDE Configuration
claude_desktop_config.json
{
  "mcpServers": {
    "cuttalo-depscope": {
      "command": "npx",
      "args": [
        "-y",
        "cuttalo-depscope"
      ]
    }
  }
}
Or

Using an AI coding agent (Claude Code, Cursor, etc.)? Copy a ready-made prompt that tells it to fetch the setup instructions and install this server for you.

Documentation Overview

DepScope

Package Intelligence for AI Agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot, Cline) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.

โ†’ Live at depscope.dev ยท 8.4M+ packages ยท 42K+ vulnerabilities (99% EPSS-enriched) ยท zero auth ยท free


Quick start (MCP)

Claude Desktop / Cursor / Windsurf โ€” remote

{
  "mcpServers": {
    "depscope": {
      "url": "https://mcp.depscope.dev/mcp"
    }
  }
}

Claude Code / local โ€” stdio

{
  "mcpServers": {
    "depscope": {
      "command": "npx",
      "args": ["-y", "depscope-mcp"]
    }
  }
}

The MCP server source is at cuttalo/depscope-mcp (AGPL-3.0).


What it does

22 MCP tools across 19 package ecosystems:

npm ยท pypi ยท cargo ยท go ยท composer ยท maven ยท nuget ยท rubygems ยท pub ยท hex ยท swift ยท cocoapods ยท cpan ยท hackage ยท cran ยท conda ยท homebrew ยท jsr ยท julia

ToolPurpose
check_packageFull safety check: deprecation ยท vulnerabilities ยท health ยท recommendation
check_maliciousMalicious-package detector
check_typosquatTyposquat detection vs popular names
package_existsHallucination detector (404 = LLM invented it)
get_health_score0โ€“100 health score with breakdown
get_vulnerabilitiesVulnerabilities + severity scoring
find_alternativesSuggested alternatives for deprecated/abandoned packages
get_breaking_changesMajor-version migration notes
get_known_bugsKnown issues for a package
compare_packagesSide-by-side comparison
check_compatibilityStack-level compatibility check
resolve_errorError message โ†’ likely cause + fix
install_commandVerified install command for the target ecosystem
get_latest_versionLatest stable version + maturity signal
pin_safeSuggested safe version pin
get_trust_signalsMulti-signal trust score
get_migration_pathStep-by-step upgrade plan
scan_projectBulk scan of dependency manifests
check_bulkFast pre-flight filter for batches
get_trendingTrending packages by ecosystem
get_package_promptCompact LLM-friendly summary
contact_depscopeReport a missing package or false positive

REST API

Same data, plain HTTPS โ€” no MCP client needed.

curl https://depscope.dev/api/check/npm/lodash
curl https://depscope.dev/api/check/pypi/requests
curl https://depscope.dev/api/check/cargo/serde

Full reference: depscope.dev/integrate


Why

LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it can hit an attacker's typosquat. DepScope verifies every package before install.

Read more: depscope.dev/why


Pricing

Free. No auth required. Generous rate limits.

If you need higher quotas, SLA, or on-prem deployment, contact us at depscope@cuttalo.com.


Open source vs proprietary

This repository is a landing page with documentation only.

  • MCP server (client SDK) โ€” open source, AGPL-3.0: โ†’ cuttalo/depscope-mcp โ†’ npm: depscope-mcp

  • Backend (API + intelligence layer) โ€” proprietary, hosted at depscope.dev.

This split lets us keep the client free, auditable, and community-extensible while sustaining the infrastructure that powers it.


Links


License

This README and accompanying landing files: CC-BY-4.0. MCP client SDK: AGPL-3.0 (see cuttalo/depscope-mcp). Backend service: proprietary.


Built by Cuttalo srl ยท Italy ๐Ÿ‡ฎ๐Ÿ‡น

Related MCP Servers

13bm/GhidraMCP

๐Ÿ โ˜• ๐Ÿ  - MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.

๐Ÿ”’ Security1 views
123Ergo/unphurl-mcp

๐Ÿ“‡ โ˜๏ธ - URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

๐Ÿ”’ Security0 views
82ch/MCP-Dandan

๐Ÿ ๐Ÿ“‡ ๐Ÿ  ๐ŸŽ ๐ŸชŸ ๐Ÿง - Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

๐Ÿ”’ Security0 views
9hannahnine-jpg/arc-gate-mcp

๐Ÿ - Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

๐Ÿ”’ Security0 views

Engagement

Views
0
Installs
0
Upvotes
0

Views and upvotes are unique per visitor network (hashed IP). Installs count copy actions.

Status

Health: Active

Recent health check succeeded.

Last checked: 7/28/2026, 9:23:18 PM

Unclaimed listing (imported or pending owner verification). Claim it โ†’
โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to get the verified badge and attach your website.

Claim this listing

Promote this listing

Optional paid placement. Free listings stay free forever.

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.