Protect your AI agents and IDEs from malicious open-source packages.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Quick Start β’ Documentation β’ Community
[!NOTE]
vetalso runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform.
70-90% of modern software is open source code β how do you know it's safe?
Traditional SCA tools drown you in CVE noise. vet takes a different approach:
Free for open source. Hosted SaaS available at SafeDep.
Install in seconds:
or download a pre-built binary
Get started immediately:
vet follows a pipeline architecture: readers ingest package manifests from diverse sources (directories, repositories, container images, SBOMs), enrichers augment each package with vulnerability, malware, and scorecard data from SafeDep Cloud, the CEL policy engine evaluates security policies against enriched data, and reporters produce actionable output in formats like SARIF, JSON, and Markdown.
Real-time protection against malicious packages powered by SafeDep Cloud. Free for open source projects. Detects zero-day malware through active code analysis.
Unlike dependency scanners that flood you with noise, vet analyzes your actual code usage to prioritize real risks.
See dependency usage evidence for details.
Define security policies using CEL expressions to enforce context specific requirements:
Package managers: npm, PyPI, Maven, Go, Ruby, Rust, PHP Container images: Docker, OCI SBOM formats: CycloneDX, SPDX Source repositories: GitHub, GitLab
Real-time protection against malicious packages by querying SafeDep's threat intelligence database, continuously populated through static and dynamic behavioral analysis.
[!NOTE] The
--malwareflag is deprecated. Active (on-demand) scanning has been retired in favour of querying SafeDep's threat intelligence database.--malwarenow behaves identically to--malware-queryand is retained for backward compatibility.
Example detections:
Key security features:
[!NOTE] The
vet inspect malwarecommand (on-demand analysis of a single package) is deprecated and will be removed in a future release. Usevet scan --malware-queryto check packages against SafeDep's known malicious packages database.
Zero-config security guardrails in CI/CD:
See vet-action documentation.
Enterprise scanning with vet CI Component:
Run vet anywhere using our container image:
See releases for pre-built binaries.
Learn more in our comprehensive documentation:
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/safedep-vet-mcp)<a href="https://allmcps.com/mcp/safedep-vet-mcp"><img src="https://allmcps.com/api/badge/safedep-vet-mcp?style=directory" alt="SafeDep Vet MCP on AllMCPs" /></a>