npm depscope-mcpstreamable-httpupdated 4mo ago
Package intelligence MCP server for AI agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.
What can you do with DepScope?
DepScope MCP Server
Package intelligence MCP server for AI agents. Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing hallucinated, deprecated, or malicious packages across 19 ecosystems.
→ Backed by depscope.dev — 1.2M+ packages indexed, 19,000+ vulnerabilities tracked, real-time.
What's new in v0.9.0
The MCP server now sends a system-prompt directive to your AI client at handshake (server.instructions). Claude Code, Cursor, Windsurf and other MCP clients receive a proactive-invocation brief automatically — manual rule files (CLAUDE.md, .cursorrules, .windsurfrules) are now optional. Existing rules still work; they're just redundant.
What the model sees at every session start:
- The 19-ecosystem coverage list
- An "INVOKE PROACTIVELY" directive with explicit triggers (install, version bump, lockfile change, "module not found" errors, library comparison)
- Three pillars: token-saving, energy-saving, security
- Standard invocation flow:
check_malicious→check_typosquat→check_package→install_command
For Claude Code there is also a companion plugin that bundles the MCP server with a skill carrying rich frontmatter triggers:
git clone https://github.com/cuttalo/depscope-claude-plugin ~/.claude/plugins/depscope
All npm versions <0.9.0 are now deprecated. Run npm update -g depscope-mcp if you installed globally.
Why this exists
LLMs frequently invent package names that look real but don't exist (fastapi-turbo, lodahs, tokio-stream-extras). When an agent tries to install one, it might hit an attacker's typosquat. DepScope verifies every package before install.
Quick start
Claude Desktop / Cursor / Windsurf (remote MCP)
Add to your MCP config:
{
"mcpServers": {
"depscope": {
"url": "https://mcp.depscope.dev/mcp"
}
}
}
Local (stdio via npx)
{
"mcpServers": {
"depscope": {
"command": "npx",
"args": ["-y", "depscope-mcp"]
}
}
}
Tools (22)
| Tool | Purpose |
|---|---|
check_package |
Full package check: deprecated/CVE/health/recommendation |
get_health_score |
0-100 score with breakdown (maintenance/popularity/security/maturity/community) |
get_vulnerabilities |
Open CVEs from OSV + KEV/EPSS |
package_exists |
Hallucination detector (404 = LLM invented it) |
find_alternatives |
Curated alternatives for deprecated/abandoned packages |
get_typosquat |
Suspicious name similarity check |
get_breaking_changes |
Migration plan between versions |
get_bugs |
Known bugs from GitHub issues |
compare_packages |
Side-by-side health/license/vuln comparison |
resolve_error |
Map error message → likely cause + fix |
search_errors |
Find similar error reports across ecosystems |
check_compat |
Stack compatibility check |
get_latest_version |
Latest stable + maturity signal |
| ... and 9 more | full list in tools.js |
Ecosystems (19)
npm · pypi · cargo · go · composer · maven · nuget · rubygems · pub · hex · swift · cocoapods · cpan · hackage · cran · conda · homebrew · jsr · julia
Pricing
Free. No auth required. Generous rate limits. The MCP server is open-source (AGPL-3.0); the backend (depscope.dev API) is proprietary.
License
AGPL-3.0-or-later. Backend is proprietary; this client is open.
Links
- depscope.dev — homepage
- docs — integration guide
- Glama listing
- awesome-mcp-servers
Install
Add DepScope to your client. Pick the one you use.
{
"servers": {
"depscope-mcp": {
"type": "http",
"url": "https://mcp.depscope.dev/mcp"
}
}
}Add to `.vscode/mcp.json` in your workspace.
claude mcp add depscope-mcp -- npx -y depscope-mcpcodex mcp add depscope-mcp -- npx -y depscope-mcpamp mcp add depscope-mcp -- npx -y depscope-mcp{
"mcpServers": {
"depscope-mcp": {
"command": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"depscope-mcp": {
"command": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
{
"mcpServers": {
"depscope-mcp": {
"command": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"depscope-mcp": {
"command": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"depscope-mcp": {
"command": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"depscope-mcp": {
"type": "local",
"command": "npx",
"args": [
"-y",
"depscope-mcp"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"depscope-mcp": {
"command": {
"path": "npx",
"args": [
"-y",
"depscope-mcp"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y depscope-mcpRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
13 tools
DepScope exposes 13 tools to a connected agent.
- check_package
- Full package check: deprecated/CVE/health/recommendation
- get_health_score
- 0-100 score with breakdown (maintenance/popularity/security/maturity/community)
- get_vulnerabilities
- Open CVEs from OSV + KEV/EPSS
- package_exists
- Hallucination detector (404 = LLM invented it)
- find_alternatives
- Curated alternatives for deprecated/abandoned packages
- get_typosquat
- Suspicious name similarity check
- get_breaking_changes
- Migration plan between versions
- get_bugs
- Known bugs from GitHub issues
- compare_packages
- Side-by-side health/license/vuln comparison
- resolve_error
- Map error message → likely cause + fix
- search_errors
- Find similar error reports across ecosystems
- check_compat
- Stack compatibility check
- get_latest_version
- Latest stable + maturity signal
Score
73 / 100
Good
- Documentation25/25
- Maintenance19/25
- Trust6/20
- Capability8/15
- Install experience15/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 119 days ago
- Has a release history
- Repository is not archived
- No licence detected
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 13 tool(s) documented
- Provides prompt templates
- Provides resources
- 18 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Version history
| Versions | Published |
|---|---|
| 0.7.64 | May 1, 2026 |
| 0.7.63 | May 1, 2026 |
| 0.7.62 | May 1, 2026 |
| 0.7.61 | May 1, 2026 |
| 0.7.60 | May 1, 2026 |
| 0.7.59 | May 1, 2026 |
| 0.7.58 | May 1, 2026 |
| 0.7.57 | May 1, 2026 |
| 0.7.56 | May 1, 2026 |
| 0.7.55 | May 1, 2026 |
| 0.7.54 | May 1, 2026 |
| 0.7.53 | Apr 30, 2026 |
| 0.7.52 | Apr 30, 2026 |
| 0.7.51 | Apr 30, 2026 |
| 0.7.50 | Apr 30, 2026 |
| 0.7.49 | Apr 30, 2026 |
| 0.7.48 | Apr 30, 2026 |
| 0.7.47 | Apr 30, 2026 |
| 0.7.46 | Apr 30, 2026 |
| 0.7.45 | Apr 30, 2026 |
| 0.7.44 | Apr 30, 2026 |
| 0.7.43 | Apr 30, 2026 |
| 0.7.42 | Apr 30, 2026 |
| 0.7.41 | Apr 30, 2026 |
| 0.7.40 | Apr 30, 2026 |
| 0.7.39 | Apr 30, 2026 |
| 0.7.38 | Apr 30, 2026 |
| 0.7.37 | Apr 30, 2026 |
| 0.7.36 | Apr 30, 2026 |
| 0.7.35 | Apr 30, 2026 |
| 0.7.34 | Apr 30, 2026 |
| 0.7.33 | Apr 30, 2026 |
| 0.7.32 | Apr 30, 2026 |
| 0.7.31 | Apr 30, 2026 |
| 0.7.30 | Apr 30, 2026 |
| 0.7.29 | Apr 29, 2026 |
| 0.7.28 | Apr 29, 2026 |
| 0.7.27 | Apr 29, 2026 |
| 0.7.26 | Apr 29, 2026 |
| 0.7.25 | Apr 29, 2026 |
| 0.7.24 | Apr 29, 2026 |
| 0.7.22 | Apr 29, 2026 |
| 0.7.21 | Apr 29, 2026 |
| 0.7.20 | Apr 29, 2026 |
| 0.7.19 | Apr 29, 2026 |
| 0.7.18 | Apr 29, 2026 |
| 0.7.17 | Apr 29, 2026 |
| 0.7.16 | Apr 29, 2026 |
| 0.7.15 | Apr 29, 2026 |
| 0.7.14 | Apr 29, 2026 |
| 0.7.13 | Apr 29, 2026 |
| 0.7.12 | Apr 29, 2026 |
| 0.7.11 | Apr 29, 2026 |
| 0.7.10 | Apr 29, 2026 |
| 0.7.6 | Apr 29, 2026 |
| 0.7.5 | Apr 29, 2026 |
| 0.7.4 | Apr 29, 2026 |
| 0.7.3 | Apr 28, 2026 |
| 0.7.2 | Apr 28, 2026 |
| 0.7.1 | Apr 27, 2026 |