{
  "markdown": "# DepScope MCP Server\n\n[![npm version](https://img.shields.io/npm/v/depscope-mcp.svg)](https://www.npmjs.com/package/depscope-mcp)\n[![License: AGPL-3.0](https://img.shields.io/badge/License-AGPL_3.0-blue.svg)](https://www.gnu.org/licenses/agpl-3.0.txt)\n[![MCP Compatible](https://img.shields.io/badge/MCP-Compatible-success)](https://modelcontextprotocol.io/)\n\n**Package intelligence MCP server for AI agents.** Stops AI coding agents (Claude, ChatGPT, Cursor, Windsurf, Copilot) from installing **hallucinated**, **deprecated**, or **malicious** packages across **19 ecosystems**.\n\n→ Backed by [depscope.dev](https://depscope.dev) — 1.2M+ packages indexed, 19,000+ vulnerabilities tracked, real-time.\n\n## What's new in v0.9.0\n\nThe MCP server now sends a **system-prompt directive** to your AI client at handshake (`server.instructions`). Claude Code, Cursor, Windsurf and other MCP clients receive a proactive-invocation brief automatically — manual rule files (`CLAUDE.md`, `.cursorrules`, `.windsurfrules`) are now **optional**. Existing rules still work; they're just redundant.\n\nWhat the model sees at every session start:\n\n- The 19-ecosystem coverage list\n- An \"INVOKE PROACTIVELY\" directive with explicit triggers (install, version bump, lockfile change, \"module not found\" errors, library comparison)\n- Three pillars: token-saving, energy-saving, security\n- Standard invocation flow: `check_malicious` → `check_typosquat` → `check_package` → `install_command`\n\nFor Claude Code there is also a **companion plugin** that bundles the MCP server with a skill carrying rich frontmatter triggers:\n\n```bash\ngit clone https://github.com/cuttalo/depscope-claude-plugin ~/.claude/plugins/depscope\n```\n\nAll npm versions `<0.9.0` are now deprecated. Run `npm update -g depscope-mcp` if you installed globally.\n\n---\n\n## Why this exists\n\nLLMs frequently invent package names that look real but don't exist (`fastapi-turbo`, `lodahs`, `tokio-stream-extras`). When an agent tries to install one, it might hit an attacker's typosquat. **DepScope verifies every package before install.**\n\n## Quick start\n\n### Claude Desktop / Cursor / Windsurf (remote MCP)\n\nAdd to your MCP config:\n\n```json\n{\n  \"mcpServers\": {\n    \"depscope\": {\n      \"url\": \"https://mcp.depscope.dev/mcp\"\n    }\n  }\n}\n```\n\n### Local (stdio via npx)\n\n```json\n{\n  \"mcpServers\": {\n    \"depscope\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"depscope-mcp\"]\n    }\n  }\n}\n```\n\n## Tools (22)\n\n| Tool | Purpose |\n|---|---|\n| `check_package` | Full package check: deprecated/CVE/health/recommendation |\n| `get_health_score` | 0-100 score with breakdown (maintenance/popularity/security/maturity/community) |\n| `get_vulnerabilities` | Open CVEs from OSV + KEV/EPSS |\n| `package_exists` | Hallucination detector (404 = LLM invented it) |\n| `find_alternatives` | Curated alternatives for deprecated/abandoned packages |\n| `get_typosquat` | Suspicious name similarity check |\n| `get_breaking_changes` | Migration plan between versions |\n| `get_bugs` | Known bugs from GitHub issues |\n| `compare_packages` | Side-by-side health/license/vuln comparison |\n| `resolve_error` | Map error message → likely cause + fix |\n| `search_errors` | Find similar error reports across ecosystems |\n| `check_compat` | Stack compatibility check |\n| `get_latest_version` | Latest stable + maturity signal |\n| ... and 9 more | full list in `tools.js` |\n\n## Ecosystems (19)\n\n`npm` · `pypi` · `cargo` · `go` · `composer` · `maven` · `nuget` · `rubygems` · `pub` · `hex` · `swift` · `cocoapods` · `cpan` · `hackage` · `cran` · `conda` · `homebrew` · `jsr` · `julia`\n\n## Pricing\n\n**Free.** No auth required. Generous rate limits. The MCP server is open-source (AGPL-3.0); the backend (depscope.dev API) is proprietary.\n\n## License\n\nAGPL-3.0-or-later. Backend is proprietary; this client is open.\n\n## Links\n\n- [depscope.dev](https://depscope.dev) — homepage\n- [docs](https://depscope.dev/integrate) — integration guide\n- [Glama listing](https://glama.ai/mcp/servers/cuttalo/depscope)\n- [awesome-mcp-servers](https://github.com/punkpeye/awesome-mcp-servers)\n",
  "bytes": 4078,
  "sha": "9c7536df4e9137c8dc5a1258ee4b7b6cad7c00a1a8561fcf24215bc2a093ed42",
  "repo_slug": "cuttalo/depscope-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_dev_depscope_mcp_9087d0b0/readme"
}