dependency-trust
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
Sollte ich dies verwenden
Qualität und Sicherheit
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"dependency-trust": {
"url": "https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d"
}
}
}Remote-Endpunkte
https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06dstreamable-httpWas es kann
Tool-Inventar
Tools (5)
🟢get_advisory(advisoryKey)
Get a security advisory (vulnerability) by its key. Returns a security advisory by key, for example a GHSA id taken from a version's advisoryKeys, including the title, CVE aliases, CVSS v3 score and vector, and a link to the full record on osv.dev. Use this only when you already have an advisory ID from get_package_version's advisoryKeys. There is no search here. To find out whether a version has vulnerabilities at all, call get_package_version first; this tool explains one advisory in depth.
Eingabe-Schema
{
"type": "object",
"properties": {
"advisoryKey": {
"type": "string",
"x-in": "path",
"description": "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys)."
}
},
"required": [
"advisoryKey"
]
}Ausgabe-Schema
{
"type": "object"
}🟢get_dependencies(system, package, version)
Get the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version. Each node has the dependency's exact version and its relation (SELF / DIRECT / INDIRECT). Use it to reason about transitive dependencies and supply chain.
Eingabe-Schema
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
},
"version": {
"type": "string",
"x-in": "path",
"description": "Exact version string, e.g. '18.2.0'."
}
},
"required": [
"system",
"package",
"version"
]
}Ausgabe-Schema
{
"type": "object"
}🟢get_package(system, package)
List every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-version flag, and deprecation status. Use it to find the latest version or check if a package is deprecated. Coding agents should call this before recommending a package or version.
Eingabe-Schema
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
}
},
"required": [
"system",
"package"
]
}Ausgabe-Schema
{
"type": "object"
}🟢get_package_version(system, package, version)
Get license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses, security advisoryKeys (known vulnerabilities), homepage/issue-tracker/source-repo links, registries, publish date, and deprecation status. Pass any advisoryKey returned here to get_advisory for the vulnerability details.
Eingabe-Schema
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
},
"version": {
"type": "string",
"x-in": "path",
"description": "Exact version string, e.g. '18.2.0'."
}
},
"required": [
"system",
"package",
"version"
]
}Ausgabe-Schema
{
"type": "object"
}🟢get_project_health(projectKey)
Get a project's OpenSSF Scorecard security posture and maintenance signals. THE trust check. Returns supply-chain trust signals for a package's source repository: the OpenSSF Scorecard overall score (0-10) and per-check results (Maintained, Code-Review, Signed-Releases, Branch-Protection, Pinned-Dependencies, Dangerous-Workflow, Token-Permissions, Security-Policy, Vulnerabilities, ...), plus stars, forks, open-issue count, and license. Use it to judge whether a dependency is actively maintained and securely operated, not just whether it has a known CVE. Get the projectKey from a version's SOURCE_REPO link (call get_package_version first), e.g. 'github.com/facebook/react'.
Eingabe-Schema
{
"type": "object",
"properties": {
"projectKey": {
"type": "string",
"x-in": "path",
"description": "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version)."
}
},
"required": [
"projectKey"
]
}Ausgabe-Schema
{
"type": "object"
}Empfohlene Prompts
get_advisoryget_advisoryCommunity
Nachweis