dependency-trust
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"dependency-trust": {
"url": "https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d"
}
}
}Puntos de conexión remotos
https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06dstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (5)
🟢get_advisory(advisoryKey)
Get a security advisory (vulnerability) by its key. Returns a security advisory by key, for example a GHSA id taken from a version's advisoryKeys, including the title, CVE aliases, CVSS v3 score and vector, and a link to the full record on osv.dev. Use this only when you already have an advisory ID from get_package_version's advisoryKeys. There is no search here. To find out whether a version has vulnerabilities at all, call get_package_version first; this tool explains one advisory in depth.
Esquema de entrada
{
"type": "object",
"properties": {
"advisoryKey": {
"type": "string",
"x-in": "path",
"description": "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys)."
}
},
"required": [
"advisoryKey"
]
}Esquema de salida
{
"type": "object"
}🟢get_dependencies(system, package, version)
Get the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version. Each node has the dependency's exact version and its relation (SELF / DIRECT / INDIRECT). Use it to reason about transitive dependencies and supply chain.
Esquema de entrada
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
},
"version": {
"type": "string",
"x-in": "path",
"description": "Exact version string, e.g. '18.2.0'."
}
},
"required": [
"system",
"package",
"version"
]
}Esquema de salida
{
"type": "object"
}🟢get_package(system, package)
List every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-version flag, and deprecation status. Use it to find the latest version or check if a package is deprecated. Coding agents should call this before recommending a package or version.
Esquema de entrada
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
}
},
"required": [
"system",
"package"
]
}Esquema de salida
{
"type": "object"
}🟢get_package_version(system, package, version)
Get license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses, security advisoryKeys (known vulnerabilities), homepage/issue-tracker/source-repo links, registries, publish date, and deprecation status. Pass any advisoryKey returned here to get_advisory for the vulnerability details.
Esquema de entrada
{
"type": "object",
"properties": {
"system": {
"enum": [
"npm",
"pypi",
"go",
"maven",
"cargo",
"nuget",
"rubygems"
],
"type": "string",
"x-in": "path",
"description": "Package ecosystem."
},
"package": {
"type": "string",
"x-in": "path",
"description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
},
"version": {
"type": "string",
"x-in": "path",
"description": "Exact version string, e.g. '18.2.0'."
}
},
"required": [
"system",
"package",
"version"
]
}Esquema de salida
{
"type": "object"
}🟢get_project_health(projectKey)
Get a project's OpenSSF Scorecard security posture and maintenance signals. THE trust check. Returns supply-chain trust signals for a package's source repository: the OpenSSF Scorecard overall score (0-10) and per-check results (Maintained, Code-Review, Signed-Releases, Branch-Protection, Pinned-Dependencies, Dangerous-Workflow, Token-Permissions, Security-Policy, Vulnerabilities, ...), plus stars, forks, open-issue count, and license. Use it to judge whether a dependency is actively maintained and securely operated, not just whether it has a known CVE. Get the projectKey from a version's SOURCE_REPO link (call get_package_version first), e.g. 'github.com/facebook/react'.
Esquema de entrada
{
"type": "object",
"properties": {
"projectKey": {
"type": "string",
"x-in": "path",
"description": "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version)."
}
},
"required": [
"projectKey"
]
}Esquema de salida
{
"type": "object"
}Prompts recomendados
get_advisoryget_advisoryComunidad
Evidencia