Depcheck
Known vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}リモートエンドポイント
https://depcheck.kaneky.dev/mcpstreamable-httpできること
ツール一覧
ツール(1)
🟢check_packages(packages)
Look up the known vulnerabilities affecting exact package versions in the public OSV database (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex), 1 to 50 packages per call. Per package: every OSV advisory for that version with its id, CVE/GHSA aliases, summary, severity (database label, CVSS vectors, v3 base scores), the versions that fix it or "no fix published", published/modified dates and a link. Plus a summary: packages checked, packages vulnerable, total advisories and the highest severity. Evidence, not advice: absence from OSV does not prove safety.
入力スキーマ
{
"type": "object",
"properties": {
"packages": {
"items": {
"properties": {
"ecosystem": {
"description": "OSV's ecosystem name, case-sensitive.",
"enum": [
"npm",
"PyPI",
"Go",
"Maven",
"crates.io",
"RubyGems",
"NuGet",
"Packagist",
"Pub",
"Hex"
],
"type": "string"
},
"name": {
"description": "As the ecosystem names it: lodash, requests, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core.",
"maxLength": 214,
"minLength": 1,
"type": "string"
},
"version": {
"description": "The exact version, not a range.",
"maxLength": 128,
"minLength": 1,
"type": "string"
}
},
"required": [
"ecosystem",
"name",
"version"
],
"type": "object"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"packages"
]
}コミュニティ
エビデンス