DepScout

Scan packages and lockfiles (npm, PyPI, Go, Maven, Cargo, NuGet) for vulnerabilities and malware.

使うべきか

品質と安全性

A
説明の品質
100%
スキーマの完全性
100%
命名の品質
100%
ポイズニングのリスク
100%
権限の一致
100%
プロトコルへの準拠
100%

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~1,397トークン数(ツール定義)
~1.6 KB一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 1.09%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "depscout": {
      "url": "https://depscout.salesup.workers.dev/mcp"
    }
  }
}

リモートエンドポイント

https://depscout.salesup.workers.dev/mcpstreamable-http

できること

ツール一覧

ツール(4)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟢check_package(ecosystem, name, version)

Check one open-source package (npm, PyPI, Go, Maven, crates.io or NuGet) for safety and freshness. Returns a malicious-package flag (from OSV MAL- and malware advisories), known vulnerabilities with severity and the version that fixes each, the minimum version that clears all of them, the latest stable version, whether the given version is outdated or deprecated, licences, last release date, and the linked repository's OpenSSF Scorecard. If no version is given, the latest version is checked. Use when the user asks "is <package> safe?", "is it malware?", "which version should I use?", "should I upgrade?", or about a package's known CVEs, and before recommending any package or version to install (npm install, pip install, go get, cargo add, etc.). Data comes from OSV.dev and deps.dev; newly published malware may not be listed yet.

入力スキーマ

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "minLength": 2,
      "maxLength": 20,
      "description": "Package ecosystem: npm, PyPI, Go, Maven, crates.io or NuGet (aliases like pip, python, cargo, rust, golang, java, dotnet also work)"
    },
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 214,
      "description": "Package name, e.g. lodash, @types/node, requests, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core, serde, Newtonsoft.Json"
    },
    "version": {
      "description": "Optional exact version to check, e.g. 4.17.15. Omit to check the latest release",
      "type": "string",
      "maxLength": 80
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_dependencies(ecosystem, packages)

Check up to 50 packages at exact versions (for example from package.json, package-lock.json, requirements.txt, go.mod, pom.xml, Cargo.toml or a .csproj) against OSV.dev in one batch. Returns a summary count and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the version that fixes each and the minimum upgrade target. Use when the user pastes a dependency file or list, or asks to "audit my dependencies" or "check my package.json / requirements.txt", or which dependencies are vulnerable or outdated. Entries without an exact version are skipped and listed; transitive dependencies are only checked if included in the list.

入力スキーマ

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "description": "Default ecosystem for all entries. Package ecosystem: npm, PyPI, Go, Maven, crates.io or NuGet (aliases like pip, python, cargo, rust, golang, java, dotnet also work)",
      "type": "string",
      "minLength": 2,
      "maxLength": 20
    },
    "packages": {
      "minItems": 1,
      "maxItems": 50,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "ecosystem": {
            "description": "Ecosystem for this entry; defaults to the top-level ecosystem",
            "type": "string",
            "minLength": 2,
            "maxLength": 20
          },
          "name": {
            "type": "string",
            "minLength": 1,
            "maxLength": 214
          },
          "version": {
            "type": "string",
            "minLength": 1,
            "maxLength": 80,
            "description": "Exact installed version, e.g. 4.17.15"
          }
        },
        "required": [
          "name",
          "version"
        ]
      },
      "description": "Packages to check, each with name and exact version"
    }
  },
  "required": [
    "packages"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢check_lockfile(content, filename)

Audit a whole lockfile or dependency file in one call, including transitive dependencies where the file records them. Paste the file content as-is: package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml, requirements.txt (== pins), poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, go.sum, go.mod, packages.lock.json (NuGet) or gradle.lockfile. Up to 3,000 packages are checked against OSV.dev. Returns a summary and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the minimum upgrade target. Use when the user pastes or attaches a lockfile, asks for a full or transitive dependency audit, or asks "is my project vulnerable?". Prefer this over check_dependencies when the user has the file itself.

入力スキーマ

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "minLength": 10,
      "maxLength": 3000000,
      "description": "The full text of the lockfile or dependency file, pasted as-is"
    },
    "filename": {
      "description": "File name, e.g. package-lock.json, yarn.lock, Cargo.lock, go.sum, poetry.lock. Helps detect the format",
      "type": "string",
      "maxLength": 120
    }
  },
  "required": [
    "content"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_vulnerability(id)

Look up one vulnerability or malicious-package advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC, MAL and other OSV IDs) and return its summary, severity, CVSS vector, aliases, publish date, the affected packages with their affected and fixed version ranges, and key references. Use when the user mentions a specific advisory or CVE ID ("what is CVE-2021-44228?", "am I affected by this GHSA?") and wants to know what it is, what is affected or which version fixes it. Only covers advisories in OSV.dev.

入力スキーマ

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "minLength": 5,
      "maxLength": 80,
      "description": "Advisory ID, e.g. CVE-2021-44228, GHSA-29mw-wpgm-hmr9, PYSEC-2018-28, MAL-2025-20690"
    }
  },
  "required": [
    "id"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 4 件