dependency-trust

Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
100%
命名品質
100%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,256Token(工具定義)
~1.2 KB典型回應大小
中等的注意力影響(128k 上下文的 0.98%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "dependency-trust": {
      "url": "https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d"
    }
  }
}

遠端端點

https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06dstreamable-http

它能做什麼

工具清單

工具(5)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢get_advisory(advisoryKey)

Get a security advisory (vulnerability) by its key. Returns a security advisory by key, for example a GHSA id taken from a version's advisoryKeys, including the title, CVE aliases, CVSS v3 score and vector, and a link to the full record on osv.dev. Use this only when you already have an advisory ID from get_package_version's advisoryKeys. There is no search here. To find out whether a version has vulnerabilities at all, call get_package_version first; this tool explains one advisory in depth.

輸入結構描述

{
  "type": "object",
  "properties": {
    "advisoryKey": {
      "type": "string",
      "x-in": "path",
      "description": "Advisory id, e.g. 'GHSA-29mw-wpgm-hmr9' (taken from a version's advisoryKeys)."
    }
  },
  "required": [
    "advisoryKey"
  ]
}

輸出結構描述

{
  "type": "object"
}
🟢get_dependencies(system, package, version)

Get the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version. Each node has the dependency's exact version and its relation (SELF / DIRECT / INDIRECT). Use it to reason about transitive dependencies and supply chain.

輸入結構描述

{
  "type": "object",
  "properties": {
    "system": {
      "enum": [
        "npm",
        "pypi",
        "go",
        "maven",
        "cargo",
        "nuget",
        "rubygems"
      ],
      "type": "string",
      "x-in": "path",
      "description": "Package ecosystem."
    },
    "package": {
      "type": "string",
      "x-in": "path",
      "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
    },
    "version": {
      "type": "string",
      "x-in": "path",
      "description": "Exact version string, e.g. '18.2.0'."
    }
  },
  "required": [
    "system",
    "package",
    "version"
  ]
}

輸出結構描述

{
  "type": "object"
}
🟢get_package(system, package)

List every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-version flag, and deprecation status. Use it to find the latest version or check if a package is deprecated. Coding agents should call this before recommending a package or version.

輸入結構描述

{
  "type": "object",
  "properties": {
    "system": {
      "enum": [
        "npm",
        "pypi",
        "go",
        "maven",
        "cargo",
        "nuget",
        "rubygems"
      ],
      "type": "string",
      "x-in": "path",
      "description": "Package ecosystem."
    },
    "package": {
      "type": "string",
      "x-in": "path",
      "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
    }
  },
  "required": [
    "system",
    "package"
  ]
}

輸出結構描述

{
  "type": "object"
}
🟢get_package_version(system, package, version)

Get license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses, security advisoryKeys (known vulnerabilities), homepage/issue-tracker/source-repo links, registries, publish date, and deprecation status. Pass any advisoryKey returned here to get_advisory for the vulnerability details.

輸入結構描述

{
  "type": "object",
  "properties": {
    "system": {
      "enum": [
        "npm",
        "pypi",
        "go",
        "maven",
        "cargo",
        "nuget",
        "rubygems"
      ],
      "type": "string",
      "x-in": "path",
      "description": "Package ecosystem."
    },
    "package": {
      "type": "string",
      "x-in": "path",
      "description": "Package name, raw and unencoded (the gateway URL-encodes it). Use scoped or namespaced names as-is, e.g. npm '@angular/core', Maven 'group:artifact'."
    },
    "version": {
      "type": "string",
      "x-in": "path",
      "description": "Exact version string, e.g. '18.2.0'."
    }
  },
  "required": [
    "system",
    "package",
    "version"
  ]
}

輸出結構描述

{
  "type": "object"
}
🟢get_project_health(projectKey)

Get a project's OpenSSF Scorecard security posture and maintenance signals. THE trust check. Returns supply-chain trust signals for a package's source repository: the OpenSSF Scorecard overall score (0-10) and per-check results (Maintained, Code-Review, Signed-Releases, Branch-Protection, Pinned-Dependencies, Dangerous-Workflow, Token-Permissions, Security-Policy, Vulnerabilities, ...), plus stars, forks, open-issue count, and license. Use it to judge whether a dependency is actively maintained and securely operated, not just whether it has a known CVE. Get the projectKey from a version's SOURCE_REPO link (call get_package_version first), e.g. 'github.com/facebook/react'.

輸入結構描述

{
  "type": "object",
  "properties": {
    "projectKey": {
      "type": "string",
      "x-in": "path",
      "description": "Source repository, raw and unencoded (the gateway URL-encodes it). Pass it as-is, e.g. 'github.com/facebook/react'. Supported hosts: github.com, gitlab.com, bitbucket.org. Take it from a version's SOURCE_REPO link (get_package_version)."
    }
  },
  "required": [
    "projectKey"
  ]
}

輸出結構描述

{
  "type": "object"
}

建議的提示詞

retrieve_data
Get details about [item] from dependency-trust
預期的工具: get_advisory
fetch_info
Fetch [information type] using dependency-trust
預期的工具: get_advisory

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本5 個工具
已驗證未記錄版本5 個工具