All apps & connectors
DepScout logo

DepScout

ClaudeCommunityby Salesup

DepScout checks open-source packages against live vulnerability and malware data, so answers about whether a package is safe, and which version to use, come from current advisories instead of model memory. What it does: - Checks one package (npm, PyPI, Go, Maven, crates.io or NuGet) at a given version or its latest release. It flags malicious packages and compromised releases first, then lists known vulnerabilities with severity, CVE IDs and the version that fixes each one, plus the minimum version that clears them all. - Reports the latest stable version, whether a version is outdated or deprecated, the last release date, licences, and the source repository's OpenSSF Scorecard. - Checks up to 50 pinned dependencies at once (for example from package.json, requirements.txt, go.mod or pom.xml) and returns only the ones with problems, with an upgrade target for each. - Explains a single advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC or MAL): severity, affected and fixed version ranges, and references. Who it's for: developers using Claude, Claude Code or other AI assistants who want to vet a dependency before installing it, triage an audit, or pick a safe version. Limitations: data comes from OSV.dev and deps.dev. A clean result means no known advisory for that exact version, not a guarantee of safety, and newly published malware may not be listed yet. Only the packages you list are checked, not their transitive dependencies. Version ranges are checked at the version written in them. DepScout is read-only and is not affiliated with OSV.dev, deps.dev, Google, the OpenSSF, GitHub or any package registry.

Details

Developer Tools
Listed Oct 2, 2026
by Salesup
MCP endpoint: https://depscout.salesup.workers.dev/mcp · streamable-http

Available tools (3)

check_dependenciescheck_packageget_vulnerability