Depcheck is answering right now. Last checked 11 min ago. It exposes 1 tools.
Known vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402.
Today is the operative word: we check Depcheck every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 11 min ago.
claude mcp add depcheck --transport http https://depcheck.kaneky.dev/mcp
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}
[mcp_servers.depcheck]
url = "https://depcheck.kaneky.dev/mcp"
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}
{
"mcpServers": {
"depcheck": {
"url": "https://depcheck.kaneky.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_packages
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://depcheck.kaneky.dev/mcp | streamable-http | answering | 122 ms | 11 min ago |
Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.
Check an npm or Python package, or a package.json, for vulnerabilities and upkeep.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...
Scan installed MCP servers for security vulnerabilities with 16 detection engines.
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Answers built from our own checks of this server.