mcpbeat Sign in

Depcheck MCP Server

answering

Depcheck is answering right now. Last checked 11 min ago. It exposes 1 tools.

Known vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402.

Uptime history 17 days of history · worst day 99%
17 days agonow
100.0%
Uptime 24h
91 of 91 checks
1
Tools
read from the server
123 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check Depcheck every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 11 min ago.

run in your terminal
claude mcp add depcheck --transport http https://depcheck.kaneky.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "depcheck": {
      "url": "https://depcheck.kaneky.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.depcheck]
url = "https://depcheck.kaneky.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "depcheck": {
      "url": "https://depcheck.kaneky.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "depcheck": {
      "url": "https://depcheck.kaneky.dev/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

packages
check_packages
Look up the known vulnerabilities affecting exact package versions in the public OSV database (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex), 1 to 50 packages per call. Per package: every OSV advisory for that version with its id, CVE/GHSA aliases, summary, severity (database label, CVSS vectors, v3 base scores), the versions that fix it or "no fix published", published/modified dates and a link. Plus a summary: packages checked, packages vulnerable, total advisories and the highest severity. Evidence, not advice: absence from OSV does not prove safety.

Endpoints

URLTransportStateLatencyChecked
https://depcheck.kaneky.dev/mcp streamable-http answering 122 ms 11 min ago

Alternatives to Depcheck

same job, measured the same way
OSV Advisories
by basitalisandhu

Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.

local only
Package Health Check
by openkrill

Check an npm or Python package, or a package.json, for vulnerabilities and upkeep.

5 tools answering
Osv Advisory MCP Server
by cyanheads

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

321 installs/wk 4 tools answering
Exploitwatch
by vercel-exploitwatch-kappa

Check dependencies against CISA's real Known Exploited Vulnerabilities feed.

1 tools answering
Cisa Kev MCP
by csoai-org

CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...

188 installs/wk local only
MCPAmpel - MCP Security Scanner
by diemoeve

Scan installed MCP servers for security vulnerabilities with 16 detection engines.

92 installs/wk local only
Agent Security Scanner MCP
by sinewaveai

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

411 installs/wk local only
ScanLabsAI Security Scanner
by scanlabsai

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

33 installs/wk 8 tools answering

Depcheck — questions

Answers built from our own checks of this server.

What can Depcheck do?
It exposes 1 tools, read directly from the server on our last check. Among them: check_packages. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Depcheck working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 123 ms. The bar chart above shows every period we have measured.
How do I connect Depcheck?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Depcheck need an API key?
No. Depcheck completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Depcheck?
It answers our handshake in 123 ms on average, which is faster than 77% of all working MCP servers we measure. That puts it in the quick quarter of the ecosystem. The comparison comes from our own checks across the whole registry, every 15 minutes.