SafeDep Vet MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 16 Sep 2026.
Protect your AI agents and IDEs from malicious open-source packages.
We read the source, 21 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
path := filepath.Join(dir, filename)
const child = spawn(binPath, process.argv.slice(2), { stdio: "inherit" });
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Operate Resource Guru from your AI agent via MCP.
Operate PagerDuty from your AI agent via MCP.
Create and manage Form.io forms, resources, actions, roles, and projects from your AI agent.
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Open-source MCP server with browser automation and knowledge packs for AI agents
Progressive on-demand access to .NET NuGet package source for AI coding agents.
List, create and deploy your Prefab project templates from any MCP agent.
MCP server giving AI coding agents version-pinned API context from your OpenAPI specs.
Answers built from our own checks of this server.