mcpbeat Sign in

DepScout MCP Server

answering

DepScout is answering right now. Last checked 12 min ago. It exposes 4 tools.

Scan packages and lockfiles (npm, PyPI, Go, Maven, Cargo, NuGet) for vulnerabilities and malware.

Uptime history 4 days of history
4 days agonow
100.0%
Uptime 24h
91 of 91 checks
4
Tools
read from the server
152 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check DepScout every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 12 min ago.

run in your terminal
claude mcp add depscout --transport http https://depscout.salesup.workers.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "depscout": {
      "url": "https://depscout.salesup.workers.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.depscout]
url = "https://depscout.salesup.workers.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "depscout": {
      "url": "https://depscout.salesup.workers.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "depscout": {
      "url": "https://depscout.salesup.workers.dev/mcp"
    }
  }
}

Available tools 4

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

dependencies
check_dependencies
Check up to 50 packages at exact versions (for example from package.json, package-lock.json, requirements.txt, go.mod, pom.xml, Cargo.toml or a .csproj) against OSV.dev in one batch. Returns a summary count and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the version that fixes each and the minimum upgrade target. Use when the user pastes a dependency file or list, or asks to "audit my dependencies" or "check my package.json / requirements.txt", or which dependencies are vulnerable or outdated. Entries without an exact version are skipped and listed; transitive dependencies are only checked if included in the list.
lockfile
check_lockfile
Audit a whole lockfile or dependency file in one call, including transitive dependencies where the file records them. Paste the file content as-is: package-lock.json, npm-shrinkwrap.json, yarn.lock, pnpm-lock.yaml, requirements.txt (== pins), poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, go.sum, go.mod, packages.lock.json (NuGet) or gradle.lockfile. Up to 3,000 packages are checked against OSV.dev. Returns a summary and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the minimum upgrade target. Use when the user pastes or attaches a lockfile, asks for a full or transitive dependency audit, or asks "is my project vulnerable?". Prefer this over check_dependencies when the user has the file itself.
package
check_package
Check one open-source package (npm, PyPI, Go, Maven, crates.io or NuGet) for safety and freshness. Returns a malicious-package flag (from OSV MAL- and malware advisories), known vulnerabilities with severity and the version that fixes each, the minimum version that clears all of them, the latest stable version, whether the given version is outdated or deprecated, licences, last release date, and the linked repository's OpenSSF Scorecard. If no version is given, the latest version is checked. Use when the user asks "is <package> safe?", "is it malware?", "which version should I use?", "should I upgrade?", or about a package's known CVEs, and before recommending any package or version to install (npm install, pip install, go get, cargo add, etc.). Data comes from OSV.dev and deps.dev; newly published malware may not be listed yet.
vulnerability
get_vulnerability
Look up one vulnerability or malicious-package advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC, MAL and other OSV IDs) and return its summary, severity, CVSS vector, aliases, publish date, the affected packages with their affected and fixed version ranges, and key references. Use when the user mentions a specific advisory or CVE ID ("what is CVE-2021-44228?", "am I affected by this GHSA?") and wants to know what it is, what is affected or which version fixes it. Only covers advisories in OSV.dev.

Endpoints

URLTransportStateLatencyChecked
https://depscout.salesup.workers.dev/mcp streamable-http answering 149 ms 12 min ago

Alternatives to DepScout

same job, measured the same way
OSV Advisories
by basitalisandhu

Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.

local only
Package Health Check
by openkrill

Check an npm or Python package, or a package.json, for vulnerabilities and upkeep.

5 tools answering
npm Plus
by ofershap

npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads.

48 installs/wk local only
Osv Advisory MCP Server
by cyanheads

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

321 installs/wk 4 tools answering
Agent Security Scanner MCP
by sinewaveai

Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

411 installs/wk local only
ScriptDocs MCP
by timwal78

Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.

37 installs/wk local only
NPMScan
by salemalem

Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

23 tools answering
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

306 installs/wk local only

DepScout — questions

Answers built from our own checks of this server.

What can DepScout do?
It exposes 4 tools, read directly from the server on our last check. Among them: check_dependencies, check_lockfile, check_package, get_vulnerability. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is DepScout working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 152 ms. The bar chart above shows every period we have measured.
How do I connect DepScout?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does DepScout need an API key?
No. DepScout completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 4 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is DepScout?
It answers our handshake in 152 ms on average, which is faster than 71% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.