DepScout is answering right now. Last checked 12 min ago. It exposes 4 tools.
Scan packages and lockfiles (npm, PyPI, Go, Maven, Cargo, NuGet) for vulnerabilities and malware.
Today is the operative word: we check DepScout every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 12 min ago.
claude mcp add depscout --transport http https://depscout.salesup.workers.dev/mcp
{
"mcpServers": {
"depscout": {
"url": "https://depscout.salesup.workers.dev/mcp"
}
}
}
[mcp_servers.depscout]
url = "https://depscout.salesup.workers.dev/mcp"
{
"mcpServers": {
"depscout": {
"url": "https://depscout.salesup.workers.dev/mcp"
}
}
}
{
"mcpServers": {
"depscout": {
"url": "https://depscout.salesup.workers.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_dependencies
check_lockfile
check_package
get_vulnerability
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://depscout.salesup.workers.dev/mcp | streamable-http | answering | 149 ms | 12 min ago |
Query OSV.dev for known vulnerabilities by package and version, and scan lockfiles in batch.
Check an npm or Python package, or a package.json, for vulnerabilities and upkeep.
npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Answers built from our own checks of this server.