cuttalo/depscope
cuttalo/depscope cuttalo/depscope](https://glama.ai/mcp/servers/cuttalo/depscope) π βοΈ π - Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) β check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote URL https://mcp.depscope.dev/mcp or stdio `npx depscope-mcp`.
Block For Production
trustsnap_2a82d76e49614c35.- Tool Surface Design
- Tool Snapshot Churn
- Tool Namespace Clarity
- Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
- Fix the failing checks first, then revalidate to confirm the recovery path.
- Compare tool enumeration outputs between runs and remove non-deterministic behavior.
trustsnap_2a82d76e49614c35- AI crawler activity
- profile / compare API / report JSON / policy / ledger inspection
Current trust snapshot
trustsnap_2a82d76e49614c35Canonical machine links
Own this MCP?
Claim ownership, prove control with a GitHub, DNS, HTTP, MCP metadata, or email-domain challenge, revalidate now, publish a badge, configure monitoring, and unlock a verified server profile.
POST /v1/servers/awesome-cuttalo/depscope/revalidateBadge embed
[](https://verify.sentinelsignal.io/servers/awesome-cuttalo/depscope)
Publisher readiness checklist
3/7 readiness checks currently pass. Paid status never changes the objective score; it can add evidence, monitoring, badge analytics, and authenticated validation.
| Check | Status | How to improve |
|---|---|---|
| Ownership verified | Needs work | Prove GitHub, DNS, HTTP, MCP metadata, or domain-email control. |
| Fresh validation | Ready | Keep public evidence inside the 48h publisher launch window. |
| Healthy endpoint | Needs work | Remote endpoint should initialize and list tools reliably. |
| Score threshold | Needs work | Aim for score >= 70 before using production-readiness language. |
| Metadata complete | Ready | Publish description, homepage/docs, remote URL, and support metadata. |
| Risk posture reviewed | Needs work | Address OAuth, write-action, destructive-tool, and protocol findings. |
| Badge ready | Ready | Publish score and freshness badges only when current evidence exists. |
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Production readiness class
Evidence confidence
Recommended for
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initializeβ’ OKtools_listβ’ Errortransport_compliance_probeβ’ Warningstep_up_auth_probeβ’ Missingconnector_replay_probeβ’ Missing β Frozen tool snapshots must survive refresh.request_association_probeβ’ Missing β Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initializeβ’ OKtools_listβ’ Errortransport_compliance_probeβ’ Warning
Evidence provenance
action_safety_probeβ’ OK
Evidence provenance
tool_snapshot_probeβ’ Missingconnector_replay_probeβ’ Missing
Why compatibility is limited by client
Remediation checklist
OpenAI connectors expect OAuth for remote server auth.Dynamic client registration materially improves connector setup.tools/list must succeed.search fetch only is not yet satisfiedwrite actions present is not yet satisfiedoauth configured is not yet satisfied
Remediation checklist
tools/list must succeed.A useful Claude integration needs at least one exposed tool.search fetch only is not yet satisfiedwrite actions present is not yet satisfiedoauth configured is not yet satisfiedadmin refresh required is not yet satisfied
Remediation checklist
- No explicit blockers recorded.
Verdict traces
server_failingβ’ critical β’ Latest validation is failingtools_list_regressedβ’ critical β’ tools/list regressedauth_mode_changedβ’ high β’ Auth mode changed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Partially client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Partially client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing allowed | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Likely to fail
- auth_connect: Passes
- safe_write_review: Passes
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewPublic server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 01, 2026 01:00:03 PM UTC | Latest validation: failing | Score 53.3 with status failing. |
| Aug 01, 2026 01:00:03 PM UTC | Score changed | Score delta +0.1 versus the previous run. |
| Aug 01, 2026 01:00:03 PM UTC | Auth mode changed | Auth mode moved from unknown to public. |
| Jul 31, 2026 09:46:12 PM UTC | Score changed | Score delta +1.3 versus the previous run. |
| Jul 31, 2026 06:36:40 AM UTC | Score changed | Score delta +0.1 versus the previous run. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://github.com/cuttalo/depscope
- Docs: https://github.com/cuttalo/depscope
- Support: https://github.com/cuttalo/depscope
- Icon: none
- Remote endpoint: https://mcp.depscope.dev/mcp
- Server card: none
Security posture
Agent Commerce & Payment Readiness - Beta
Beta assessment. Verify separates commerce-adjacent context from observed payment execution. Usage, billing, pricing, card, wallet, or meter terms alone do not make a server payment-capable. This is not a certification of safety, compliance, or fraud prevention.
Warnings
No commerce-specific warnings generated.
Evidence
| Field | Value | Source | Matched terms | Confidence |
|---|---|---|---|---|
| commerce_signal | weak | server_metadata | limit, rate | low |
Recommended operator fixes
- No commerce-specific fixes suggested.
Tool capability & risk inventory
No tool inventory available from the latest validation run.
Write-action governance
Status detail: No unsafe write-action governance gaps detected on the latest validation.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
Need at least two validation runs before diffing action controls.
Why this score?
Algorithmic score breakdown
Compatibility profiles
Connector URL: https://mcp.depscope.dev/mcp # No OAuth metadata detected. # Server: awesome-cuttalo/depscope
{
"mcpServers": {
"depscope": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.depscope.dev/mcp"]
}
}
}
smithery mcp add "https://mcp.depscope.dev/mcp"
curl -sS https://mcp.depscope.dev/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| Critical | Ensure tools/list succeeds consistently | Tools discovery is the minimum viable contract for most MCP clients and directories. | Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.Playbook
|
| Critical | Respond to latest validation is failing | Core MCP flows did not validate successfully on the latest run. | Fix the failing checks first, then revalidate to confirm the recovery path.Playbook
|
| Critical | Respond to tools/list regressed | Tool discovery became less reliable on the latest run. | Compare tool enumeration outputs between runs and remove non-deterministic behavior.Playbook
|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Associate roots, sampling, and elicitation with active client requests | Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Keep connector refreshes backward compatible | Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| High | Publish a complete server card | Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals. | Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.Playbook
|
| High | Respond to auth mode changed | Auth mode changed from unknown to public. | Document the new auth posture and confirm protected-resource and challenge metadata still match reality.Playbook
|
| High | Stop asking users to paste secrets directly | Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server.Playbook
|
| Medium | Raise Interface Quality score | How well the tool/resource interface communicates and behaves under automation. | Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically.Playbook
|
| Medium | Reduce tool-surface churn | Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Medium | Repair prompts/list or stop advertising prompts | Prompt metadata should either work live or be removed from the advertised capability set. | Only advertise prompts if prompts/list works and prompt arguments are documented.Playbook
|
| Medium | Repair resources/list or stop advertising resources | Resource metadata should either work live or be removed from the advertised capability set. | Only advertise resources if resources/list works and resources expose stable URIs/types.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
| Low | Publish or reconcile the server in the official MCP registry | Official registry presence improves discovery confidence and cross-source consistency. | Inspect the latest validation evidence and resolve the client-visible regression.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Tool Surface Design | 0/4 | -4.0 |
| Tool Snapshot Churn | 0/4 | -4.0 |
| Tool Namespace Clarity | 0/4 | -4.0 |
| Tool Capability Clarity | 0/4 | -4.0 |
| Schema Completeness | 0/4 | -4.0 |
| Result Shape Stability | 0/4 | -4.0 |
| Input Sanitization Safety | 0/4 | -4.0 |
| Recovery Semantics | 0.4/4 | -3.6 |
| Trust Confidence | 0.4/4 | -3.6 |
| Error Contract | 0.5/4 | -3.5 |
| Dependency Supply Chain Signal | 0.5/4 | -3.5 |
| SLO Health | 1.3/4 | -2.7 |
Validation diff
Regressed checks: connector_publishability_probe, oauth_protected_resource, server_card, tools_list
Improved checks: action_safety_probe, initialize, probe_noise_resilience, provenance_divergence_probe, session_resume_probe
| Component | Previous | Latest | Delta |
|---|---|---|---|
slo_health_score | 2.0 | 1.28 | -0.72 |
freshness_confidence_score | 1.5 | 2.0 | 0.5 |
maintenance_signal_score | 1.85 | 2.05 | 0.2 |
trust_confidence_score | 0.3 | 0.4 | 0.1 |
Tool snapshot diff & changelog
Need at least two validation runs before building a tool changelog.
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Transport compliance drilldown
Issues: missing_protocol_header
Request association
Utility coverage
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Likely to fail |
|
| Read-only fetch flow | Likely to fail |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Passes |
|
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | n/a |
| Version | n/a | n/a |
| Homepage | n/a | n/a |
Active alerts
- Latest validation is failing (critical)
Core MCP flows did not validate successfully on the latest run. - tools/list regressed (critical)
Tool discovery became less reliable on the latest run. - Auth mode changed (high)
Auth mode changed from unknown to public.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
awesome-cuttalo/depscope |
awesome_mcp_servers | yes | 53.29 |
cuttalo/depscope |
glama_registry | no | 46.45 |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| Registry source | Multiple registries or registry sync paths claim this same canonical server. | awesome_mcp_servers glama_registry |
| Remote URL | Aliases currently point at different MCP endpoints, which can indicate mirrors, stale registry data, or a real endpoint split. | https://glama.ai/mcp/servers/e5nnosy6xx https://mcp.depscope.dev/mcp |
| Homepage | Registry entries disagree on the primary homepage for this server. | https://github.com/cuttalo/depscope https://glama.ai/mcp/servers/e5nnosy6xx |
| Registry identifier | Different registry-specific identifiers resolve to the same canonical server record here. | awesome_mcp_servers:cuttalo/depscope glama_registry:e5nnosy6xx |
Install snippets
Connector URL: https://mcp.depscope.dev/mcp # No OAuth metadata detected. # Server: awesome-cuttalo/depscope
{
"mcpServers": {
"depscope": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.depscope.dev/mcp"]
}
}
}
smithery mcp add "https://mcp.depscope.dev/mcp"
curl -sS https://mcp.depscope.dev/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.awesome-cuttalo/depscope.Claims & monitoring
No verified maintainer claim recorded.
Alert routing
| Watch | Team | Channels | Minimum severity |
|---|---|---|---|
| No active watch destinations. | |||
Maintainer analytics
Maintainer response quality
Maintainer annotations
No maintainer annotations have been recorded yet.
Maintainer rebuttals & expected behavior
No maintainer rebuttals or expected-behavior overrides are recorded yet.
Latest validation evidence
Failures
oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization serverserver_cardClient error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404tools_listClient error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
OK | n/a | No high-risk write, destructive, or exec tools detected. |
advanced_capabilities_probe |
Missing | n/a | No advanced MCP capability signals detected. |
connector_publishability_probe |
Error | n/a | Publishability blockers: tools list, server card, tool surface. |
connector_replay_probe |
Missing | n/a | No connector replay evidence recorded. |
determinism_probe |
Missing | n/a | tools list unavailable |
initialize |
OK | 189.9 ms | Protocol 2025-03-26 |
interactive_flow_probe |
Missing | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 275.3 ms | Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
Warning | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 198.6 ms | Fetched https://mcp.depscope.dev/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Missing | 291.8 ms | Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400 |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
OK | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Missing | 296.7 ms | Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400 |
server_card |
Error | 228.2 ms | Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
session_resume_probe |
OK | 293.5 ms | 22 tool(s) exposed |
step_up_auth_probe |
Missing | n/a | No OAuth or incremental-scope signals detected. |
tool_snapshot_probe |
Missing | n/a | no tools |
tools_list |
Error | 178.4 ms | Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400 |
transport_compliance_probe |
Warning | 428.2 ms | Issues: missing protocol header (bad protocol=400, DELETE=200, expired session=404). |
utility_coverage_probe |
Missing | 211.0 ms | No completions evidence; no pagination evidence; tasks missing. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": false,
"confirmation_signals": [],
"safeguard_count": 0,
"summary": {
"bulk_access_tools": 0,
"capability_distribution": {},
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 0,
"medium": 0
},
"secret_tools": 0,
"tool_count": 0
}
},
"latency_ms": null,
"status": "ok"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": false,
"resource_links": false,
"resources": false,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [],
"enabled_count": 0,
"initialize_capability_keys": [
"tools"
]
},
"latency_ms": null,
"status": "missing"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"tools_list",
"server_card",
"tool_surface"
],
"criteria": {
"action_safety": true,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": true,
"remote_transport": true,
"request_association": true,
"server_card": false,
"session_resume": true,
"step_up_auth": true,
"tool_surface": false,
"tools_list": false,
"transport_compliance": true
},
"high_risk_tools": 0,
"tool_count": 0,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "error"
},
"connector_replay_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"determinism_probe": {
"details": {
"reason": "tools_list_unavailable"
},
"latency_ms": null,
"status": "missing"
},
"initialize": {
"details": {
"headers": {
"content-type": "text/event-stream",
"mcp-session-id": "7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"tools": {}
},
"instructions": "DepScope: dependency safety & intelligence MCP for AI agents. Covers 19 package ecosystems: npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia.\n\nINVOKE PROACTIVELY \u2014 before suggesting any package install, version bump, lockfile change, or when a 'module not found' / 'package broken' error appears. Do NOT wait for the user to ask.\n\nThree pillars:\n- TOKEN-SAVING: one DepScope call replaces a web search + readme fetch + npm/pypi page browse.\n- ENERGY-SAVING: skip installs of malicious, typosquatted, deprecated or hallucinated packages \u2014 no wasted CI cycles or rollbacks.\n- SECURITY: stop supply-chain attacks (malware, typosquats, hostile takeovers, known CVEs) BEFORE the install command leaves your reply.\n\nStandard flow for any new package:\n1. check_malicious + check_typosquat \u2014 security gate (~50ms)\n2. check_package OR get_health_score \u2014 verdict\n3. install_command \u2014 returns the safe pinned command\n\nBatch installs (>=2 packages): use check_bulk in ONE call (\u2264100 items, <100ms).\nLockfile / requirements.txt / package.json change: use scan_project.\nVersion bumps (X@1 \u2192 X@2): use get_breaking_changes + get_migration_path.\nDiagnose 'module not found' / 'X.Y broken' errors: use resolve_error and get_known_bugs.\nChoosing between libraries: use find_alternatives and compare_packages.\n\nAll tools are read-only, zero-auth, free. Never destructive. Latency typically 50-300ms per call.",
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "depscope",
"version": "0.9.0"
}
}
},
"url": "https://mcp.depscope.dev/mcp"
},
"latency_ms": 189.88,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": []
},
"latency_ms": null,
"status": "missing"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.depscope.dev/.well-known/oauth-protected-resource"
},
"latency_ms": 275.28,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": false,
"official_identifiers": [
"ai.ai-akari/one-minute-akari",
"ai.filtrix.mcp/filtrix-ai",
"ai.findip/patent-search",
"ai.finstat/finstat",
"ai.artidrop/artidrop",
"ai.agentutility/mcp-browser-workflow",
"ai.fodda/brand-intelligence",
"ai.afmr/discovery",
"ai.boolsai/directory",
"ai.agenticfabricationnetwork/ufp"
],
"official_peer_count": 10,
"registry_source": "awesome_mcp_servers"
},
"latency_ms": null,
"status": "warning"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/plain; charset=UTF-8",
"strict-transport-security": "max-age=63072000; includeSubDomains; preload"
},
"http_status": 200,
"url": "https://mcp.depscope.dev/robots.txt"
},
"latency_ms": 198.6,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"error": "Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400",
"headers": {
"content-type": "application/json"
},
"http_status": 400,
"payload": {},
"reason": "not_advertised",
"url": "https://mcp.depscope.dev/mcp"
},
"latency_ms": 291.82,
"status": "missing"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"direct_official_match": false,
"drift_fields": [],
"metadata_document_count": 1,
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": null,
"server_card_version": null
},
"latency_ms": null,
"status": "ok"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"error": "Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400",
"headers": {
"content-type": "application/json"
},
"http_status": 400,
"payload": {},
"reason": "not_advertised",
"url": "https://mcp.depscope.dev/mcp"
},
"latency_ms": 296.7,
"status": "missing"
},
"server_card": {
"details": {
"error": "Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.depscope.dev/.well-known/mcp/server-card.json"
},
"latency_ms": 228.18,
"status": "error"
},
"session_resume_probe": {
"details": {
"headers": {
"content-type": "text/event-stream",
"mcp-session-id": "7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"
},
"http_status": 200,
"payload": {
"id": 301,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "check_malicious"
},
"description": "Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_malicious"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "check_typosquat"
},
"description": "Typosquat detector. USE WHEN: name differs from a well-known package by 1-2 chars (`lodsh`, `reqeusts`); copy-paste from unreliable source; downloads near zero but name looks familiar. RETURNS: {is_typosquat, likely_target, confidence}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_typosquat"
},
{
"annotations": {
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "check_bulk"
},
"description": "Fast pre-flight filter for a batch of (ecosystem, package) pairs. DB-only, <100ms for 100 items. USE WHEN: about to emit `npm install a b c \u2026` or `pip install a b c \u2026` \u2014 catches hallucinated names, stdlib, typos, and known-bad in ONE call. NOT a dep-tree audit (use scan_project for that). RETURNS: per-item {status: exists|stdlib|malicious|typosquat_suspect|historical_incident|unknown}.",
"inputSchema": {
"properties": {
"items": {
"items": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
}
},
"required": [
"items"
],
"type": "object"
},
"name": "check_bulk"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "package_exists"
},
"description": "Boolean registry existence check. USE WHEN: about to emit a package name in an install command but unsure it exists; verifying a name generated from training data. RETURNS: {exists}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "package_exists"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_latest_version"
},
"description": "Latest published version + deprecation flag \u2014 the cheapest call. USE WHEN: only a version string matters (pinning a dep, answering 'what version of X'). If you also need health/vulns use check_package. RETURNS: {latest, deprecated, published_at}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_latest_version"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_health_score"
},
"description": "Single 0-100 health score \u2014 cheapest go/no-go gate (>=70 safe). USE WHEN: CI gating or pkg already screened for malware/typos. NOT a first screen \u2014 run check_malicious + check_typosquat first. For a verbal verdict use get_package_prompt. RETURNS: {score, verdict}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_health_score"
},
{
"annotations": {
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "install_command"
},
"description": "Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, \u2026). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
},
"version": {
"description": "Optional explicit version; defaults to latest.",
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "install_command"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_package_prompt"
},
"description": "LLM-optimised package brief \u2014 plain text ~300 tokens (~75% cheaper than JSON). Verdict (SAFE/AVOID/URGENT/MALICIOUS) + health + vulns + alternatives + maintainer alerts. USE WHEN: you want to reason over a package and drop the output directly in context; 'is X safe'. PREFER THIS over check_package in 95% of LLM cases. RETURNS: plain-text brief.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_package_prompt"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "check_package"
},
"description": "Full machine-readable JSON report (~2k tokens). USE WHEN: you need to programmatically parse specific fields (CI gating, UI, sub-field extraction). Otherwise prefer get_package_prompt. RETURNS: {package, health:{score}, vulnerabilities[], latest, deprecated, maintainers, recommendation}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"description": "Package name (e.g. 'express', 'fastapi', 'serde').",
"type": "string"
},
"version": {
"description": "Specific version (optional; default = latest).",
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_package"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_vulnerabilities"
},
"description": "CVE/OSV advisories affecting the latest (or specified) version. USE WHEN: security-sensitive project; user asks 'any CVEs in X'; you already know the pkg exists. RETURNS: {vulnerability_count, vulnerabilities[]: {id, severity, cvss, fixed_in}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_vulnerabilities"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "find_alternatives"
},
"description": "Curated replacements for deprecated/unhealthy packages, including stdlib built-ins (e.g. `fs.rm` for rimraf). USE WHEN: pkg flagged AVOID/URGENT; 'what to use instead of X'; before guessing a replacement name. RETURNS: {alternatives[]: {name, reason, is_stdlib}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "find_alternatives"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_migration_path"
},
"description": "Prescriptive migration plan between DIFFERENT packages \u2014 rationale + literal code diff + breaking changes + effort minutes. USE WHEN: replacing `request`\u2192`axios`, `moment`\u2192`dayjs`, `flask`\u2192`fastapi`, etc.; both endpoints known. RETURNS: {rationale, diff, breaking_changes[], estimated_minutes}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"from_package": {
"description": "Deprecated/legacy package to migrate away from.",
"type": "string"
},
"to_package": {
"description": "Modern replacement package.",
"type": "string"
}
},
"required": [
"ecosystem",
"from_package",
"to_package"
],
"type": "object"
},
"name": "get_migration_path"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_breaking_changes"
},
"description": "Breaking changes between two majors of the SAME package (`next@14`\u2192`15`). USE WHEN: user is bumping a major; before recommending a major upgrade. Different from get_migration_path (same pkg vs. different pkg). RETURNS: {breaking_changes[]: {area, description, hint}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"from_version": {
"type": "string"
},
"package": {
"type": "string"
},
"to_version": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_breaking_changes"
},
{
"annotations": {
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "pin_safe"
},
"description": "Highest version below the chosen CVE severity tier, respecting a semver constraint. USE WHEN: writing a package.json/requirements.txt line; resolving dependabot by lowest-risk patched version. RETURNS: {recommended_version, walk_log[]}.",
"inputSchema": {
"properties": {
"constraint": {
"description": "npm-style constraint: ^X.Y.Z, ~X.Y.Z, >=X.Y.Z, or exact X.Y.Z.",
"type": "string"
},
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"include_prerelease": {
"default": false,
"type": "boolean"
},
"min_severity": {
"description": "Lowest severity to exclude. Default: high (excludes critical+high).",
"enum": [
"critical",
"high",
"medium",
"low"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "pin_safe"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "scan_project"
},
"description": "Audit a project's dependencies in one shot. Returns a single-sentence `verdict` (e.g. \"DO NOT INSTALL \u2014 1 hallucinated: fastapi-turbo\") that an agent can paste into its reply, plus per-package health/vulns/recommendation. Detects hallucinated packages, deprecated, typosquats, critical vulnerabilities. Accepts EITHER {ecosystem, packages:[name@ver, \u2026]} (up to 100, returns JSON) OR {packages:[{ecosystem, package}, \u2026]} (up to 50, mixed ecosystems, returns text brief). USE WHEN: user pastes package.json/requirements.txt/Cargo.toml; agent generated install command; 'is my stack OK'. RETURNS: JSON with `verdict`, `project_risk`, `summary.hallucinated_packages`, `summary.deprecated_packages`, per-package health.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "Required when packages is a string array.",
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"packages": {
"description": "Either ['express','lodash@4.17.0'] (single ecosystem, up to 100) or [{ecosystem, package}, \u2026] (mixed, up to 50)."
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "scan_project"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "compare_packages"
},
"description": "Side-by-side comparison (health, vulns, downloads, maintainers, last release) of 2-10 packages in the same ecosystem. USE WHEN: 'X vs Y' / 'should I pick X or Y'. RETURNS: table-shaped JSON, one row per package.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"packages": {
"description": "Package names to compare, e.g. ['express','fastify','hono'].",
"items": {
"type": "string"
},
"maxItems": 10,
"minItems": 2,
"type": "array"
}
},
"required": [
"ecosystem",
"packages"
],
"type": "object"
},
"name": "compare_packages"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "check_compatibility"
},
"description": "Is this specific multi-package version combo verified to work together? USE WHEN: pinning a stack (next@15 + react@19 + node@22); before recommending a version matrix. RETURNS: {compatible, conflicts[], notes}.",
"inputSchema": {
"properties": {
"packages": {
"additionalProperties": {
"type": "string"
},
"description": "Package -> version map, e.g. {\"next\":\"15\",\"react\":\"19\"}.",
"type": "object"
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "check_compatibility"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "resolve_error"
},
"description": "Map error OR free-text query to a verified fix. USE WHEN: user pastes a concrete error/stack (ENOENT, ImportError, build failure) \u2014 pass `error`. OR user describes a symptom ('webpack slow', 'pip stuck') \u2014 pass `query`. Always prefer this over guessing a fix. RETURNS: exact-match {status, solution, confidence, source_url} or search results [{title, summary, source_url}].",
"inputSchema": {
"properties": {
"context": {
"description": "Optional context for error-mode calls (ecosystem, package, version).",
"type": "object"
},
"error": {
"description": "Concrete error message / stack trace. Triggers exact-match lookup.",
"type": "string"
},
"limit": {
"default": 10,
"description": "Max search results (query mode only).",
"maximum": 20,
"minimum": 1,
"type": "integer"
},
"query": {
"description": "Free-text symptom description. Triggers KB search.",
"type": "string"
}
},
"type": "object"
},
"name": "resolve_error"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_known_bugs"
},
"description": "Non-CVE known bugs for a specific package version. USE WHEN: unexpected behavior that is NOT a security issue; a pinned version misbehaves. RETURNS: {bugs[]: {title, fixed_in, workaround}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
},
"version": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_known_bugs"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_trust_signals"
},
"description": "One-call aggregate of ALL non-CVE supply-chain trust signals: maintainer trust (bus factor, ownership changes), OpenSSF Scorecard, quality (criticality, release velocity, publish security), and SLSA/Sigstore provenance. USE WHEN: deep-vetting a package beyond CVEs (hardened/regulated env, SBOM/compliance, small-pkg ownership review, choosing between healthy candidates). Runs 4 backend endpoints in parallel. RETURNS: {maintainer, scorecard, quality, provenance} \u2014 each may be null if its backend call failed.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_trust_signals"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "get_trending"
},
"description": "Live trending packages with rank-delta and weekly growth %. USE WHEN: 'what is rising in npm/PyPI/Cargo right now'; recommendation not biased by training-data cutoff. RETURNS: {items[]: {name, rank, rank_delta, weekly_growth_pct}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "Optional. If omitted returns cross-ecosystem trending.",
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"limit": {
"description": "Max results, 1-50. Default 20.",
"type": "integer"
},
"scope": {
"description": "Time window. Defaults to week.",
"enum": [
"all",
"week",
"day"
],
"type": "string"
}
},
"type": "object"
},
"name": "get_trending"
},
{
"annotations": {
"destructiveHint": false,
"idempotentHint": false,
"openWorldHint": true,
"readOnlyHint": false,
"title": "contact_depscope"
},
"description": "Inbound ticket: bug/listing/security/anomaly/partnership. USE WHEN: reporting wrong data (`bug`), requesting a new pkg/ecosystem index (`listing`), disclosing a DepScope security issue (`security`), flagging a concrete mismatch in another tool's output vs. authoritative source (`anomaly` \u2014 provide tool_called+observed+expected), or partnership/press (`partnership`). RETURNS: {ticket_id} or {anomaly_id}.",
"inputSchema": {
"properties": {
"body": {
"description": "Message body (10-8000 chars). Be specific: include package name, ecosystem, error trace, repro steps when applicable.",
"type": "string"
},
"company": {
"description": "Company / organization (optional).",
"type": "string"
},
"ecosystem": {
"description": "For kind=anomaly: ecosystem of the involved package, if any.",
"type": "string"
},
"email": {
"description": "Reply-to email of the requester (required for bug/listing/security/partnership).",
"type": "string"
},
"evidence_url": {
"description": "For kind=anomaly: URL to authoritative source (registry page, GHSA, CVE, repo, ...) supporting your expectation.",
"type": "string"
},
"expected": {
"description": "For kind=anomaly: what you expected to see (1-1500 chars). Be concrete.",
"type": "string"
},
"kind": {
"description": "Ticket category. `anomaly` routes to structured anomaly triage (requires tool_called/observed/expected).",
"enum": [
"bug",
"listing",
"security",
"anomaly",
"partnership"
],
"type": "string"
},
"name": {
"description": "Sender display name (optional).",
"type": "string"
},
"observed": {
"description": "For kind=anomaly: what DepScope returned (1-1500 chars).",
"type": "string"
},
"package": {
"description": "For kind=anomaly: package name involved, if any.",
"type": "string"
},
"subject": {
"description": "Short subject line (3-200 chars).",
"type": "string"
},
"tool_called": {
"description": "For kind=anomaly: DepScope tool that produced the anomaly (e.g. check_package, get_migration_path).",
"type": "string"
},
"version": {
"description": "For kind=anomaly: package version involved, if any.",
"type": "string"
}
},
"type": "object"
},
"name": "contact_depscope"
}
]
}
},
"requested_protocol_version": "2025-03-26",
"resumed": true,
"session_id_present": true,
"transport": "streamable-http",
"url": "https://mcp.depscope.dev/mcp"
},
"latency_ms": 293.49,
"status": "ok"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [],
"broad_scopes": [],
"challenge_headers": [],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [],
"supported_scopes": []
},
"latency_ms": null,
"status": "missing"
},
"tool_snapshot_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"tools_list": {
"details": {
"error": "Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400",
"headers": {
"content-type": "application/json"
},
"http_status": 400,
"payload": {},
"url": "https://mcp.depscope.dev/mcp"
},
"latency_ms": 178.41,
"status": "error"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json"
},
"bad_protocol_payload": {
"error": {
"code": -32000,
"message": "Bad Request: Unsupported protocol version: 1999-99-99 (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"
},
"id": null,
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 400,
"delete_error": null,
"delete_status_code": 200,
"expired_session_error": null,
"expired_session_status_code": 404,
"issues": [
"missing_protocol_header"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": true,
"transport": "streamable-http"
},
"latency_ms": 428.23,
"status": "warning"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 400,
"probe_status": "missing"
}
},
"latency_ms": 210.99,
"status": "missing"
}
},
"failures": {
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.depscope.dev/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
},
"server_card": {
"error": "Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.depscope.dev/.well-known/mcp/server-card.json"
},
"tools_list": {
"error": "Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400",
"headers": {
"content-type": "application/json"
},
"http_status": 400,
"payload": {},
"url": "https://mcp.depscope.dev/mcp"
}
},
"remote_url": "https://mcp.depscope.dev/mcp",
"server_card_payload": null,
"server_identifier": "awesome-cuttalo/depscope"
}
Known versions
- No versions recorded.
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 01, 2026 01:00:03 PM UTC | Failing | 53.3 | 2838.2 ms | 0 |
| Jul 31, 2026 09:46:12 PM UTC | Failing | 53.2 | 2422.0 ms | 0 |
| Jul 31, 2026 06:36:40 AM UTC | Failing | 51.9 | 2236.5 ms | 0 |
| Jul 31, 2026 06:36:40 AM UTC | Failing | 51.8 | 2369.4 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 01, 2026 01:00:03 PM UTC | Failing | 53.3 | 2025-03-26 | public | 0 | 0 | auth_mode_changed |
| Jul 31, 2026 09:46:12 PM UTC | Failing | 53.2 | unknown | unknown | 0 | 0 | none |
| Jul 31, 2026 06:36:40 AM UTC | Failing | 51.9 | unknown | unknown | 0 | 0 | none |
| Jul 31, 2026 06:36:40 AM UTC | Failing | 51.8 | unknown | unknown | 0 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 01, 2026 01:00:00 PM UTC | Completed | Failing | 2838.2 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Jul 31, 2026 09:46:10 PM UTC | Completed | Failing | 2422.0 ms | |
| Jul 31, 2026 06:36:38 AM UTC | Completed | Failing | 2236.5 ms | |
| Jul 31, 2026 06:36:38 AM UTC | Completed | Failing | 2369.4 ms | |