{"schema_version":"verify.report.v1","generated_at":"2026-08-01T18:37:10.704097+00:00","snapshot_id":"trustsnap_2a82d76e49614c35","server":{"namespace":"awesome-cuttalo","name":"depscope","title":"cuttalo/depscope","description":"cuttalo/depscope cuttalo/depscope](https://glama.ai/mcp/servers/cuttalo/depscope) 📇 ☁️ 🏠 - Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) — check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote URL https://mcp.depscope.dev/mcp or stdio `npx depscope-mcp`.","homepage_url":"https://github.com/cuttalo/depscope","docs_url":"https://github.com/cuttalo/depscope","icon_url":null,"support_url":"https://github.com/cuttalo/depscope","remote_url":"https://mcp.depscope.dev/mcp","server_card_url":null,"latest_version":null,"current_status":"failing","current_score":53.29,"transport_type":"streamable-http","has_oauth":false,"has_dcr":false,"has_prompts":false,"tool_count":0,"current_validation_schema_version":"16d1d270090d6c8f","last_validated_at":"2026-08-01T13:00:03.499896+00:00","registry_source":"awesome_mcp_servers","registry_identifier":"awesome_mcp_servers:cuttalo/depscope","canonical_identifier":"awesome-cuttalo/depscope","current_score_components":{"auth_operability_score":2.0,"error_contract_score":0.5,"rate_limit_semantics_score":2.0,"schema_completeness_score":0.0,"backward_compatibility_score":4.0,"slo_health_score":1.28,"security_hygiene_score":2.0,"task_success_score":3.33,"trust_confidence_score":0.4,"abuse_noise_ratio_score":2.5,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":4.0,"registry_consistency_score":2.0,"installability_score":2.0,"session_semantics_score":2.5,"tool_surface_design_score":0.0,"result_shape_stability_score":0.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.38,"maintenance_signal_score":2.05,"adoption_signal_score":2.0,"freshness_confidence_score":2.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":4.0,"step_up_auth_score":3.0,"transport_compliance_score":3.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":2.0,"tool_snapshot_churn_score":0.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":3.0,"official_registry_presence_score":3.0,"provenance_divergence_score":4.0,"safety_transparency_score":2.0,"tool_capability_clarity_score":0.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":4.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":3.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":0.5,"input_sanitization_safety_score":0.0,"tool_namespace_clarity_score":0.0},"capability_taxonomy":["development","web","security","automation","streamable_http"],"machine_summary":{"verdict":"needs_remediation","best_for":["Generic Streamable HTTP"],"avoid_if":["You need a production-approved server today.","Latest validation is failing"],"requires_auth":false,"supports_oauth":false,"risk_level":"low"},"taxonomy_tags":["development","web","security","automation"],"score_decomposition":[{"key":"access_protocol","label":"Access & Protocol","score":31.5,"max_score":44.0,"hint":"Connectivity, auth, and transport expectations for common clients.","components":[{"key":"auth_operability_score","score":2.0},{"key":"installability_score","score":2.0},{"key":"session_semantics_score","score":2.5},{"key":"transport_fidelity_score","score":4.0},{"key":"spec_recency_score","score":2.0},{"key":"session_resume_score","score":4.0},{"key":"step_up_auth_score","score":3.0},{"key":"transport_compliance_score","score":3.0},{"key":"request_association_score","score":3.0},{"key":"oauth_interop_score","score":3.0},{"key":"least_privilege_scope_score","score":3.0}]},{"key":"interface_quality","label":"Interface Quality","score":13.88,"max_score":56.0,"hint":"How well the tool/resource interface communicates and behaves under automation.","components":[{"key":"error_contract_score","score":0.5},{"key":"rate_limit_semantics_score","score":2.0},{"key":"schema_completeness_score","score":0.0},{"key":"prompt_contract_score","score":2.0},{"key":"resource_contract_score","score":2.0},{"key":"tool_surface_design_score","score":0.0},{"key":"tool_capability_clarity_score","score":0.0},{"key":"tool_namespace_clarity_score","score":0.0},{"key":"result_shape_stability_score","score":0.0},{"key":"utility_coverage_score","score":2.0},{"key":"advanced_capability_coverage_score","score":2.0},{"key":"tool_snapshot_churn_score","score":0.0},{"key":"connector_replay_score","score":3.0},{"key":"recovery_semantics_score","score":0.38}]},{"key":"security_posture","label":"Security Posture","score":24.0,"max_score":36.0,"hint":"How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.","components":[{"key":"security_hygiene_score","score":2.0},{"key":"destructive_operation_safety_score","score":3.0},{"key":"egress_ssrf_resilience_score","score":3.0},{"key":"execution_sandbox_safety_score","score":4.0},{"key":"data_exfiltration_resilience_score","score":3.0},{"key":"secret_handling_hygiene_score","score":3.0},{"key":"input_sanitization_safety_score","score":0.0},{"key":"interactive_flow_safety_score","score":3.0},{"key":"action_safety_score","score":3.0}]},{"key":"reliability_trust","label":"Reliability & Trust","score":13.51,"max_score":24.0,"hint":"Operational stability, consistency, and trustworthiness over time.","components":[{"key":"backward_compatibility_score","score":4.0},{"key":"slo_health_score","score":1.28},{"key":"task_success_score","score":3.33},{"key":"trust_confidence_score","score":0.4},{"key":"abuse_noise_ratio_score","score":2.5},{"key":"freshness_confidence_score","score":2.0}]},{"key":"discovery_governance","label":"Discovery & Governance","score":17.55,"max_score":28.0,"hint":"How well the server is documented, listed, and governed in public registries.","components":[{"key":"discovery_metadata_score","score":4.0},{"key":"registry_consistency_score","score":2.0},{"key":"maintenance_signal_score","score":2.05},{"key":"safety_transparency_score","score":2.0},{"key":"dependency_supply_chain_signal_score","score":0.5},{"key":"official_registry_presence_score","score":3.0},{"key":"provenance_divergence_score","score":4.0}]},{"key":"adoption_market","label":"Adoption & Market","score":4.0,"max_score":8.0,"hint":"Adoption clues and public evidence that the server is intended for external use.","components":[{"key":"adoption_signal_score","score":2.0},{"key":"connector_publishability_score","score":2.0}]}],"validation_diff":{"latest_score":53.29,"previous_score":53.24,"score_delta":0.05,"latest_summary":"failing","previous_summary":"failing","summary_changed":false,"tool_count_delta":0,"prompt_count_delta":0,"resource_count_delta":0,"component_deltas":[{"key":"slo_health_score","latest":1.28,"previous":2.0,"delta":-0.72},{"key":"freshness_confidence_score","latest":2.0,"previous":1.5,"delta":0.5},{"key":"maintenance_signal_score","latest":2.05,"previous":1.85,"delta":0.2},{"key":"trust_confidence_score","latest":0.4,"previous":0.3,"delta":0.1}],"regressed_checks":[],"improved_checks":[],"tool_snapshot_diff":null,"auth_mode_changed":false,"latest_auth_mode":"public","previous_auth_mode":"public","write_action_surface_expanded":false,"latest_high_risk_tools":0,"previous_high_risk_tools":0,"protocol_regressed":false,"latest_protocol_version":"2025-03-26","previous_protocol_version":"2025-03-26","registry_drift_changed":false,"latest_registry_drift":[],"previous_registry_drift":[],"connector_refresh_breaking":false,"previous_connector_refresh_breaking":false,"request_association_violation":false,"previous_request_association_violation":false},"tool_snapshot_diff":null,"connector_replay":{"status":"missing","backward_compatible":false,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]},"request_association":{"status":"missing","advertised_capabilities":[],"session_id_present":false,"protocol_version":null,"observed_methods":[],"violating_methods":[],"http_status":null,"issues":[]},"production_readiness":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first.","badge":"score-low","critical_alerts":1},"recommended_for":[{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 83."}],"history_summary":{"points":[{"timestamp":"2026-07-31T06:36:40.479892+00:00","score":51.82,"status":"failing","latency_ms":2369.4,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-07-31T06:36:40.484620+00:00","score":51.9,"status":"failing","latency_ms":2236.46,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-07-31T21:46:12.817169+00:00","score":53.24,"status":"failing","latency_ms":2421.99,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-08-01T13:00:03.499896+00:00","score":53.29,"status":"failing","latency_ms":2838.19,"tool_count":0,"prompt_count":0,"resource_count":0}],"status_counts":{"failing":4},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":2466.51,"healthy_ratio_recent":0.0,"freshness_hours":5.62,"latest_status":"failing"},"validation_timeline":[{"timestamp":"2026-08-01T13:00:03.499896+00:00","summary_status":"failing","score":53.29,"protocol_version":"2025-03-26","auth_mode":"public","tool_count":0,"prompt_count":0,"resource_count":0,"high_risk_tools":0,"safe_to_publish":true,"change_flags":[]},{"timestamp":"2026-07-31T21:46:12.817169+00:00","summary_status":"failing","score":53.24,"protocol_version":"2025-03-26","auth_mode":"public","tool_count":0,"prompt_count":0,"resource_count":0,"high_risk_tools":0,"safe_to_publish":true,"change_flags":["auth_mode_changed"]},{"timestamp":"2026-07-31T06:36:40.484620+00:00","summary_status":"failing","score":51.9,"protocol_version":null,"auth_mode":"unknown","tool_count":0,"prompt_count":0,"resource_count":0,"high_risk_tools":0,"safe_to_publish":false,"change_flags":[]},{"timestamp":"2026-07-31T06:36:40.479892+00:00","summary_status":"failing","score":51.82,"protocol_version":null,"auth_mode":"unknown","tool_count":0,"prompt_count":0,"resource_count":0,"high_risk_tools":0,"safe_to_publish":false,"change_flags":[]}],"evidence_confidence":{"score":70.0,"label":"medium","reason":"Based on 4 recent validations, 26 captured checks, and validation age of 5.6 hours.","live_check_count":26,"validation_age_hours":5.62},"incident_feed":[{"type":"validation_snapshot","timestamp":"2026-08-01T13:00:03.499896+00:00","title":"Latest validation: failing","message":"Score 53.3 with status failing."},{"type":"score_change","timestamp":"2026-08-01T13:00:03.499896+00:00","title":"Score changed","message":"Score delta +0.1 versus the previous run."},{"type":"score_change","timestamp":"2026-07-31T21:46:12.817169+00:00","title":"Score changed","message":"Score delta +1.3 versus the previous run."},{"type":"auth_mode_change","timestamp":"2026-07-31T21:46:12.817169+00:00","title":"Auth mode changed","message":"Auth mode moved from unknown to public."},{"type":"score_change","timestamp":"2026-07-31T06:36:40.484620+00:00","title":"Score changed","message":"Score delta +0.1 versus the previous run."}],"remediations":[{"code":"fix_tools_list","severity":"critical","title":"Ensure tools/list succeeds consistently","why":"Tools discovery is the minimum viable contract for most MCP clients and directories.","action":"Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.","playbook":["Make `tools/list` deterministic across repeated calls.","Document or relax auth requirements for discovery routes.","Check that tool names, descriptions, and schemas remain stable across deploys."],"maintainer_context":null},{"code":"respond_server_failing","severity":"critical","title":"Respond to latest validation is failing","why":"Core MCP flows did not validate successfully on the latest run.","action":"Fix the failing checks first, then revalidate to confirm the recovery path.","playbook":["Fix the failing checks first.","Review the latest incident feed and validation diff for the first regression.","Revalidate once the remediation lands."]},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_adoption_market","severity":"medium","title":"Raise Adoption & Market score","why":"Adoption clues and public evidence that the server is intended for external use.","action":"Increase external documentation and directory coverage so users can discover and evaluate the server.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."]},{"code":"improve_interface_quality","severity":"medium","title":"Raise Interface Quality score","why":"How well the tool/resource interface communicates and behaves under automation.","action":"Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."]},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_to_official_registry","severity":"low","title":"Publish or reconcile the server in the official MCP registry","why":"Official registry presence improves discovery confidence and cross-source consistency.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"client_remediation_modes":[{"key":"openai_connectors","label":"ChatGPT custom connector","status":"partial","why_not_ready":[{"label":"OpenAI connectors expect OAuth for remote server auth.","state":"blocked"},{"label":"Dynamic client registration materially improves connector setup.","state":"blocked"},{"label":"tools/list must succeed.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"write actions present is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"claude_desktop","label":"Claude remote MCP","status":"partial","why_not_ready":[{"label":"tools/list must succeed.","state":"blocked"},{"label":"A useful Claude integration needs at least one exposed tool.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"write actions present is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"write_safe","label":"Write-safe publishing","status":"ready","why_not_ready":[],"maintainer_context":null}],"client_profiles":[{"key":"openai_connectors","label":"OpenAI Connectors","score":66.7,"compatibility":"partial","missing_requirements":["OpenAI connectors expect OAuth for remote server auth.","Dynamic client registration materially improves connector setup.","tools/list must succeed."],"snippet":"Connector URL: https://mcp.depscope.dev/mcp\n# No OAuth metadata detected.\n# Server: awesome-cuttalo/depscope"},{"key":"claude_desktop","label":"Claude Desktop","score":66.7,"compatibility":"partial","missing_requirements":["tools/list must succeed.","A useful Claude integration needs at least one exposed tool."],"snippet":"{\n  \"mcpServers\": {\n    \"depscope\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://mcp.depscope.dev/mcp\"]\n    }\n  }\n}"},{"key":"smithery","label":"Smithery","score":60.0,"compatibility":"partial","missing_requirements":["Tool discovery must succeed.","Machine-readable failure semantics should be present."],"snippet":"smithery mcp add \"https://mcp.depscope.dev/mcp\""},{"key":"generic_streamable_http","label":"Generic Streamable HTTP","score":83.3,"compatibility":"compatible","missing_requirements":["tools/list must succeed."],"snippet":"curl -sS https://mcp.depscope.dev/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"}],"client_readiness_verdicts":[{"key":"openai_connectors","label":"Client compatibility: ChatGPT","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; tools/list must succeed.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"error","source":"live_validation","note":null,"http_status":400},{"check":"transport_compliance_probe","status":"warning","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":"Frozen tool snapshots must survive refresh.","http_status":null},{"check":"request_association_probe","status":"missing","source":"live_validation","note":"Roots, sampling, and elicitation should stay request-scoped.","http_status":null}],"confidence":{"score":70.0,"label":"medium"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"claude_desktop","label":"Client compatibility: Claude","status":"partial","reason":"tools/list must succeed.; A useful Claude integration needs at least one exposed tool.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"error","source":"live_validation","note":null,"http_status":400},{"check":"transport_compliance_probe","status":"warning","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":70.0,"label":"medium"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"unsafe_for_write_actions","label":"Write-action publishing","status":"no","reason":"Current write surface is bounded enough for cautious review with production policy controls.","evidence":[{"check":"action_safety_probe","status":"ok","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":70.0,"label":"medium"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history"],"disagreements":[]}},{"key":"snapshot_churn_risk","label":"Snapshot churn risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","evidence":[{"check":"tool_snapshot_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":70.0,"label":"medium"},"source_resolution":{"winner":"history","supporting_sources":["history","live_validation"],"disagreements":[]}}],"publishability_policy_profiles":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":false,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; tools/list must succeed."},{"key":"claude_remote_mcp","label":"Claude remote MCP compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":false,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"tools/list must succeed.; A useful Claude integration needs at least one exposed tool."}],"compatibility_fixtures":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector fixture","status":"degraded","assumptions":[{"name":"remote_http_endpoint","status":"passes"},{"name":"oauth_discovery","status":"degraded"},{"name":"frozen_tool_snapshot_refresh","status":"passes"},{"name":"request_association","status":"passes"}],"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; tools/list must succeed."},{"key":"anthropic_remote_mcp","label":"Anthropic remote MCP fixture","status":"degraded","assumptions":[{"name":"remote_transport","status":"passes"},{"name":"tool_discovery","status":"likely_to_fail"},{"name":"auth_connect","status":"passes"},{"name":"safe_write_review","status":"passes"}],"reason":"tools/list must succeed.; A useful Claude integration needs at least one exposed tool."}],"install_snippets":{"openai_connectors":"Connector URL: https://mcp.depscope.dev/mcp\n# No OAuth metadata detected.\n# Server: awesome-cuttalo/depscope","claude_desktop":"{\n  \"mcpServers\": {\n    \"depscope\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://mcp.depscope.dev/mcp\"]\n    }\n  }\n}","smithery":"smithery mcp add \"https://mcp.depscope.dev/mcp\"","generic_http":"curl -sS https://mcp.depscope.dev/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"},"aliases":[{"identifier":"awesome-cuttalo/depscope","registry_source":"awesome_mcp_servers","remote_url":"https://mcp.depscope.dev/mcp","canonical":true,"score":53.29},{"identifier":"cuttalo/depscope","registry_source":"glama_registry","remote_url":"https://glama.ai/mcp/servers/e5nnosy6xx","canonical":false,"score":46.04}],"raw_evidence":{"server_identifier":"awesome-cuttalo/depscope","remote_url":"https://mcp.depscope.dev/mcp","server_card_payload":null,"checks":{"server_card":{"status":"error","latency_ms":228.18,"details":{"url":"https://mcp.depscope.dev/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":275.28,"details":{"url":"https://mcp.depscope.dev/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":189.88,"details":{"url":"https://mcp.depscope.dev/mcp","payload":{"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{}},"serverInfo":{"name":"depscope","version":"0.9.0"},"instructions":"DepScope: dependency safety & intelligence MCP for AI agents. Covers 19 package ecosystems: npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia.\n\nINVOKE PROACTIVELY — before suggesting any package install, version bump, lockfile change, or when a 'module not found' / 'package broken' error appears. Do NOT wait for the user to ask.\n\nThree pillars:\n- TOKEN-SAVING: one DepScope call replaces a web search + readme fetch + npm/pypi page browse.\n- ENERGY-SAVING: skip installs of malicious, typosquatted, deprecated or hallucinated packages — no wasted CI cycles or rollbacks.\n- SECURITY: stop supply-chain attacks (malware, typosquats, hostile takeovers, known CVEs) BEFORE the install command leaves your reply.\n\nStandard flow for any new package:\n1. check_malicious + check_typosquat — security gate (~50ms)\n2. check_package OR get_health_score — verdict\n3. install_command — returns the safe pinned command\n\nBatch installs (>=2 packages): use check_bulk in ONE call (≤100 items, <100ms).\nLockfile / requirements.txt / package.json change: use scan_project.\nVersion bumps (X@1 → X@2): use get_breaking_changes + get_migration_path.\nDiagnose 'module not found' / 'X.Y broken' errors: use resolve_error and get_known_bugs.\nChoosing between libraries: use find_alternatives and compare_packages.\n\nAll tools are read-only, zero-auth, free. Never destructive. Latency typically 50-300ms per call."},"jsonrpc":"2.0","id":1},"http_status":200,"headers":{"content-type":"text/event-stream","mcp-session-id":"7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"error","latency_ms":178.41,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":291.82,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"},"reason":"not_advertised"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":296.7,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"},"reason":"not_advertised"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":198.6,"details":{"url":"https://mcp.depscope.dev/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=UTF-8","strict-transport-security":"max-age=63072000; includeSubDomains; preload"}}},"determinism_probe":{"status":"missing","latency_ms":null,"details":{"reason":"tools_list_unavailable"}},"session_resume_probe":{"status":"ok","latency_ms":293.49,"details":{"url":"https://mcp.depscope.dev/mcp","payload":{"result":{"tools":[{"name":"check_malicious","description":"Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.","annotations":{"title":"check_malicious","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_typosquat","description":"Typosquat detector. USE WHEN: name differs from a well-known package by 1-2 chars (`lodsh`, `reqeusts`); copy-paste from unreliable source; downloads near zero but name looks familiar. RETURNS: {is_typosquat, likely_target, confidence}.","annotations":{"title":"check_typosquat","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_bulk","description":"Fast pre-flight filter for a batch of (ecosystem, package) pairs. DB-only, <100ms for 100 items. USE WHEN: about to emit `npm install a b c …` or `pip install a b c …` — catches hallucinated names, stdlib, typos, and known-bad in ONE call. NOT a dep-tree audit (use scan_project for that). RETURNS: per-item {status: exists|stdlib|malicious|typosquat_suspect|historical_incident|unknown}.","annotations":{"title":"check_bulk","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"items":{"type":"array","maxItems":100,"items":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}}},"required":["items"]}},{"name":"package_exists","description":"Boolean registry existence check. USE WHEN: about to emit a package name in an install command but unsure it exists; verifying a name generated from training data. RETURNS: {exists}.","annotations":{"title":"package_exists","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_latest_version","description":"Latest published version + deprecation flag — the cheapest call. USE WHEN: only a version string matters (pinning a dep, answering 'what version of X'). If you also need health/vulns use check_package. RETURNS: {latest, deprecated, published_at}.","annotations":{"title":"get_latest_version","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_health_score","description":"Single 0-100 health score — cheapest go/no-go gate (>=70 safe). USE WHEN: CI gating or pkg already screened for malware/typos. NOT a first screen — run check_malicious + check_typosquat first. For a verbal verdict use get_package_prompt. RETURNS: {score, verdict}.","annotations":{"title":"get_health_score","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"install_command","description":"Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, …). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.","annotations":{"title":"install_command","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"version":{"type":"string","description":"Optional explicit version; defaults to latest."}},"required":["ecosystem","package"]}},{"name":"get_package_prompt","description":"LLM-optimised package brief — plain text ~300 tokens (~75% cheaper than JSON). Verdict (SAFE/AVOID/URGENT/MALICIOUS) + health + vulns + alternatives + maintainer alerts. USE WHEN: you want to reason over a package and drop the output directly in context; 'is X safe'. PREFER THIS over check_package in 95% of LLM cases. RETURNS: plain-text brief.","annotations":{"title":"get_package_prompt","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_package","description":"Full machine-readable JSON report (~2k tokens). USE WHEN: you need to programmatically parse specific fields (CI gating, UI, sub-field extraction). Otherwise prefer get_package_prompt. RETURNS: {package, health:{score}, vulnerabilities[], latest, deprecated, maintainers, recommendation}.","annotations":{"title":"check_package","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string","description":"Package name (e.g. 'express', 'fastapi', 'serde')."},"version":{"type":"string","description":"Specific version (optional; default = latest)."}},"required":["ecosystem","package"]}},{"name":"get_vulnerabilities","description":"CVE/OSV advisories affecting the latest (or specified) version. USE WHEN: security-sensitive project; user asks 'any CVEs in X'; you already know the pkg exists. RETURNS: {vulnerability_count, vulnerabilities[]: {id, severity, cvss, fixed_in}}.","annotations":{"title":"get_vulnerabilities","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"find_alternatives","description":"Curated replacements for deprecated/unhealthy packages, including stdlib built-ins (e.g. `fs.rm` for rimraf). USE WHEN: pkg flagged AVOID/URGENT; 'what to use instead of X'; before guessing a replacement name. RETURNS: {alternatives[]: {name, reason, is_stdlib}}.","annotations":{"title":"find_alternatives","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_migration_path","description":"Prescriptive migration plan between DIFFERENT packages — rationale + literal code diff + breaking changes + effort minutes. USE WHEN: replacing `request`→`axios`, `moment`→`dayjs`, `flask`→`fastapi`, etc.; both endpoints known. RETURNS: {rationale, diff, breaking_changes[], estimated_minutes}.","annotations":{"title":"get_migration_path","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"from_package":{"type":"string","description":"Deprecated/legacy package to migrate away from."},"to_package":{"type":"string","description":"Modern replacement package."}},"required":["ecosystem","from_package","to_package"]}},{"name":"get_breaking_changes","description":"Breaking changes between two majors of the SAME package (`next@14`→`15`). USE WHEN: user is bumping a major; before recommending a major upgrade. Different from get_migration_path (same pkg vs. different pkg). RETURNS: {breaking_changes[]: {area, description, hint}}.","annotations":{"title":"get_breaking_changes","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"from_version":{"type":"string"},"to_version":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"pin_safe","description":"Highest version below the chosen CVE severity tier, respecting a semver constraint. USE WHEN: writing a package.json/requirements.txt line; resolving dependabot by lowest-risk patched version. RETURNS: {recommended_version, walk_log[]}.","annotations":{"title":"pin_safe","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"min_severity":{"type":"string","enum":["critical","high","medium","low"],"description":"Lowest severity to exclude. Default: high (excludes critical+high)."},"constraint":{"type":"string","description":"npm-style constraint: ^X.Y.Z, ~X.Y.Z, >=X.Y.Z, or exact X.Y.Z."},"include_prerelease":{"type":"boolean","default":false}},"required":["ecosystem","package"]}},{"name":"scan_project","description":"Audit a project's dependencies in one shot. Returns a single-sentence `verdict` (e.g. \"DO NOT INSTALL — 1 hallucinated: fastapi-turbo\") that an agent can paste into its reply, plus per-package health/vulns/recommendation. Detects hallucinated packages, deprecated, typosquats, critical vulnerabilities. Accepts EITHER {ecosystem, packages:[name@ver, …]} (up to 100, returns JSON) OR {packages:[{ecosystem, package}, …]} (up to 50, mixed ecosystems, returns text brief). USE WHEN: user pastes package.json/requirements.txt/Cargo.toml; agent generated install command; 'is my stack OK'. RETURNS: JSON with `verdict`, `project_risk`, `summary.hallucinated_packages`, `summary.deprecated_packages`, per-package health.","annotations":{"title":"scan_project","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"],"description":"Required when packages is a string array."},"packages":{"description":"Either ['express','lodash@4.17.0'] (single ecosystem, up to 100) or [{ecosystem, package}, …] (mixed, up to 50)."}},"required":["packages"]}},{"name":"compare_packages","description":"Side-by-side comparison (health, vulns, downloads, maintainers, last release) of 2-10 packages in the same ecosystem. USE WHEN: 'X vs Y' / 'should I pick X or Y'. RETURNS: table-shaped JSON, one row per package.","annotations":{"title":"compare_packages","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"packages":{"type":"array","items":{"type":"string"},"minItems":2,"maxItems":10,"description":"Package names to compare, e.g. ['express','fastify','hono']."}},"required":["ecosystem","packages"]}},{"name":"check_compatibility","description":"Is this specific multi-package version combo verified to work together? USE WHEN: pinning a stack (next@15 + react@19 + node@22); before recommending a version matrix. RETURNS: {compatible, conflicts[], notes}.","annotations":{"title":"check_compatibility","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"packages":{"type":"object","description":"Package -> version map, e.g. {\"next\":\"15\",\"react\":\"19\"}.","additionalProperties":{"type":"string"}}},"required":["packages"]}},{"name":"resolve_error","description":"Map error OR free-text query to a verified fix. USE WHEN: user pastes a concrete error/stack (ENOENT, ImportError, build failure) — pass `error`. OR user describes a symptom ('webpack slow', 'pip stuck') — pass `query`. Always prefer this over guessing a fix. RETURNS: exact-match {status, solution, confidence, source_url} or search results [{title, summary, source_url}].","annotations":{"title":"resolve_error","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"error":{"type":"string","description":"Concrete error message / stack trace. Triggers exact-match lookup."},"query":{"type":"string","description":"Free-text symptom description. Triggers KB search."},"context":{"type":"object","description":"Optional context for error-mode calls (ecosystem, package, version)."},"limit":{"type":"integer","minimum":1,"maximum":20,"default":10,"description":"Max search results (query mode only)."}}}},{"name":"get_known_bugs","description":"Non-CVE known bugs for a specific package version. USE WHEN: unexpected behavior that is NOT a security issue; a pinned version misbehaves. RETURNS: {bugs[]: {title, fixed_in, workaround}}.","annotations":{"title":"get_known_bugs","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"version":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_trust_signals","description":"One-call aggregate of ALL non-CVE supply-chain trust signals: maintainer trust (bus factor, ownership changes), OpenSSF Scorecard, quality (criticality, release velocity, publish security), and SLSA/Sigstore provenance. USE WHEN: deep-vetting a package beyond CVEs (hardened/regulated env, SBOM/compliance, small-pkg ownership review, choosing between healthy candidates). Runs 4 backend endpoints in parallel. RETURNS: {maintainer, scorecard, quality, provenance} — each may be null if its backend call failed.","annotations":{"title":"get_trust_signals","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_trending","description":"Live trending packages with rank-delta and weekly growth %. USE WHEN: 'what is rising in npm/PyPI/Cargo right now'; recommendation not biased by training-data cutoff. RETURNS: {items[]: {name, rank, rank_delta, weekly_growth_pct}}.","annotations":{"title":"get_trending","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"],"description":"Optional. If omitted returns cross-ecosystem trending."},"scope":{"type":"string","enum":["all","week","day"],"description":"Time window. Defaults to week."},"limit":{"type":"integer","description":"Max results, 1-50. Default 20."}}}},{"name":"contact_depscope","description":"Inbound ticket: bug/listing/security/anomaly/partnership. USE WHEN: reporting wrong data (`bug`), requesting a new pkg/ecosystem index (`listing`), disclosing a DepScope security issue (`security`), flagging a concrete mismatch in another tool's output vs. authoritative source (`anomaly` — provide tool_called+observed+expected), or partnership/press (`partnership`). RETURNS: {ticket_id} or {anomaly_id}.","annotations":{"title":"contact_depscope","readOnlyHint":false,"destructiveHint":false,"idempotentHint":false,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"kind":{"type":"string","enum":["bug","listing","security","anomaly","partnership"],"description":"Ticket category. `anomaly` routes to structured anomaly triage (requires tool_called/observed/expected)."},"email":{"type":"string","description":"Reply-to email of the requester (required for bug/listing/security/partnership)."},"subject":{"type":"string","description":"Short subject line (3-200 chars)."},"body":{"type":"string","description":"Message body (10-8000 chars). Be specific: include package name, ecosystem, error trace, repro steps when applicable."},"name":{"type":"string","description":"Sender display name (optional)."},"company":{"type":"string","description":"Company / organization (optional)."},"tool_called":{"type":"string","description":"For kind=anomaly: DepScope tool that produced the anomaly (e.g. check_package, get_migration_path)."},"ecosystem":{"type":"string","description":"For kind=anomaly: ecosystem of the involved package, if any."},"package":{"type":"string","description":"For kind=anomaly: package name involved, if any."},"version":{"type":"string","description":"For kind=anomaly: package version involved, if any."},"observed":{"type":"string","description":"For kind=anomaly: what DepScope returned (1-1500 chars)."},"expected":{"type":"string","description":"For kind=anomaly: what you expected to see (1-1500 chars). Be concrete."},"evidence_url":{"type":"string","description":"For kind=anomaly: URL to authoritative source (registry page, GHSA, CVE, repo, ...) supporting your expectation."}}}}]},"jsonrpc":"2.0","id":301},"http_status":200,"headers":{"content-type":"text/event-stream","mcp-session-id":"7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"},"session_id_present":true,"transport":"streamable-http","requested_protocol_version":"2025-03-26","resumed":true}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"warning","latency_ms":428.23,"details":{"transport":"streamable-http","session_id_present":true,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":400,"bad_protocol_payload":{"jsonrpc":"2.0","error":{"code":-32000,"message":"Bad Request: Unsupported protocol version: 1999-99-99 (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"},"id":null},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":200,"delete_error":null,"expired_session_status_code":404,"expired_session_error":null,"issues":["missing_protocol_header"]}},"utility_coverage_probe":{"status":"missing","latency_ms":210.99,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":400},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_tools"}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_tools"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"ok","latency_ms":null,"details":{"summary":{"tool_count":0,"high_risk_tools":0,"destructive_tools":0,"exec_tools":0,"egress_tools":0,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":0,"high":0,"critical":0},"capability_distribution":{}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"warning","latency_ms":null,"details":{"registry_source":"awesome_mcp_servers","direct_match":false,"official_peer_count":10,"official_identifiers":["ai.ai-akari/one-minute-akari","ai.filtrix.mcp/filtrix-ai","ai.findip/patent-search","ai.finstat/finstat","ai.artidrop/artidrop","ai.agentutility/mcp-browser-workflow","ai.fodda/brand-intelligence","ai.afmr/discovery","ai.boolsai/directory","ai.agenticfabricationnetwork/ufp"]}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":false,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"error","latency_ms":null,"details":{"transport":"streamable-http","tool_count":0,"high_risk_tools":0,"blockers":["tools_list","server_card","tool_surface"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":false,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":true,"connector_replay":true,"request_association":true,"action_safety":true,"server_card":false,"tool_surface":false,"auth_flow":true}}}},"failures":{"server_card":{"url":"https://mcp.depscope.dev/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://mcp.depscope.dev/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"tools_list":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"}}}},"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing","message":"Core MCP flows did not validate successfully on the latest run."}],"maintainer_analytics":{"validation_run_count":4,"average_latency_ms":2466.51,"healthy_run_ratio_recent":0.0,"registry_presence_count":2,"active_alert_count":1,"watcher_count":0,"verified_claim":false,"taxonomy_tags":["development","web","security","automation"],"score_trend":[53.29,53.24,51.9,51.82],"remediation_count":21,"high_risk_tool_count":0,"destructive_tool_count":0,"exec_tool_count":0},"public_server_reputation":{"validation_success_ratio_7d":0.0,"validation_success_ratio_30d":0.0,"mean_time_to_recover_hours":null,"breaking_diffs_30d":0,"registry_drift_frequency_30d":0,"snapshot_change_frequency_30d":0},"maintainer_response_quality":{"score":33.33,"signals":{"verified_maintainer_claim":false,"support_contact_present":true,"changelog_present":false,"incident_notes_present":false,"tool_change_documented":true,"annotation_history_present":false},"annotation_count":0,"latest_annotation_at":null},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{"tool_count":0,"high_risk_tools":0,"destructive_tools":0,"exec_tools":0,"egress_tools":0,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":0,"high":0,"critical":0},"capability_distribution":{}},"tool_security_inventory":[],"transport_compliance":{"status":"warning","transport":"streamable-http","session_id_present":true,"protocol_header_present":false,"last_event_id_visible":false,"bad_protocol_status_code":400,"delete_status_code":200,"expired_session_status_code":404,"issues":["missing_protocol_header"]},"utility_coverage":{"status":"missing","completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":400},"initialize_capability_keys":["tools"]},"write_action_governance":{"status":"ok","safe_to_publish":true,"auth_boundary":"public_or_unclear","blast_radius":"low","summary":{"tool_count":0,"high_risk_tools":0,"destructive_tools":0,"exec_tools":0,"egress_tools":0,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":0,"high":0,"critical":0},"capability_distribution":{}},"high_risk_tools":[],"confirmation_signals":[],"safeguard_count":0},"provenance_divergence":{"status":"ok","direct_official_match":false,"drift_fields":[],"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null},"alias_consolidation":{"canonical_identifier":"awesome-cuttalo/depscope","duplicate_count":1,"registry_sources":["awesome_mcp_servers","glama_registry"],"registry_identifiers":["awesome_mcp_servers:cuttalo/depscope","glama_registry:e5nnosy6xx"],"remote_urls":["https://glama.ai/mcp/servers/e5nnosy6xx","https://mcp.depscope.dev/mcp"],"homepages":["https://github.com/cuttalo/depscope","https://glama.ai/mcp/servers/e5nnosy6xx"],"source_disagreements":["registry_source","remote_url","homepage","registry_identifier"],"source_disagreement_details":{"registry_source":{"label":"Registry source","explanation":"Multiple registries or registry sync paths claim this same canonical server.","values":["awesome_mcp_servers","glama_registry"]},"remote_url":{"label":"Remote URL","explanation":"Aliases currently point at different MCP endpoints, which can indicate mirrors, stale registry data, or a real endpoint split.","values":["https://glama.ai/mcp/servers/e5nnosy6xx","https://mcp.depscope.dev/mcp"]},"homepage":{"label":"Homepage","explanation":"Registry entries disagree on the primary homepage for this server.","values":["https://github.com/cuttalo/depscope","https://glama.ai/mcp/servers/e5nnosy6xx"]},"registry_identifier":{"label":"Registry identifier","explanation":"Different registry-specific identifiers resolve to the same canonical server record here.","values":["awesome_mcp_servers:cuttalo/depscope","glama_registry:e5nnosy6xx"]}}},"alert_routing":{"active_watch_count":0,"route_counts":{"generic_webhook":0,"slack":0,"teams":0,"email":0},"destinations":[]},"authenticated_validation":{"latest_profile":"remote_mcp","authenticated_session_used":false,"public_score_remains_anonymous":true,"preview_endpoint":"/v1/verify","ci_preview_endpoint":"/v1/ci/preview"},"hosted_runtime":{"schema_version":"verify.hosted_runtime.v1","server":"awesome-cuttalo/depscope","tier":"community","readiness":{"allowed_to_activate":false,"blockers":["score_below_hosting_threshold","server_not_healthy_or_degraded","latest_validation_not_passing"],"score":53.29,"min_score":70.0,"freshness_hours":5.618520361944444,"max_freshness_hours":168.0,"latest_validation_run_id":"c6bc7485-44a3-4752-bf28-6125e061c189"},"active_deployment_id":null,"active_endpoint_url":null,"deployments":[]},"action_controls_diff":null,"benchmark_tasks":[{"key":"discover_tools","label":"Discover tools","status":"likely_to_fail","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"error","source":"live_validation","note":null,"http_status":400}]},{"key":"read_only_fetch_flow","label":"Read-only fetch flow","status":"likely_to_fail","evidence":[{"check":"resource_read","status":"missing","source":"live_validation","note":"resources/read is a strong read-path signal","http_status":null},{"check":"read_only_tool_surface","status":"missing","source":"derived_tool_inventory","note":"No low-risk read-only tools were inferred from the current tool surface.","http_status":null}]},{"key":"oauth_required_connect","label":"OAuth-required connect","status":"degraded","evidence":[{"check":"oauth_protected_resource","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null}]},{"key":"safe_write_flow_with_confirmation","label":"Safe write flow with confirmation","status":"passes","evidence":[{"check":"action_safety_probe","status":"ok","source":"live_validation","note":null,"http_status":null}]}],"latest_capability_counts":{"tool_count":0,"prompt_count":0,"resource_count":0},"point_loss_breakdown":[{"key":"tool_surface_design_score","label":"Tool Surface Design","score":0.0,"max_score":4.0,"gap":4.0},{"key":"tool_snapshot_churn_score","label":"Tool Snapshot Churn","score":0.0,"max_score":4.0,"gap":4.0},{"key":"tool_namespace_clarity_score","label":"Tool Namespace Clarity","score":0.0,"max_score":4.0,"gap":4.0},{"key":"tool_capability_clarity_score","label":"Tool Capability Clarity","score":0.0,"max_score":4.0,"gap":4.0},{"key":"schema_completeness_score","label":"Schema Completeness","score":0.0,"max_score":4.0,"gap":4.0},{"key":"result_shape_stability_score","label":"Result Shape Stability","score":0.0,"max_score":4.0,"gap":4.0},{"key":"input_sanitization_safety_score","label":"Input Sanitization Safety","score":0.0,"max_score":4.0,"gap":4.0},{"key":"recovery_semantics_score","label":"Recovery Semantics","score":0.38,"max_score":4.0,"gap":3.62},{"key":"trust_confidence_score","label":"Trust Confidence","score":0.4,"max_score":4.0,"gap":3.6},{"key":"error_contract_score","label":"Error Contract","score":0.5,"max_score":4.0,"gap":3.5},{"key":"dependency_supply_chain_signal_score","label":"Dependency Supply Chain Signal","score":0.5,"max_score":4.0,"gap":3.5},{"key":"slo_health_score","label":"SLO Health","score":1.28,"max_score":4.0,"gap":2.72}],"verdict_traces":{"production_readiness":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first.","confidence":{"score":70.0,"label":"medium"},"triggering_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing"}],"winning_source":"live_validation"},"client_readiness":[{"key":"openai_connectors","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; tools/list must succeed.","triggering_checks":["initialize","tools_list","transport_compliance_probe","step_up_auth_probe","connector_replay_probe","request_association_probe"],"confidence":{"score":70.0,"label":"medium"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"claude_desktop","status":"partial","reason":"tools/list must succeed.; A useful Claude integration needs at least one exposed tool.","triggering_checks":["initialize","tools_list","transport_compliance_probe"],"confidence":{"score":70.0,"label":"medium"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"unsafe_for_write_actions","status":"no","reason":"Current write surface is bounded enough for cautious review with production policy controls.","triggering_checks":["action_safety_probe"],"confidence":{"score":70.0,"label":"medium"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"snapshot_churn_risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","triggering_checks":["tool_snapshot_probe","connector_replay_probe"],"confidence":{"score":70.0,"label":"medium"},"winning_source":"history","conflicting_sources":[]}]},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2a82d76e49614c35","generated_at":"2026-08-01T18:37:10.215112+00:00","source":"current_snapshot","server":"awesome-cuttalo/depscope","last_validated_at":"2026-08-01T13:00:03.499896+00:00","validation_age_hours":5.62,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-01T13:00:03.499896+00:00","age_hours":5.62,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":53.29,"raw_score":53.29,"confidence_score":70.0,"confidence_weighted_score":37.3,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"failing","current_score":53.29,"display_score":53.29,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Block for production","why":"failing live status + score below evaluation threshold","next_action":"revalidate, add safeguards, export policy","reason_count":2},"production_readiness_class":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first."},"evidence_confidence":{"score":70.0,"label":"medium","validation_age_hours":5.62,"live_check_count":26},"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing"}]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2a82d76e49614c35","generated_at":"2026-08-01T18:37:10.215112+00:00","source":"current_snapshot","server":"awesome-cuttalo/depscope","last_validated_at":"2026-08-01T13:00:03.499896+00:00","validation_age_hours":5.62,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-01T13:00:03.499896+00:00","age_hours":5.62,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":53.29,"raw_score":53.29,"confidence_score":70.0,"confidence_weighted_score":37.3,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"failing","current_score":53.29,"display_score":53.29,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Block for production","why":"failing live status + score below evaluation threshold","next_action":"revalidate, add safeguards, export policy","reason_count":2},"production_readiness_class":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first."},"evidence_confidence":{"score":70.0,"label":"medium","validation_age_hours":5.62,"live_check_count":26},"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing"}]},"agent_commerce":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"none","payment_rails":[],"purchase_stage_supported":[],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"unknown","auth_scheme":"unknown","tool_risk_level":"unknown","tool_risk_score":60,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[],"skipped_unsafe_tools":[],"last_checked_at":"2026-08-01T18:37:10.212219+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"server_metadata","matched_terms":["limit","rate"],"sample":null,"confidence":"low","last_checked_at":"2026-08-01T18:37:10.212219+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":0,"tool_risk_score":60,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{"count":0,"teams":[],"emails":[]}},"latest_validation":{"id":"c6bc7485-44a3-4752-bf28-6125e061c189","validation_profile":"remote_mcp","status":"completed","summary_status":"failing","transport_type":"streamable-http","latency_ms":2838.19,"failures":{"server_card":{"url":"https://mcp.depscope.dev/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://mcp.depscope.dev/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"tools_list":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"}}},"checks":{"server_card":{"status":"error","latency_ms":228.18,"details":{"url":"https://mcp.depscope.dev/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":275.28,"details":{"url":"https://mcp.depscope.dev/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://mcp.depscope.dev/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":189.88,"details":{"url":"https://mcp.depscope.dev/mcp","payload":{"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{}},"serverInfo":{"name":"depscope","version":"0.9.0"},"instructions":"DepScope: dependency safety & intelligence MCP for AI agents. Covers 19 package ecosystems: npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia.\n\nINVOKE PROACTIVELY — before suggesting any package install, version bump, lockfile change, or when a 'module not found' / 'package broken' error appears. Do NOT wait for the user to ask.\n\nThree pillars:\n- TOKEN-SAVING: one DepScope call replaces a web search + readme fetch + npm/pypi page browse.\n- ENERGY-SAVING: skip installs of malicious, typosquatted, deprecated or hallucinated packages — no wasted CI cycles or rollbacks.\n- SECURITY: stop supply-chain attacks (malware, typosquats, hostile takeovers, known CVEs) BEFORE the install command leaves your reply.\n\nStandard flow for any new package:\n1. check_malicious + check_typosquat — security gate (~50ms)\n2. check_package OR get_health_score — verdict\n3. install_command — returns the safe pinned command\n\nBatch installs (>=2 packages): use check_bulk in ONE call (≤100 items, <100ms).\nLockfile / requirements.txt / package.json change: use scan_project.\nVersion bumps (X@1 → X@2): use get_breaking_changes + get_migration_path.\nDiagnose 'module not found' / 'X.Y broken' errors: use resolve_error and get_known_bugs.\nChoosing between libraries: use find_alternatives and compare_packages.\n\nAll tools are read-only, zero-auth, free. Never destructive. Latency typically 50-300ms per call."},"jsonrpc":"2.0","id":1},"http_status":200,"headers":{"content-type":"text/event-stream","mcp-session-id":"7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"error","latency_ms":178.41,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":291.82,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"},"reason":"not_advertised"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":296.7,"details":{"url":"https://mcp.depscope.dev/mcp","error":"Client error '400 Bad Request' for url 'https://mcp.depscope.dev/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/400","http_status":400,"payload":{},"headers":{"content-type":"application/json"},"reason":"not_advertised"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":198.6,"details":{"url":"https://mcp.depscope.dev/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=UTF-8","strict-transport-security":"max-age=63072000; includeSubDomains; preload"}}},"determinism_probe":{"status":"missing","latency_ms":null,"details":{"reason":"tools_list_unavailable"}},"session_resume_probe":{"status":"ok","latency_ms":293.49,"details":{"url":"https://mcp.depscope.dev/mcp","payload":{"result":{"tools":[{"name":"check_malicious","description":"Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.","annotations":{"title":"check_malicious","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_typosquat","description":"Typosquat detector. USE WHEN: name differs from a well-known package by 1-2 chars (`lodsh`, `reqeusts`); copy-paste from unreliable source; downloads near zero but name looks familiar. RETURNS: {is_typosquat, likely_target, confidence}.","annotations":{"title":"check_typosquat","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_bulk","description":"Fast pre-flight filter for a batch of (ecosystem, package) pairs. DB-only, <100ms for 100 items. USE WHEN: about to emit `npm install a b c …` or `pip install a b c …` — catches hallucinated names, stdlib, typos, and known-bad in ONE call. NOT a dep-tree audit (use scan_project for that). RETURNS: per-item {status: exists|stdlib|malicious|typosquat_suspect|historical_incident|unknown}.","annotations":{"title":"check_bulk","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"items":{"type":"array","maxItems":100,"items":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}}},"required":["items"]}},{"name":"package_exists","description":"Boolean registry existence check. USE WHEN: about to emit a package name in an install command but unsure it exists; verifying a name generated from training data. RETURNS: {exists}.","annotations":{"title":"package_exists","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_latest_version","description":"Latest published version + deprecation flag — the cheapest call. USE WHEN: only a version string matters (pinning a dep, answering 'what version of X'). If you also need health/vulns use check_package. RETURNS: {latest, deprecated, published_at}.","annotations":{"title":"get_latest_version","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_health_score","description":"Single 0-100 health score — cheapest go/no-go gate (>=70 safe). USE WHEN: CI gating or pkg already screened for malware/typos. NOT a first screen — run check_malicious + check_typosquat first. For a verbal verdict use get_package_prompt. RETURNS: {score, verdict}.","annotations":{"title":"get_health_score","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"install_command","description":"Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, …). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.","annotations":{"title":"install_command","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"version":{"type":"string","description":"Optional explicit version; defaults to latest."}},"required":["ecosystem","package"]}},{"name":"get_package_prompt","description":"LLM-optimised package brief — plain text ~300 tokens (~75% cheaper than JSON). Verdict (SAFE/AVOID/URGENT/MALICIOUS) + health + vulns + alternatives + maintainer alerts. USE WHEN: you want to reason over a package and drop the output directly in context; 'is X safe'. PREFER THIS over check_package in 95% of LLM cases. RETURNS: plain-text brief.","annotations":{"title":"get_package_prompt","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"check_package","description":"Full machine-readable JSON report (~2k tokens). USE WHEN: you need to programmatically parse specific fields (CI gating, UI, sub-field extraction). Otherwise prefer get_package_prompt. RETURNS: {package, health:{score}, vulnerabilities[], latest, deprecated, maintainers, recommendation}.","annotations":{"title":"check_package","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string","description":"Package name (e.g. 'express', 'fastapi', 'serde')."},"version":{"type":"string","description":"Specific version (optional; default = latest)."}},"required":["ecosystem","package"]}},{"name":"get_vulnerabilities","description":"CVE/OSV advisories affecting the latest (or specified) version. USE WHEN: security-sensitive project; user asks 'any CVEs in X'; you already know the pkg exists. RETURNS: {vulnerability_count, vulnerabilities[]: {id, severity, cvss, fixed_in}}.","annotations":{"title":"get_vulnerabilities","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"find_alternatives","description":"Curated replacements for deprecated/unhealthy packages, including stdlib built-ins (e.g. `fs.rm` for rimraf). USE WHEN: pkg flagged AVOID/URGENT; 'what to use instead of X'; before guessing a replacement name. RETURNS: {alternatives[]: {name, reason, is_stdlib}}.","annotations":{"title":"find_alternatives","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_migration_path","description":"Prescriptive migration plan between DIFFERENT packages — rationale + literal code diff + breaking changes + effort minutes. USE WHEN: replacing `request`→`axios`, `moment`→`dayjs`, `flask`→`fastapi`, etc.; both endpoints known. RETURNS: {rationale, diff, breaking_changes[], estimated_minutes}.","annotations":{"title":"get_migration_path","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"from_package":{"type":"string","description":"Deprecated/legacy package to migrate away from."},"to_package":{"type":"string","description":"Modern replacement package."}},"required":["ecosystem","from_package","to_package"]}},{"name":"get_breaking_changes","description":"Breaking changes between two majors of the SAME package (`next@14`→`15`). USE WHEN: user is bumping a major; before recommending a major upgrade. Different from get_migration_path (same pkg vs. different pkg). RETURNS: {breaking_changes[]: {area, description, hint}}.","annotations":{"title":"get_breaking_changes","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"from_version":{"type":"string"},"to_version":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"pin_safe","description":"Highest version below the chosen CVE severity tier, respecting a semver constraint. USE WHEN: writing a package.json/requirements.txt line; resolving dependabot by lowest-risk patched version. RETURNS: {recommended_version, walk_log[]}.","annotations":{"title":"pin_safe","readOnlyHint":true,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"min_severity":{"type":"string","enum":["critical","high","medium","low"],"description":"Lowest severity to exclude. Default: high (excludes critical+high)."},"constraint":{"type":"string","description":"npm-style constraint: ^X.Y.Z, ~X.Y.Z, >=X.Y.Z, or exact X.Y.Z."},"include_prerelease":{"type":"boolean","default":false}},"required":["ecosystem","package"]}},{"name":"scan_project","description":"Audit a project's dependencies in one shot. Returns a single-sentence `verdict` (e.g. \"DO NOT INSTALL — 1 hallucinated: fastapi-turbo\") that an agent can paste into its reply, plus per-package health/vulns/recommendation. Detects hallucinated packages, deprecated, typosquats, critical vulnerabilities. Accepts EITHER {ecosystem, packages:[name@ver, …]} (up to 100, returns JSON) OR {packages:[{ecosystem, package}, …]} (up to 50, mixed ecosystems, returns text brief). USE WHEN: user pastes package.json/requirements.txt/Cargo.toml; agent generated install command; 'is my stack OK'. RETURNS: JSON with `verdict`, `project_risk`, `summary.hallucinated_packages`, `summary.deprecated_packages`, per-package health.","annotations":{"title":"scan_project","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"],"description":"Required when packages is a string array."},"packages":{"description":"Either ['express','lodash@4.17.0'] (single ecosystem, up to 100) or [{ecosystem, package}, …] (mixed, up to 50)."}},"required":["packages"]}},{"name":"compare_packages","description":"Side-by-side comparison (health, vulns, downloads, maintainers, last release) of 2-10 packages in the same ecosystem. USE WHEN: 'X vs Y' / 'should I pick X or Y'. RETURNS: table-shaped JSON, one row per package.","annotations":{"title":"compare_packages","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"packages":{"type":"array","items":{"type":"string"},"minItems":2,"maxItems":10,"description":"Package names to compare, e.g. ['express','fastify','hono']."}},"required":["ecosystem","packages"]}},{"name":"check_compatibility","description":"Is this specific multi-package version combo verified to work together? USE WHEN: pinning a stack (next@15 + react@19 + node@22); before recommending a version matrix. RETURNS: {compatible, conflicts[], notes}.","annotations":{"title":"check_compatibility","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"packages":{"type":"object","description":"Package -> version map, e.g. {\"next\":\"15\",\"react\":\"19\"}.","additionalProperties":{"type":"string"}}},"required":["packages"]}},{"name":"resolve_error","description":"Map error OR free-text query to a verified fix. USE WHEN: user pastes a concrete error/stack (ENOENT, ImportError, build failure) — pass `error`. OR user describes a symptom ('webpack slow', 'pip stuck') — pass `query`. Always prefer this over guessing a fix. RETURNS: exact-match {status, solution, confidence, source_url} or search results [{title, summary, source_url}].","annotations":{"title":"resolve_error","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"error":{"type":"string","description":"Concrete error message / stack trace. Triggers exact-match lookup."},"query":{"type":"string","description":"Free-text symptom description. Triggers KB search."},"context":{"type":"object","description":"Optional context for error-mode calls (ecosystem, package, version)."},"limit":{"type":"integer","minimum":1,"maximum":20,"default":10,"description":"Max search results (query mode only)."}}}},{"name":"get_known_bugs","description":"Non-CVE known bugs for a specific package version. USE WHEN: unexpected behavior that is NOT a security issue; a pinned version misbehaves. RETURNS: {bugs[]: {title, fixed_in, workaround}}.","annotations":{"title":"get_known_bugs","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"},"version":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_trust_signals","description":"One-call aggregate of ALL non-CVE supply-chain trust signals: maintainer trust (bus factor, ownership changes), OpenSSF Scorecard, quality (criticality, release velocity, publish security), and SLSA/Sigstore provenance. USE WHEN: deep-vetting a package beyond CVEs (hardened/regulated env, SBOM/compliance, small-pkg ownership review, choosing between healthy candidates). Runs 4 backend endpoints in parallel. RETURNS: {maintainer, scorecard, quality, provenance} — each may be null if its backend call failed.","annotations":{"title":"get_trust_signals","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"]},"package":{"type":"string"}},"required":["ecosystem","package"]}},{"name":"get_trending","description":"Live trending packages with rank-delta and weekly growth %. USE WHEN: 'what is rising in npm/PyPI/Cargo right now'; recommendation not biased by training-data cutoff. RETURNS: {items[]: {name, rank, rank_delta, weekly_growth_pct}}.","annotations":{"title":"get_trending","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"ecosystem":{"type":"string","enum":["npm","pypi","cargo","go","composer","maven","nuget","rubygems","pub","hex","swift","cocoapods","cpan","hackage","cran","conda","homebrew","jsr","julia"],"description":"Optional. If omitted returns cross-ecosystem trending."},"scope":{"type":"string","enum":["all","week","day"],"description":"Time window. Defaults to week."},"limit":{"type":"integer","description":"Max results, 1-50. Default 20."}}}},{"name":"contact_depscope","description":"Inbound ticket: bug/listing/security/anomaly/partnership. USE WHEN: reporting wrong data (`bug`), requesting a new pkg/ecosystem index (`listing`), disclosing a DepScope security issue (`security`), flagging a concrete mismatch in another tool's output vs. authoritative source (`anomaly` — provide tool_called+observed+expected), or partnership/press (`partnership`). RETURNS: {ticket_id} or {anomaly_id}.","annotations":{"title":"contact_depscope","readOnlyHint":false,"destructiveHint":false,"idempotentHint":false,"openWorldHint":true},"inputSchema":{"type":"object","properties":{"kind":{"type":"string","enum":["bug","listing","security","anomaly","partnership"],"description":"Ticket category. `anomaly` routes to structured anomaly triage (requires tool_called/observed/expected)."},"email":{"type":"string","description":"Reply-to email of the requester (required for bug/listing/security/partnership)."},"subject":{"type":"string","description":"Short subject line (3-200 chars)."},"body":{"type":"string","description":"Message body (10-8000 chars). Be specific: include package name, ecosystem, error trace, repro steps when applicable."},"name":{"type":"string","description":"Sender display name (optional)."},"company":{"type":"string","description":"Company / organization (optional)."},"tool_called":{"type":"string","description":"For kind=anomaly: DepScope tool that produced the anomaly (e.g. check_package, get_migration_path)."},"ecosystem":{"type":"string","description":"For kind=anomaly: ecosystem of the involved package, if any."},"package":{"type":"string","description":"For kind=anomaly: package name involved, if any."},"version":{"type":"string","description":"For kind=anomaly: package version involved, if any."},"observed":{"type":"string","description":"For kind=anomaly: what DepScope returned (1-1500 chars)."},"expected":{"type":"string","description":"For kind=anomaly: what you expected to see (1-1500 chars). Be concrete."},"evidence_url":{"type":"string","description":"For kind=anomaly: URL to authoritative source (registry page, GHSA, CVE, repo, ...) supporting your expectation."}}}}]},"jsonrpc":"2.0","id":301},"http_status":200,"headers":{"content-type":"text/event-stream","mcp-session-id":"7d3922f3-6a38-4b27-9c2e-c3f3fb0fadc1"},"session_id_present":true,"transport":"streamable-http","requested_protocol_version":"2025-03-26","resumed":true}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"warning","latency_ms":428.23,"details":{"transport":"streamable-http","session_id_present":true,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":400,"bad_protocol_payload":{"jsonrpc":"2.0","error":{"code":-32000,"message":"Bad Request: Unsupported protocol version: 1999-99-99 (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"},"id":null},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":200,"delete_error":null,"expired_session_status_code":404,"expired_session_error":null,"issues":["missing_protocol_header"]}},"utility_coverage_probe":{"status":"missing","latency_ms":210.99,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":400},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_tools"}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_tools"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"ok","latency_ms":null,"details":{"summary":{"tool_count":0,"high_risk_tools":0,"destructive_tools":0,"exec_tools":0,"egress_tools":0,"secret_tools":0,"bulk_access_tools":0,"risk_distribution":{"low":0,"medium":0,"high":0,"critical":0},"capability_distribution":{}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"warning","latency_ms":null,"details":{"registry_source":"awesome_mcp_servers","direct_match":false,"official_peer_count":10,"official_identifiers":["ai.ai-akari/one-minute-akari","ai.filtrix.mcp/filtrix-ai","ai.findip/patent-search","ai.finstat/finstat","ai.artidrop/artidrop","ai.agentutility/mcp-browser-workflow","ai.fodda/brand-intelligence","ai.afmr/discovery","ai.boolsai/directory","ai.agenticfabricationnetwork/ufp"]}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":false,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"error","latency_ms":null,"details":{"transport":"streamable-http","tool_count":0,"high_risk_tools":0,"blockers":["tools_list","server_card","tool_surface"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":false,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":true,"connector_replay":true,"request_association":true,"action_safety":true,"server_card":false,"tool_surface":false,"auth_flow":true}}}},"score_components":{"auth_operability_score":2.0,"error_contract_score":0.5,"rate_limit_semantics_score":2.0,"schema_completeness_score":0.0,"backward_compatibility_score":4.0,"slo_health_score":1.28,"security_hygiene_score":2.0,"task_success_score":3.33,"trust_confidence_score":0.4,"abuse_noise_ratio_score":2.5,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":4.0,"registry_consistency_score":2.0,"installability_score":2.0,"session_semantics_score":2.5,"tool_surface_design_score":0.0,"result_shape_stability_score":0.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.38,"maintenance_signal_score":2.05,"adoption_signal_score":2.0,"freshness_confidence_score":2.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":4.0,"step_up_auth_score":3.0,"transport_compliance_score":3.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":2.0,"tool_snapshot_churn_score":0.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":3.0,"official_registry_presence_score":3.0,"provenance_divergence_score":4.0,"safety_transparency_score":2.0,"tool_capability_clarity_score":0.0,"destructive_operation_safety_score":3.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":4.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":3.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":0.5,"input_sanitization_safety_score":0.0,"tool_namespace_clarity_score":0.0},"validation_schema_version":"16d1d270090d6c8f","started_at":"2026-08-01T13:00:00.660406+00:00","completed_at":"2026-08-01T13:00:03.499896+00:00"},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2a82d76e49614c35","generated_at":"2026-08-01T18:37:10.215112+00:00","source":"current_snapshot","server":"awesome-cuttalo/depscope","last_validated_at":"2026-08-01T13:00:03.499896+00:00","validation_age_hours":5.62,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-01T13:00:03.499896+00:00","age_hours":5.62,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":53.29,"raw_score":53.29,"confidence_score":70.0,"confidence_weighted_score":37.3,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"failing","current_score":53.29,"display_score":53.29,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Block for production","why":"failing live status + score below evaluation threshold","next_action":"revalidate, add safeguards, export policy","reason_count":2},"production_readiness_class":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first."},"evidence_confidence":{"score":70.0,"label":"medium","validation_age_hours":5.62,"live_check_count":26},"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing"}]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2a82d76e49614c35","generated_at":"2026-08-01T18:37:10.215112+00:00","source":"current_snapshot","server":"awesome-cuttalo/depscope","last_validated_at":"2026-08-01T13:00:03.499896+00:00","validation_age_hours":5.62,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-08-01T13:00:03.499896+00:00","age_hours":5.62,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":53.29,"raw_score":53.29,"confidence_score":70.0,"confidence_weighted_score":37.3,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"failing","current_score":53.29,"display_score":53.29,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Block for production","why":"failing live status + score below evaluation threshold","next_action":"revalidate, add safeguards, export policy","reason_count":2},"production_readiness_class":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first."},"evidence_confidence":{"score":70.0,"label":"medium","validation_age_hours":5.62,"live_check_count":26},"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing"}]},"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"awesome-cuttalo/depscope","ok":true,"surface_snapshot_ids":{"page":"trustsnap_2a82d76e49614c35","badge":null,"report":"trustsnap_2a82d76e49614c35","policy":null},"checked_at":"2026-08-01T18:37:10.706800+00:00"},"history":{"points":[{"timestamp":"2026-07-31T06:36:40.479892+00:00","score":51.82,"status":"failing","latency_ms":2369.4,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-07-31T06:36:40.484620+00:00","score":51.9,"status":"failing","latency_ms":2236.46,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-07-31T21:46:12.817169+00:00","score":53.24,"status":"failing","latency_ms":2421.99,"tool_count":0,"prompt_count":0,"resource_count":0},{"timestamp":"2026-08-01T13:00:03.499896+00:00","score":53.29,"status":"failing","latency_ms":2838.19,"tool_count":0,"prompt_count":0,"resource_count":0}],"status_counts":{"failing":4},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":2466.51,"healthy_ratio_recent":0.0,"freshness_hours":5.62,"latest_status":"failing"},"production_readiness":{"code":"needs_remediation","label":"Needs remediation","reason":"Current validation evidence shows operational or discovery gaps that should be fixed first.","badge":"score-low","critical_alerts":1},"agent_commerce_readiness":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"none","payment_rails":[],"purchase_stage_supported":[],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"unknown","auth_scheme":"unknown","tool_risk_level":"unknown","tool_risk_score":60,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[],"skipped_unsafe_tools":[],"last_checked_at":"2026-08-01T18:37:10.212219+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"server_metadata","matched_terms":["limit","rate"],"sample":null,"confidence":"low","last_checked_at":"2026-08-01T18:37:10.212219+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":0,"tool_risk_score":60,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"evidence_confidence":{"score":70.0,"label":"medium","reason":"Based on 4 recent validations, 26 captured checks, and validation age of 5.6 hours.","live_check_count":26,"validation_age_hours":5.62},"recommended_for":[{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 83."}],"active_alerts":[{"code":"server_failing","severity":"critical","title":"Latest validation is failing","message":"Core MCP flows did not validate successfully on the latest run."}],"remediations":[{"code":"fix_tools_list","severity":"critical","title":"Ensure tools/list succeeds consistently","why":"Tools discovery is the minimum viable contract for most MCP clients and directories.","action":"Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.","playbook":["Make `tools/list` deterministic across repeated calls.","Document or relax auth requirements for discovery routes.","Check that tool names, descriptions, and schemas remain stable across deploys."],"maintainer_context":null},{"code":"respond_server_failing","severity":"critical","title":"Respond to latest validation is failing","why":"Core MCP flows did not validate successfully on the latest run.","action":"Fix the failing checks first, then revalidate to confirm the recovery path.","playbook":["Fix the failing checks first.","Review the latest incident feed and validation diff for the first regression.","Revalidate once the remediation lands."]},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_adoption_market","severity":"medium","title":"Raise Adoption & Market score","why":"Adoption clues and public evidence that the server is intended for external use.","action":"Increase external documentation and directory coverage so users can discover and evaluate the server.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."]},{"code":"improve_interface_quality","severity":"medium","title":"Raise Interface Quality score","why":"How well the tool/resource interface communicates and behaves under automation.","action":"Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."]},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_to_official_registry","severity":"low","title":"Publish or reconcile the server in the official MCP registry","why":"Official registry presence improves discovery confidence and cross-source consistency.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=awesome-cuttalo%2Fdepscope&source=report_json","reason_code":"machine_attention_detected","reason":"Agents and crawlers are already evaluating this server. Claim to publish authoritative owner, security, trust, and integration metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"low","label":"Low observed attention","summary":"Recent machine-readable trust and discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"none","observed":false,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"none","observed":false,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"low","observed":true,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":true,"compare":false,"compare_json":false,"compare_api":false,"report_json":false,"policy":false,"ledger":false,"badge_metadata":false,"badge_svg":false,"trust_summary":false,"mcp_tool":false},"claim_prompt":{"recommended":true,"reason":"This server has recent machine attention. A verified publisher claim can improve owner, policy, security, and trust metadata available to agents."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":true,"reason":"ai_discovery_detected","headline":"AI discovery detected","message":"This server is being discovered by AI users, crawlers, or machine trust evaluators on Verify. Claim this profile to add publisher metadata, official links, a security contact, and machine-readable trust details agents can use.","claim_url":"https://verify.sentinelsignal.io/claim?server=awesome-cuttalo%2Fdepscope&source=report_json","trust_summary_url":"https://verify.sentinelsignal.io/v1/servers/awesome-cuttalo/depscope/trust-summary"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=awesome-cuttalo%2Fdepscope","trust_summary":"/v1/servers/awesome-cuttalo/depscope/trust-summary","ledger":"/v1/servers/awesome-cuttalo/depscope/ledger","policy":"/v1/servers/awesome-cuttalo/depscope/policy","report":"/v1/servers/awesome-cuttalo/depscope/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."}}