
DepScout
Claude connectorCommunityCheck npm, PyPI, Go, Maven, crates.io and NuGet packages for known vulnerabilities and malware, find the minimum safe version, and audit pi…
- Tools
- 3
exposed by this connector
Movement
From our daily snapshots over the last 30 days.
Rank by popularity
Rank by trending score
Popularity score
Trending score
In its category
How this connector compares with others in the same category. Positions are counted within the category, not across the whole directory.
Developer tools509th of 736 by popularity · not ranked by trending score
| # | Connector | Popularity | Trending | 7d |
|---|---|---|---|---|
| 506 | 4,585 | 223places down | ||
| 507 | 4,585 | 150places down | ||
| 508 | 4,524 | 277places down | ||
| 509 | 4,524 | — | ||
| 510 | 4,524 | 172places down | ||
| 511 | 4,459 | 348places down | ||
| 512 | 4,459 | — |
This connector isn’t ranked by trending score, so the category’s top connectors are shown instead.
| # | Connector | Trending | Popularity | 7d |
|---|---|---|---|---|
| 1 | 2,725,800 | 52places up | ||
| 2 | 762,405 | — | ||
| 3 | 560,539 | — | ||
| 4 | 538,389 | — | ||
| 5 | 251,015 | — | ||
| 6 | 250,429 | — | ||
| 7 | 183,005 | 57places up |
DepScout checks open-source packages against live vulnerability and malware data, so answers about whether a package is safe, and which version to use, come from current advisories instead of model memory.
What it does:
- Checks one package (npm, PyPI, Go, Maven, crates.io or NuGet) at a given version or its latest release. It flags malicious packages and compromised releases first, then lists known vulnerabilities with severity, CVE IDs and the version that fixes each one, plus the minimum version that clears them all.
- Reports the latest stable version, whether a version is outdated or deprecated, the last release date, licences, and the source repository's OpenSSF Scorecard.
- Checks up to 50 pinned dependencies at once (for example from package.json, requirements.txt, go.mod or pom.xml) and returns only the ones with problems, with an upgrade target for each.
- Explains a single advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC or MAL): severity, affected and fixed version ranges, and references.
Who it's for: developers using Claude, Claude Code or other AI assistants who want to vet a dependency before installing it, triage an audit, or pick a safe version.
Limitations: data comes from OSV.dev and deps.dev. A clean result means no known advisory for that exact version, not a guarantee of safety, and newly published malware may not be listed yet. Only the packages you list are checked, not their transitive dependencies. Version ranges are checked at the version written in them. DepScout is read-only and is not affiliated with OSV.dev, deps.dev, Google, the OpenSSF, GitHub or any package registry.
Tools
- check_dependencies
- check_package
- get_vulnerability
- Categories
- Sign-in
- Not required
- Connector URL
- https://depscout.salesup.workers.dev/mcp
- Transport
- Streamable HTTP
- Works with
- Claude, Claude API, Claude Code, Claude Desktop
- Added
- October 2, 2026
- More info