MCP MCP server · io.github.safedep
io.github.safedep/vet-mcp
Protect your AI agents and IDEs from malicious open-source packages.
- host stars
- 1,105
- 30-day movement
- +21/day
- Related entries
- 1
- Connections
- 0
ocilocalstdio
SafeDep Vet MCP is an MCP server (stdio transport) exposing the `vet` open-source supply-chain security tool to AI agents and IDEs. It checks packages against SafeDep's threat intelligence database for malware and analyzes dependency usage to prioritize real vulnerabilities across npm, PyPI, Maven, Go, Ruby, Rust, and PHP.
Use it when you want an AI agent or IDE to screen open-source dependencies for malicious packages and real, usage-based vulnerability risk before they are adopted.
Use it to
- Screen packages for malware via SafeDep threat intelligence
- Prioritize vulnerabilities based on actual code usage
- Enforce policy-as-code rules with CEL expressions
- Scan manifests, container images, and SBOMs (CycloneDX, SPDX)
- Add security guardrails in GitHub Actions or GitLab CI
For Developers securing dependencies in agents, IDEs, and CI pipelines
- Runs
- installed — on your machine
- Transport
- stdio
- Packaged as
- oci:ghcr.io/safedep/vet:v1.19.1
- Install
- docker run ghcr.io/safedep/vet:v1.19.1
- Version
- 1.19.1
- Last release
- 2026-09-16
topicssupply-chain-securitymalware-detectionvulnerability-analysismcp-serverdependency-scanningpolicy-as-code