MCP server · Security
DepScope MCP server
by cuttalo
Check if a software package is real, safe, and up to date before your AI installs it.

DepScope is a free service that checks software packages for you. A package is a small piece of code someone else wrote that your project borrows. This helper is handy if you use an AI assistant to write or fix code and you want to be sure it is not telling you to install something fake, unsafe, or out of date.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. It cannot go and check a real website or database. An MCP server is a small helper program that gives your AI one new skill. This one connects your AI to DepScope, so when you ask about a package, your AI can look it up there and tell you what it finds.
What this MCP server does
You ask your AI something like whether a package is safe to use. Your AI sends that question to the DepScope helper. The helper talks to the DepScope service, which holds information on millions of packages across many programming languages. DepScope checks the package for problems like known security holes, fake lookalike names, or the fact that it does not exist at all. Your AI then tells you the answer in plain words in the chat.
Click to zoomWhat you can do with it
- Check whether a package is real or made up by the AI
- See if a package has known security problems
- Spot names that look like a popular package but are slightly different
- Get a health score for a package
- Find a safer alternative to an old or abandoned package
- Get the correct install command for a package
- Scan a whole list of packages at once
Try asking your AI
- “Is the npm package lodash safe to use?”
- “Check if fastapi-turbo actually exists”
- “What are the known vulnerabilities in requests for Python?”
- “Find me an alternative to this abandoned package”
What it gives back to you
You get a short answer in the chat, not a file. It usually includes whether the package exists, a health score, any known security issues, and a simple recommendation. Sometimes it also suggests a safer version to use or a different package to try instead.
Before you start
What you need
- An AI assistant that supports MCP, like Claude Desktop, Cursor, or Windsurf
- For the local option: Node.js installed on your computer
Good to know
This tool only reads information and does not change anything on your computer, so it is safe to try, but always read the answer before you install anything.
Install it with your AI
Add DepScope MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check DepScope MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Anyone who uses an AI assistant to write or fix code and wants to avoid installing fake or unsafe packages.





