Complete AI Training

MCP server · Security · official

SafeDep vet MCP server

by safedep · official

Lets your AI check npm and PyPI packages for known malware and vulnerabilities before you install them.

Flow diagram: you ask your AI “Is the npm package express-cookie-parser safe?”, the SafeDep vet MCP server connects it to SafeDep vet, and you get back A short answer in your chat.

This is a helper from SafeDep that plugs into your AI assistant and lets it check software packages for you. It is handy if you use AI coding tools that suggest packages to install, and you want to know whether those packages are safe first. You do not need to be a security expert to use it.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to another service. This one connects your AI to SafeDep's vet tool, which knows about known bad and risky packages. So when you ask your AI to check a package, it can actually go and look it up instead of guessing.

What this MCP server does

You ask your AI something like whether a package is safe to install. Your AI passes that question to this helper, which runs the vet tool behind the scenes. Vet looks the package up against SafeDep's database of known malicious packages and vulnerability information. Then your AI tells you back what it found, in normal words, right in your chat.

Flow diagram: you ask your AI “Is the npm package express-cookie-parser safe?”, the SafeDep vet MCP server connects it to SafeDep vet, and you get back A short answer in your chat. Click to zoom

What you can do with it

  • Check whether an npm or PyPI package is known to be malicious
  • Look up known vulnerabilities for packages you are about to install
  • Check packages that an AI coding tool suggested before you add them
  • Scan a project folder for risky dependencies
  • Get a short summary of what was found instead of raw security data

Try asking your AI

  • “Is the npm package express-cookie-parser safe to install?”
  • “Check this PyPI package for known malware before I add it”
  • “Look at the packages in my project and tell me if any are known to be bad”
  • “I am about to install a package an AI suggested. Can you check it for vulnerabilities?”

What it gives back to you

You get a plain answer in your chat, usually a short summary of what was found. If a package is flagged, you will see which package and why, such as known malware or a serious vulnerability. If nothing is wrong, you get a clean result. It is meant to be a quick yes or no with a bit of detail, not a wall of technical output.

Before you start

What you need

  • The vet tool installed on your computer (the setup guide shows how, for example with Homebrew or npm)
  • An AI assistant that supports MCP servers, such as the Claude desktop app
  • An internet connection so vet can look packages up

Good to know

It only checks and reports on packages, it does not install or change anything for you, so treat its answer as advice and not a guarantee.

Install it with your AI

Add SafeDep vet MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check SafeDep vet MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Anyone who installs software packages, especially developers and office workers using AI coding tools that suggest packages to add.