Complete Your Security Stack
DepScope users also rely on these tools to enhance their workflow:
1Password
Try FreeSecrets and credential manager
Keep API keys and .env secrets out of your repo
Gamma
Try FreeAI presentation builder
Turn ideas into polished decks instantly
AdCreative.ai
Try FreeAI-powered ad creatives
Generate marketing visuals in seconds
💰 Affiliate disclosure: We may earn a commission if you sign up through these links at no extra cost to you.
DepScope
Free keyless MCP server that catches hallucinated, vulnerable, and typosquatted packages
0Visit DepScope
https://depscope.dev
About DepScope
DepScope is a free MCP server that screens every package an AI agent suggests before it reaches npm install. It targets three specific failure modes. The first is hallucination: LLMs invent plausible-sounding package names, and DepScope verifies each one against live registries across 19 ecosystems and flags typosquats by Levenshtein distance to popular packages — the exact mechanism attackers rely on when they register a name a model is likely to hallucinate. The second is vulnerability exposure, covered by live lookups against OSV, CISA's Known Exploited Vulnerabilities list, EPSS scores, the OpenSSF malicious-package feed, and a deprecated-package index, returning severity, fix version, and migration path in one call. The third is token cost: pre-curated briefs of roughly 300 tokens replace the four-to-eight thousand tokens an agent would otherwise burn scraping registry and CVE pages per decision, a reported 74% reduction. It covers 8.5 million packages across 19 ecosystems — npm, PyPI, Cargo, Go, Composer, Maven, NuGet, RubyGems, pub, hex, Swift, CPAN, Hackage, CRAN, conda, Homebrew, JSR, and Julia — with 22 MCP tools, no auth, no API key, and no rate limit. Remote MCP works out of the box in Claude Desktop, Cursor, and Windsurf, with a curl one-liner for everything else, and the SDKs are open source. There is also a browser paste-a-manifest scan and a published ten-model hallucination benchmark.
Key Features
DepScope Pros & Cons
✅ Pros
- +Completely free with no key, no quota, and no signup — nothing to evaluate around
- +Slot-hallucination and typosquatting are a real, actively exploited attack path
- +Token savings are a direct cost reduction on every agent dependency decision
- +Ecosystem coverage well beyond the usual npm-and-PyPI pairing
⚠️ Cons
- −No published business model, which raises questions about long-term availability
- −No auth and no rate limit means no SLA or support commitment either
- −Screening is advisory — it does not block installs on its own
- −Depends on upstream feeds (OSV, KEV, EPSS) for freshness
Who Is DepScope Best For?
Tags
Is this your tool?
Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.
Claim Now →ChatGPT already recommends DepScope. Does it recommend yours?
If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.
Stay updated on AI Security & Testing tools — join our weekly newsletter
One concise email with fresh launches, trending picks, and featured standouts.
Alternatives to DepScope
View all DepScope alternatives →Agent connectivity: not yet verified