✍️Writing & Content35🎨Image Generation43🎬Video & Animation76🎵Audio & Music67💬Chatbots & Assistants58💻Coding & Development284📈Marketing & SEO87Productivity218🎯Design & UI/UX71📊Data & Analytics69📚Education & Research30💼Business & Finance75🏥Healthcare & Wellness18🔍Search & Knowledge17🤖AI Agent Infrastructure121🛡️AI Security & Testing17🧊3D & Spatial21🔎SEO Tools34🏡Real Estate4🗃️Data Extraction32🧠ADHD & Focus Tools9
Listed in AI Security & Testing with 17 other toolsPart of 1554+ curated AI tools on AISO
DepScope logo

DepScope

Free keyless MCP server that catches hallucinated, vulnerable, and typosquatted packages

0
freeFree for everyone — no API key, no auth, no rate limit, no signup. SDKs are open source. No paid tier is published.View full pricing →

Visit DepScope

https://depscope.dev

About DepScope

DepScope is a free MCP server that screens every package an AI agent suggests before it reaches npm install. It targets three specific failure modes. The first is hallucination: LLMs invent plausible-sounding package names, and DepScope verifies each one against live registries across 19 ecosystems and flags typosquats by Levenshtein distance to popular packages — the exact mechanism attackers rely on when they register a name a model is likely to hallucinate. The second is vulnerability exposure, covered by live lookups against OSV, CISA's Known Exploited Vulnerabilities list, EPSS scores, the OpenSSF malicious-package feed, and a deprecated-package index, returning severity, fix version, and migration path in one call. The third is token cost: pre-curated briefs of roughly 300 tokens replace the four-to-eight thousand tokens an agent would otherwise burn scraping registry and CVE pages per decision, a reported 74% reduction. It covers 8.5 million packages across 19 ecosystems — npm, PyPI, Cargo, Go, Composer, Maven, NuGet, RubyGems, pub, hex, Swift, CPAN, Hackage, CRAN, conda, Homebrew, JSR, and Julia — with 22 MCP tools, no auth, no API key, and no rate limit. Remote MCP works out of the box in Claude Desktop, Cursor, and Windsurf, with a curl one-liner for everything else, and the SDKs are open source. There is also a browser paste-a-manifest scan and a published ten-model hallucination benchmark.

Key Features

Hallucination guard verifies packages against live registries in 19 ecosystems
Typosquat detection by Levenshtein distance to popular package names
Live CVE intel from OSV, CISA KEV, EPSS, and the OpenSSF malicious feed
Severity, fix version, and migration path returned in one call
~300-token briefs replacing 4–8k tokens of scraping per decision (−74%)
8.5M packages, 19 ecosystems, 22 MCP tools
Remote MCP with zero install in Claude Desktop, Cursor, and Windsurf
Browser manifest scan plus a published 10-model hallucination benchmark

DepScope Pros & Cons

Pros

  • +Completely free with no key, no quota, and no signup — nothing to evaluate around
  • +Slot-hallucination and typosquatting are a real, actively exploited attack path
  • +Token savings are a direct cost reduction on every agent dependency decision
  • +Ecosystem coverage well beyond the usual npm-and-PyPI pairing

⚠️ Cons

  • No published business model, which raises questions about long-term availability
  • No auth and no rate limit means no SLA or support commitment either
  • Screening is advisory — it does not block installs on its own
  • Depends on upstream feeds (OSV, KEV, EPSS) for freshness

Who Is DepScope Best For?

👤Anyone letting a coding agent add dependencies to a real project
👤Teams worried about slopsquatting and hallucinated package names
👤Developers who want CVE context inline in the agent rather than in a separate scan

Tags

mcpsupply-chainsecuritynpmfreeopen-source
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends DepScope. Does it recommend yours?

If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Stay updated on AI Security & Testing tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to DepScope

View all DepScope alternatives →

Agent connectivity: not yet verified