Server definition
- Hash
- sha256:aef119e6868549594bf6df1af9b8e34b7979cc893db33159f801cfa739f10666
- What it is
- What a remote MCP server returned when asked what it offers: 22 tools
The blob, as servednamed by its sha256
{
"instructions": "DepScope: dependency safety & intelligence MCP for AI agents. Covers 19 package ecosystems: npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia.\n\nINVOKE PROACTIVELY — before suggesting any package install, version bump, lockfile change, or when a 'module not found' / 'package broken' error appears. Do NOT wait for the user to ask.\n\nThree pillars:\n- TOKEN-SAVING: one DepScope call replaces a web search + readme fetch + npm/pypi page browse.\n- ENERGY-SAVING: skip installs of malicious, typosquatted, deprecated or hallucinated packages — no wasted CI cycles or rollbacks.\n- SECURITY: stop supply-chain attacks (malware, typosquats, hostile takeovers, known CVEs) BEFORE the install command leaves your reply.\n\nStandard flow for any new package:\n1. check_malicious + check_typosquat — security gate (~50ms)\n2. check_package OR get_health_score — verdict\n3. install_command — returns the safe pinned command\n\nBatch installs (>=2 packages): use check_bulk in ONE call (≤100 items, <100ms).\nLockfile / requirements.txt / package.json change: use scan_project.\nVersion bumps (X@1 → X@2): use get_breaking_changes + get_migration_path.\nDiagnose 'module not found' / 'X.Y broken' errors: use resolve_error and get_known_bugs.\nChoosing between libraries: use find_alternatives and compare_packages.\n\nAll tools are read-only, zero-auth, free. Never destructive. Latency typically 50-300ms per call.",
"tools": [
{
"description": "Fast pre-flight filter for a batch of (ecosystem, package) pairs. DB-only, <100ms for 100 items. USE WHEN: about to emit `npm install a b c …` or `pip install a b c …` — catches hallucinated names, stdlib, typos, and known-bad in ONE call. NOT a dep-tree audit (use scan_project for that). RETURNS: per-item {status: exists|stdlib|malicious|typosquat_suspect|historical_incident|unknown}.",
"inputSchema": {
"properties": {
"items": {
"items": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"maxItems": 100,
"type": "array"
}
},
"required": [
"items"
],
"type": "object"
},
"name": "check_bulk",
"outputSchema": null
},
{
"description": "Is this specific multi-package version combo verified to work together? USE WHEN: pinning a stack (next@15 + react@19 + node@22); before recommending a version matrix. RETURNS: {compatible, conflicts[], notes}.",
"inputSchema": {
"properties": {
"packages": {
"additionalProperties": {
"type": "string"
},
"description": "Package -> version map, e.g. {\"next\":\"15\",\"react\":\"19\"}.",
"type": "object"
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "check_compatibility",
"outputSchema": null
},
{
"description": "Supply-chain malware check against OpenSSF/OSV. USE WHEN: about to suggest install of an unvetted/unfamiliar package; name came from a blog/tutorial. Call BEFORE check_package for untrusted pkgs. RETURNS: {is_malicious, threat_tier, source}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_malicious",
"outputSchema": null
},
{
"description": "Full machine-readable JSON report (~2k tokens). USE WHEN: you need to programmatically parse specific fields (CI gating, UI, sub-field extraction). Otherwise prefer get_package_prompt. RETURNS: {package, health:{score}, vulnerabilities[], latest, deprecated, maintainers, recommendation}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"description": "Package name (e.g. 'express', 'fastapi', 'serde').",
"type": "string"
},
"version": {
"description": "Specific version (optional; default = latest).",
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_package",
"outputSchema": null
},
{
"description": "Typosquat detector. USE WHEN: name differs from a well-known package by 1-2 chars (`lodsh`, `reqeusts`); copy-paste from unreliable source; downloads near zero but name looks familiar. RETURNS: {is_typosquat, likely_target, confidence}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "check_typosquat",
"outputSchema": null
},
{
"description": "Side-by-side comparison (health, vulns, downloads, maintainers, last release) of 2-10 packages in the same ecosystem. USE WHEN: 'X vs Y' / 'should I pick X or Y'. RETURNS: table-shaped JSON, one row per package.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"packages": {
"description": "Package names to compare, e.g. ['express','fastify','hono'].",
"items": {
"type": "string"
},
"maxItems": 10,
"minItems": 2,
"type": "array"
}
},
"required": [
"ecosystem",
"packages"
],
"type": "object"
},
"name": "compare_packages",
"outputSchema": null
},
{
"description": "Inbound ticket: bug/listing/security/anomaly/partnership. USE WHEN: reporting wrong data (`bug`), requesting a new pkg/ecosystem index (`listing`), disclosing a DepScope security issue (`security`), flagging a concrete mismatch in another tool's output vs. authoritative source (`anomaly` — provide tool_called+observed+expected), or partnership/press (`partnership`). RETURNS: {ticket_id} or {anomaly_id}.",
"inputSchema": {
"properties": {
"body": {
"description": "Message body (10-8000 chars). Be specific: include package name, ecosystem, error trace, repro steps when applicable.",
"type": "string"
},
"company": {
"description": "Company / organization (optional).",
"type": "string"
},
"ecosystem": {
"description": "For kind=anomaly: ecosystem of the involved package, if any.",
"type": "string"
},
"email": {
"description": "Reply-to email of the requester (required for bug/listing/security/partnership).",
"type": "string"
},
"evidence_url": {
"description": "For kind=anomaly: URL to authoritative source (registry page, GHSA, CVE, repo, ...) supporting your expectation.",
"type": "string"
},
"expected": {
"description": "For kind=anomaly: what you expected to see (1-1500 chars). Be concrete.",
"type": "string"
},
"kind": {
"description": "Ticket category. `anomaly` routes to structured anomaly triage (requires tool_called/observed/expected).",
"enum": [
"bug",
"listing",
"security",
"anomaly",
"partnership"
],
"type": "string"
},
"name": {
"description": "Sender display name (optional).",
"type": "string"
},
"observed": {
"description": "For kind=anomaly: what DepScope returned (1-1500 chars).",
"type": "string"
},
"package": {
"description": "For kind=anomaly: package name involved, if any.",
"type": "string"
},
"subject": {
"description": "Short subject line (3-200 chars).",
"type": "string"
},
"tool_called": {
"description": "For kind=anomaly: DepScope tool that produced the anomaly (e.g. check_package, get_migration_path).",
"type": "string"
},
"version": {
"description": "For kind=anomaly: package version involved, if any.",
"type": "string"
}
},
"type": "object"
},
"name": "contact_depscope",
"outputSchema": null
},
{
"description": "Curated replacements for deprecated/unhealthy packages, including stdlib built-ins (e.g. `fs.rm` for rimraf). USE WHEN: pkg flagged AVOID/URGENT; 'what to use instead of X'; before guessing a replacement name. RETURNS: {alternatives[]: {name, reason, is_stdlib}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "find_alternatives",
"outputSchema": null
},
{
"description": "Breaking changes between two majors of the SAME package (`next@14`→`15`). USE WHEN: user is bumping a major; before recommending a major upgrade. Different from get_migration_path (same pkg vs. different pkg). RETURNS: {breaking_changes[]: {area, description, hint}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"from_version": {
"type": "string"
},
"package": {
"type": "string"
},
"to_version": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_breaking_changes",
"outputSchema": null
},
{
"description": "Single 0-100 health score — cheapest go/no-go gate (>=70 safe). USE WHEN: CI gating or pkg already screened for malware/typos. NOT a first screen — run check_malicious + check_typosquat first. For a verbal verdict use get_package_prompt. RETURNS: {score, verdict}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_health_score",
"outputSchema": null
},
{
"description": "Non-CVE known bugs for a specific package version. USE WHEN: unexpected behavior that is NOT a security issue; a pinned version misbehaves. RETURNS: {bugs[]: {title, fixed_in, workaround}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
},
"version": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_known_bugs",
"outputSchema": null
},
{
"description": "Latest published version + deprecation flag — the cheapest call. USE WHEN: only a version string matters (pinning a dep, answering 'what version of X'). If you also need health/vulns use check_package. RETURNS: {latest, deprecated, published_at}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_latest_version",
"outputSchema": null
},
{
"description": "Prescriptive migration plan between DIFFERENT packages — rationale + literal code diff + breaking changes + effort minutes. USE WHEN: replacing `request`→`axios`, `moment`→`dayjs`, `flask`→`fastapi`, etc.; both endpoints known. RETURNS: {rationale, diff, breaking_changes[], estimated_minutes}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"from_package": {
"description": "Deprecated/legacy package to migrate away from.",
"type": "string"
},
"to_package": {
"description": "Modern replacement package.",
"type": "string"
}
},
"required": [
"ecosystem",
"from_package",
"to_package"
],
"type": "object"
},
"name": "get_migration_path",
"outputSchema": null
},
{
"description": "LLM-optimised package brief — plain text ~300 tokens (~75% cheaper than JSON). Verdict (SAFE/AVOID/URGENT/MALICIOUS) + health + vulns + alternatives + maintainer alerts. USE WHEN: you want to reason over a package and drop the output directly in context; 'is X safe'. PREFER THIS over check_package in 95% of LLM cases. RETURNS: plain-text brief.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_package_prompt",
"outputSchema": null
},
{
"description": "Live trending packages with rank-delta and weekly growth %. USE WHEN: 'what is rising in npm/PyPI/Cargo right now'; recommendation not biased by training-data cutoff. RETURNS: {items[]: {name, rank, rank_delta, weekly_growth_pct}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "Optional. If omitted returns cross-ecosystem trending.",
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"limit": {
"description": "Max results, 1-50. Default 20.",
"type": "integer"
},
"scope": {
"description": "Time window. Defaults to week.",
"enum": [
"all",
"week",
"day"
],
"type": "string"
}
},
"type": "object"
},
"name": "get_trending",
"outputSchema": null
},
{
"description": "One-call aggregate of ALL non-CVE supply-chain trust signals: maintainer trust (bus factor, ownership changes), OpenSSF Scorecard, quality (criticality, release velocity, publish security), and SLSA/Sigstore provenance. USE WHEN: deep-vetting a package beyond CVEs (hardened/regulated env, SBOM/compliance, small-pkg ownership review, choosing between healthy candidates). Runs 4 backend endpoints in parallel. RETURNS: {maintainer, scorecard, quality, provenance} — each may be null if its backend call failed.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_trust_signals",
"outputSchema": null
},
{
"description": "CVE/OSV advisories affecting the latest (or specified) version. USE WHEN: security-sensitive project; user asks 'any CVEs in X'; you already know the pkg exists. RETURNS: {vulnerability_count, vulnerabilities[]: {id, severity, cvss, fixed_in}}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "get_vulnerabilities",
"outputSchema": null
},
{
"description": "Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, …). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
},
"version": {
"description": "Optional explicit version; defaults to latest.",
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "install_command",
"outputSchema": null
},
{
"description": "Boolean registry existence check. USE WHEN: about to emit a package name in an install command but unsure it exists; verifying a name generated from training data. RETURNS: {exists}.",
"inputSchema": {
"properties": {
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "package_exists",
"outputSchema": null
},
{
"description": "Highest version below the chosen CVE severity tier, respecting a semver constraint. USE WHEN: writing a package.json/requirements.txt line; resolving dependabot by lowest-risk patched version. RETURNS: {recommended_version, walk_log[]}.",
"inputSchema": {
"properties": {
"constraint": {
"description": "npm-style constraint: ^X.Y.Z, ~X.Y.Z, >=X.Y.Z, or exact X.Y.Z.",
"type": "string"
},
"ecosystem": {
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"include_prerelease": {
"default": false,
"type": "boolean"
},
"min_severity": {
"description": "Lowest severity to exclude. Default: high (excludes critical+high).",
"enum": [
"critical",
"high",
"medium",
"low"
],
"type": "string"
},
"package": {
"type": "string"
}
},
"required": [
"ecosystem",
"package"
],
"type": "object"
},
"name": "pin_safe",
"outputSchema": null
},
{
"description": "Map error OR free-text query to a verified fix. USE WHEN: user pastes a concrete error/stack (ENOENT, ImportError, build failure) — pass `error`. OR user describes a symptom ('webpack slow', 'pip stuck') — pass `query`. Always prefer this over guessing a fix. RETURNS: exact-match {status, solution, confidence, source_url} or search results [{title, summary, source_url}].",
"inputSchema": {
"properties": {
"context": {
"description": "Optional context for error-mode calls (ecosystem, package, version).",
"type": "object"
},
"error": {
"description": "Concrete error message / stack trace. Triggers exact-match lookup.",
"type": "string"
},
"limit": {
"default": 10,
"description": "Max search results (query mode only).",
"maximum": 20,
"minimum": 1,
"type": "integer"
},
"query": {
"description": "Free-text symptom description. Triggers KB search.",
"type": "string"
}
},
"type": "object"
},
"name": "resolve_error",
"outputSchema": null
},
{
"description": "Audit a project's dependencies in one shot. Returns a single-sentence `verdict` (e.g. \"DO NOT INSTALL — 1 hallucinated: fastapi-turbo\") that an agent can paste into its reply, plus per-package health/vulns/recommendation. Detects hallucinated packages, deprecated, typosquats, critical vulnerabilities. Accepts EITHER {ecosystem, packages:[name@ver, …]} (up to 100, returns JSON) OR {packages:[{ecosystem, package}, …]} (up to 50, mixed ecosystems, returns text brief). USE WHEN: user pastes package.json/requirements.txt/Cargo.toml; agent generated install command; 'is my stack OK'. RETURNS: JSON with `verdict`, `project_risk`, `summary.hallucinated_packages`, `summary.deprecated_packages`, per-package health.",
"inputSchema": {
"properties": {
"ecosystem": {
"description": "Required when packages is a string array.",
"enum": [
"npm",
"pypi",
"cargo",
"go",
"composer",
"maven",
"nuget",
"rubygems",
"pub",
"hex",
"swift",
"cocoapods",
"cpan",
"hackage",
"cran",
"conda",
"homebrew",
"jsr",
"julia"
],
"type": "string"
},
"packages": {
"description": "Either ['express','[email protected]'] (single ecosystem, up to 100) or [{ecosystem, package}, …] (mixed, up to 50)."
}
},
"required": [
"packages"
],
"type": "object"
},
"name": "scan_project",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:aef119e6868549594bf6df1af9b8e34b7979cc893db33159f801cfa739f10666 | sha256sum