פיתוח · שרת MCP מקומי
Dependency Auditor
CVE scanning for npm/pip/cargo dependencies via OSV.
מה ה-MCP Registry מציין
הרשומה כפי שפורסמה ב-MCP Registry הרשמי (נקרא ב-4 באוקטובר 2026), בגרסה האחרונה.
- שם במרשם
io.github.4hmetuyar/dependency-auditor- גרסה
- 0.2.4
- סטטוס
- פעיל
- קטגוריה
- פיתוח
- שכבת תעבורה
- stdio (תהליך מקומי)
- חבילה
- npm
- פורסם
- 28 בספטמבר 2026
- עודכן
- 28 בספטמבר 2026
- מפרסם
- 4hmetuyar (GitHub) · 26 שרתים עם דפים כאן
- מרחב שמות
- מרחב השמות אומת על ידי ה-MCP Registry דרך GitHub (github.com/4hmetuyar) · איך
- מאגר קוד
- github.com/GuardBee/guardbee-mcp (תיקייה packages/dependency-auditor)
- מקור
- הרשומה ב-API של המרשם
חבילות
| מרשם | חבילה | גרסה | שכבת תעבורה |
|---|---|---|---|
| npm | @guardbee/mcp-dependency-auditor | 0.2.4 | stdio |
איך מחברים את Dependency Auditor
Dependency Auditor רץ באופן מקומי מתוך חבילת Node.js שפורסמה במרשם npm: @guardbee/mcp-dependency-auditor, גרסה 0.2.4. הוא משתמש ב-MCP על גבי stdio, ולכן הלקוח מפעיל אותו כתוכנה ומתקשר איתו דרך קלט ופלט סטנדרטיים. כדי להריץ אותו צריך Node.js; לקוחות מפעילים אותו בדרך כלל עם npx - הפקודה המקובלת היא npx -y @guardbee/mcp-dependency-auditor@0.2.4.
בפורמט ה-JSON של mcpServers, שלקוחות MCP רבים לדסקטופ ולעורכי קוד קוראים, הרשומה נראית כך (מצייני מקום בסוגריים זוויתיים):
{
"mcpServers": {
"dependency-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-dependency-auditor@0.2.4"
]
}
}
}נגזר מהרשומה במרשם, ולא נבדק כאן. מה השרת עושה, ובאילו תנאים, נקבע על ידי המפרסם שלו; כדאי לבדוק את מאגר הקוד או את האתר שלו לפני שנותנים לו גישה לחשבונות או לקבצים שלך. איך מוסיפים שרת MCP לעוזר AI · לפני שמתחברים
עוד מ-4hmetuyar (GitHub)
| שרת | הרצה |
|---|---|
| A2a AuditorScans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure. | מקומי · stdio |
| Agent Graph AuditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs. | מקומי · stdio |
| Ai Code ScannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection. | מקומי · stdio |
| Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases. | מקומי · stdio |
| Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log. | מקומי · stdio |
| Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection. | מקומי · stdio |
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | מקומי · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | מקומי · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | מקומי · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | מקומי · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | מקומי · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | מקומי · stdio |
עוד שרתים בקטגוריה פיתוח
| שרת | הרצה |
|---|---|
| Dep Diff MCPTranslates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions. | מרוחק ומקומי · HTTP ו-stdioבדיקה חיה: ✓ לחיצת יד |
| Dep OraclePredictive dependency security engine. Trust scores, zombie detection, blast radius analysis. | מקומי · stdio |
| Dep ScopeSymbol-level npm dependency analysis: scan verdicts, native alternatives, migration prompts. | מקומי · stdio |
| DepcheckKnown vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402. | מרוחק · HTTPבדיקה חיה: ✓ לחיצת יד |
| Dependency Freshness MCPNpm & PyPI freshness for AI agents: latest version, deprecations, dated breaking-change diffs. | מרוחק · HTTPבדיקה חיה: נדרשת התחברות |
| Dependency Management MCP ServerSonatype component intelligence: versions, security analysis, and Trust Score recommendations. | מרוחק · HTTPבדיקה חיה: נדרשת התחברות |
| Dependency Vulnerability Tracker - package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session - free testnet funds. | מרוחק · HTTPבדיקה חיה: ✓ לחיצת יד |
| DepFeedChange intelligence for coding agents: sourced breaking changes for npm, PyPI, and Rust packages. | מרוחק · HTTPבדיקה חיה: ✗ אין לחיצת יד |