Sviluppo · Server MCP locale
Dependency Auditor
CVE scanning for npm/pip/cargo dependencies via OSV.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.4hmetuyar/dependency-auditor- Versione
- 0.2.4
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 28 settembre 2026
- Aggiornato
- 28 settembre 2026
- Editore
- 4hmetuyar (GitHub) · 26 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/4hmetuyar) · come funziona
- Repository
- github.com/GuardBee/guardbee-mcp (cartella packages/dependency-auditor)
- Fonte
- Voce nell’API del registro
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npm | @guardbee/mcp-dependency-auditor | 0.2.4 | stdio |
Come collegare Dependency Auditor
Dependency Auditor viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @guardbee/mcp-dependency-auditor, versione 0.2.4. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @guardbee/mcp-dependency-auditor@0.2.4.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"dependency-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-dependency-auditor@0.2.4"
]
}
}
}Ricavato dalla voce del registro, non testato qui. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di 4hmetuyar (GitHub)
| Server | Esecuzione |
|---|---|
| A2a AuditorScans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure. | Locale · stdio |
| Agent Graph AuditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs. | Locale · stdio |
| Ai Code ScannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection. | Locale · stdio |
| Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases. | Locale · stdio |
| Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log. | Locale · stdio |
| Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection. | Locale · stdio |
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | Locale · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Locale · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | Locale · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | Locale · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Locale · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Locale · stdio |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| Dep Diff MCPTranslates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Dep OraclePredictive dependency security engine. Trust scores, zombie detection, blast radius analysis. | Locale · stdio |
| Dep ScopeSymbol-level npm dependency analysis: scan verdicts, native alternatives, migration prompts. | Locale · stdio |
| DepcheckKnown vulnerabilities for exact package versions from OSV, with fixes. Paid per call, x402. | Remoto · HTTPVerifica live: ✓ handshake |
| Dependency Freshness MCPNpm & PyPI freshness for AI agents: latest version, deprecations, dated breaking-change diffs. | Remoto · HTTPVerifica live: accesso richiesto |
| Dependency Management MCP ServerSonatype component intelligence: versions, security analysis, and Trust Score recommendations. | Remoto · HTTPVerifica live: accesso richiesto |
| Dependency Vulnerability Tracker - package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session - free testnet funds. | Remoto · HTTPVerifica live: ✓ handshake |
| DepFeedChange intelligence for coding agents: sourced breaking changes for npm, PyPI, and Rust packages. | Remoto · HTTPVerifica live: ✗ nessun handshake |