Developer · Local MCP server
Dependency Auditor
CVE scanning for npm/pip/cargo dependencies via OSV.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/dependency-auditor- Version
- 0.2.4
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-28
- Updated
- 2026-09-28
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/dependency-auditor)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-dependency-auditor | 0.2.4 | stdio |
How to connect Dependency Auditor
Dependency Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-dependency-auditor version 0.2.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-dependency-auditor@0.2.4.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"dependency-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-dependency-auditor@0.2.4"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| A2a AuditorScans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure. | Local · stdio |
| Agent Graph AuditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs. | Local · stdio |
| Ai Code ScannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection. | Local · stdio |
| Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases. | Local · stdio |
| Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log. | Local · stdio |
| Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection. | Local · stdio |
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | Local · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Local · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | Local · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | Local · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Local · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| DepLicense check, outdated deps, security for AI agents. | Local · stdio |
| Dep Diff MCPTranslates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions. | Remote & Local · HTTP, stdio |
| Dep OraclePredictive dependency security engine. Trust scores, zombie detection, blast radius analysis. | Local · stdio |
| Dep ScopeSymbol-level npm dependency analysis: scan verdicts, native alternatives, migration prompts. | Local · stdio |
| Dependency Freshness MCPNpm & PyPI freshness for AI agents: latest version, deprecations, dated breaking-change diffs. | Remote · HTTP |
| Dependency Management MCP ServerSonatype component intelligence: versions, security analysis, and Trust Score recommendations. | Remote · HTTP |
| Dependency MCPMCP server for checking package versions across multiple package managers. | Local · stdio |
| Dependency Vulnerability Tracker — package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session — free testnet funds. | Remote · HTTP |