Developer · Local MCP server

Dependency Auditor

CVE scanning for npm/pip/cargo dependencies via OSV.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.4hmetuyar/dependency-auditor
Version
0.2.4
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-09-28
Updated
2026-09-28
Publisher
4hmetuyar (GitHub) · 26 servers with pages here
Repository
github.com/GuardBee/guardbee-mcp (folder packages/dependency-auditor)
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npm@guardbee/mcp-dependency-auditor0.2.4stdioNone declared

How to connect Dependency Auditor

Dependency Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-dependency-auditor version 0.2.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-dependency-auditor@0.2.4.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "dependency-auditor": {
      "command": "npx",
      "args": [
        "-y",
        "@guardbee/mcp-dependency-auditor@0.2.4"
      ]
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from 4hmetuyar (GitHub)

All 26 →
ServerRunsEndpoint or package
A2a AuditorScans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure.Local · stdionpm: @guardbee/mcp-a2a-auditor
Agent Graph AuditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs.Local · stdionpm: @guardbee/mcp-agent-graph-auditor
Ai Code ScannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection.Local · stdionpm: @guardbee/mcp-ai-code-scanner
Compliance CheckerKVKK/GDPR/CCPA compliance checks for codebases.Local · stdionpm: @guardbee/mcp-compliance-checker
Db GatewayKVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log.Local · stdionpm: @guardbee/mcp-db-gateway
Dns IntelligenceDNS record enumeration, misconfiguration and dangling-subdomain detection.Local · stdionpm: @guardbee/mcp-dns-intelligence
Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs.Local · stdionpm: @guardbee/mcp-elicitation-auditor
Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints.Local · stdionpm: @guardbee/mcp-llm-redteam
MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats.Local · stdionpm: @guardbee/mcp-config-auditor
MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets.Local · stdionpm: @guardbee/mcp-server-auditor
Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory.Local · stdionpm: @guardbee/mcp-memory-poisoning-scanner
Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks.Local · stdionpm: @guardbee/mcp-model-scanner

More developer servers

All 6,250 →
ServerRunsEndpoint or package
DepLicense check, outdated deps, security for AI agents.Local · stdionpm: @rog0x/mcp-dep-tools
Dep Diff MCPTranslates a lockfile diff into a human-readable upgrade plan for npm, PyPI, and GitHub Actions.Remote & Local · HTTP, stdiodep-diff.digicatalyst.ca
Dep OraclePredictive dependency security engine. Trust scores, zombie detection, blast radius analysis.Local · stdionpm: dep-oracle
Dep ScopeSymbol-level npm dependency analysis: scan verdicts, native alternatives, migration prompts.Local · stdionpm: @florianbruniaux/dep-scope
Dependency Freshness MCPNpm & PyPI freshness for AI agents: latest version, deprecations, dated breaking-change diffs.Remote · HTTPpeppy-weekend--dependency-freshness-mcp.apify.actor
Dependency Management MCP ServerSonatype component intelligence: versions, security analysis, and Trust Score recommendations.Remote · HTTPmcp.guide.sonatype.com
Dependency MCPMCP server for checking package versions across multiple package managers.Local · stdionpm: dependency-mcp
Dependency Vulnerability Tracker — package security advisories ($0.01/query)Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.Remote · HTTPa2awire.com