DepScout

io.github.yc-droidv1.0.0Updated Oct 7, 2026

Scan packages and lockfiles (npm, PyPI, Go, Maven, Cargo, NuGet) for vulnerabilities and malware.

VerifiedStreamable HTTPWeb executableDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Scans package manifests and lockfiles across npm, PyPI, Go, Maven, Cargo and NuGet for known vulnerabilities and malware.

What it does
DepScout is a remote MCP server that checks software dependencies for security problems. According to its registry description, it scans packages and lockfiles for the npm, PyPI, Go, Maven, Cargo and NuGet ecosystems, looking for vulnerabilities and malware. No individual tools are listed in the manifest, so the exact operations are not documented here.
When to use it
Useful when an assistant needs to review a project's dependencies for known vulnerabilities or malicious packages, for example during a dependency audit or before adding a new library. It fits workflows where lockfiles or package manifests are already available to check.
Requirements
A remote streamable HTTP endpoint at the provider's hosted address; no local runtime, package, environment variables or headers are declared. The manifest declares no authentication, so no credentials appear to be needed.
Before you install
The manifest declares no authentication, environment variables or headers, so no secrets are requested. Because it is a hosted third-party service, any package names, lockfile contents or dependency data sent to it leave the user's machine; avoid submitting private or proprietary dependency information unless that is acceptable.

Installation

In SourceWeft

  1. Open DepScout in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "depscout": {
      "type": "http",
      "url": "https://depscout.salesup.workers.dev/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestOct 7, 2026