PluginBench
MCP Server
Active
Apache-2.0

SafeDep Vet MCP MCP Server

io.github.safedep/vet-mcp

Real-time malicious package detection and software supply chain security for AI agents and IDEs.

What is the SafeDep Vet MCP MCP server?

SafeDep Vet MCP is an MCP server that protects AI agents and IDEs from malicious open-source packages through real-time threat intelligence and behavioral analysis. It scans dependencies across multiple ecosystems (npm, PyPI, Maven, Go, Ruby, Rust, PHP) and container images to detect zero-day malware, vulnerabilities, and policy violations using CEL-based policy-as-code enforcement.

Vet integrates SafeDep's malicious package detection into your AI workflow and development environment. It analyzes your project dependencies against a continuously-updated threat intelligence database, performs static and dynamic behavioral analysis to catch zero-day malware, and lets you enforce security policies as code. Unlike traditional SCA tools that flood you with CVE noise, vet prioritizes actual risks by analyzing real code usage patterns.

How to install SafeDep Vet MCP

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "vet-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/safedep/vet:v1.19.1",
        "--rm",
        "-i",
        "-s",
        "-l",
        "/tmp/vet-mcp.log",
        "server",
        "mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • scan — Scan dependencies in directories, repositories, container images, and SBOMs for malware, vulnerabilities, and policy violations
  • malware-query — Query SafeDep's threat intelligence database for known malicious packages (no API key required)
  • policy-as-code — Define and enforce security policies using CEL expressions for CVE severity, license compliance, and OpenSSF Scorecard requirements
  • dependency-usage-analysis — Analyze actual code usage to identify which vulnerabilities and risks actually impact your project
  • multi-format-reporting — Generate reports in SARIF, JSON, CSV, HTML, and Markdown formats
  • SBOM-support — Import and export CycloneDX and SPDX SBOMs
  • AI-usage-discovery — Discover AI tool usage signals across various tools and configurations
  • GitHub-Actions-pinning — Pin GitHub Actions to commit SHAs to prevent supply chain attacks

Use cases

  • Scan your project dependencies for known malicious packages before they reach production
  • Enforce security policies in CI/CD pipelines (GitHub Actions, GitLab CI) to fail builds on critical vulnerabilities or policy violations
  • Analyze container images and VS Code extensions for malware and supply chain risks
  • Discover AI tool usage across your codebase and configurations
  • Generate compliance reports (SARIF, JSON, Markdown) for security audits and policy enforcement

SafeDep Vet MCP MCP server FAQ

What is SafeDep Vet MCP?

Vet is an MCP server that integrates SafeDep's malicious package detection and supply chain security scanning into AI agents and IDEs. It detects zero-day malware, analyzes vulnerabilities based on actual code usage, and enforces security policies as code.

Is it free?

Yes, vet is free for open source projects. Malware detection queries against SafeDep's threat intelligence database require no API key. SafeDep Cloud offers additional features and hosted SaaS options for enterprises.

How do I install it in Cursor or Claude?

Add the MCP server configuration pointing to the container image `ghcr.io/safedep/vet:v1.19.1`. Alternatively, install vet locally via Homebrew (`brew install safedep/tap/vet`), npm, or download a pre-built binary, then configure your AI editor to use it.

What authentication is required?

No authentication is required for basic malware queries against SafeDep's threat intelligence database. Advanced features and continuous monitoring through SafeDep Cloud may require an account.

What package managers does it support?

Vet supports npm, PyPI, Maven, Go, Ruby, Rust, PHP, and can scan container images (Docker/OCI) and SBOM formats (CycloneDX, SPDX).

Can it integrate with CI/CD?

Yes, vet integrates with GitHub Actions (via vet-action), GitLab CI, and can run in any container environment. It supports zero-config security guardrails and policy enforcement in CI/CD pipelines.

README (reference)

Source of truth, from the repository.

<p align="center"> <a href="https://safedep.io"> <picture> <source srcset="docs/assets/vet-banner-dark.svg" media="(prefers-color-scheme: dark)"> <source srcset="docs/assets/vet-banner-light.svg" media="(prefers-color-scheme: light)"> <img src="docs/assets/vet-banner-light.svg" alt="SafeDep VET - Real-time malicious package detection & software supply chain security" width="100%"> </picture> </a> </p> <div align="center"> <p> <a href="#quick-start"><strong>Quick Start</strong></a> • <a href="https://docs.safedep.io/"><strong>Documentation</strong></a> • <a href="#community--support"><strong>Community</strong></a> </p> </div> <div align="center">

Go Report Card License Release OpenSSF Scorecard SLSA 3 CodeQL

Ask DeepWiki MCP Toplist

</div>

[!NOTE] vet also runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform.

Why vet?

70-90% of modern software is open source code — how do you know it's safe?

Traditional SCA tools drown you in CVE noise. vet takes a different approach:

  • Shadow AI discovery — Discover AI tool usage signals across various tools and configurations
  • Catch malware before it ships — Zero-day detection through static and dynamic behavioral analysis (requires SafeDep Cloud access)
  • Cut through vulnerability noise — Analyzes actual code usage to surface only the risks that matter
  • Enforce policy as code — Express security, license, and quality requirements as CEL expressions
  • CI/CD integration — Zero-config security guardrails in CI/CD

Free for open source. Hosted SaaS available at SafeDep.

Quick Start

Install in seconds:

# macOS & Linux
brew install safedep/tap/vet

# Using npm
npm install -g @safedep/vet

or download a pre-built binary

Get started immediately:

# Scan for malware in your dependencies
vet scan -D . --malware-query

# Fail CI on critical vulnerabilities
vet scan -D . --filter 'vulns.critical.exists(p, true)' --filter-fail

Architecture

vet follows a pipeline architecture: readers ingest package manifests from diverse sources (directories, repositories, container images, SBOMs), enrichers augment each package with vulnerability, malware, and scorecard data from SafeDep Cloud, the CEL policy engine evaluates security policies against enriched data, and reporters produce actionable output in formats like SARIF, JSON, and Markdown.

<details> <summary>View architecture diagram</summary>
graph TB
    subgraph "OSS Ecosystem"
        R1[npm Registry]
        R2[PyPI Registry]
        R3[Maven Central]
        R4[Other Registries]
    end

    subgraph "SafeDep Cloud"
        M[Continuous Monitoring]
        A[Real-time Code Analysis<br/>Malware Detection]
        T[Threat Intelligence DB<br/>Vulnerabilities • Malware • Scorecard]
    end

    subgraph "vet CLI"
        S[Source Repository<br/>Scanner]
        P[CEL Policy Engine]
        O[Reports & Actions<br/>SARIF/JSON/CSV]
    end

    R1 -->|New Packages| M
    R2 -->|New Packages| M
    R3 -->|New Packages| M
    R4 -->|New Packages| M
    M -->|Behavioral Analysis| A
    A -->|Malware Signals| T

    S -->|Query Package Info| T
    T -->|Security Intelligence| S
    S -->|Analysis Results| P
    P -->|Policy Decisions| O

    style M fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
    style A fill:#E8A87C,stroke:#B88A5A,color:#1a1a1a
    style T fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
    style S fill:#90C695,stroke:#6B9870,color:#1a1a1a
    style P fill:#E8C47C,stroke:#B89B5A,color:#1a1a1a
    style O fill:#B8A3D4,stroke:#9478AA,color:#1a1a1a
</details>

Key Features

Malicious Package Detection

Real-time protection against malicious packages powered by SafeDep Cloud. Free for open source projects. Detects zero-day malware through active code analysis.

Vulnerability Analysis

Unlike dependency scanners that flood you with noise, vet analyzes your actual code usage to prioritize real risks. See dependency usage evidence for details.

Policy as Code

Define security policies using CEL expressions to enforce context specific requirements:

# Block packages with critical CVEs
vet scan --filter 'vulns.critical.exists(p, true)' --filter-fail

# Enforce license compliance
vet scan --filter 'licenses.contains_license("GPL-3.0")' --filter-fail

# Require minimum OpenSSF Scorecard scores
vet scan --filter 'scorecard.scores.Maintained < 5' --filter-fail

Multi-Ecosystem Support

Package managers: npm, PyPI, Maven, Go, Ruby, Rust, PHP Container images: Docker, OCI SBOM formats: CycloneDX, SPDX Source repositories: GitHub, GitLab

Malicious Package Detection

Real-time protection against malicious packages by querying SafeDep's threat intelligence database, continuously populated through static and dynamic behavioral analysis.

Quick Setup

# Query known malicious packages (no API key needed)
vet scan -D . --malware-query

[!NOTE] The --malware flag is deprecated. Active (on-demand) scanning has been retired in favour of querying SafeDep's threat intelligence database. --malware now behaves identically to --malware-query and is retained for backward compatibility.

Example detections:

Key security features:

  • Real-time lookups against SafeDep's known malicious packages database
  • Behavioral analysis using static and dynamic analysis (performed continuously in SafeDep Cloud)
  • Human-in-the-loop triaging for high-impact findings
  • Public analysis log for transparency

Advanced Usage

# Specialized scans
vet scan --vsx --malware-query                  # VS Code extensions
vet scan -D .github/workflows --malware-query   # GitHub Actions
vet scan --image nats:2.10 --malware-query      # Container images

[!NOTE] The vet inspect malware command (on-demand analysis of a single package) is deprecated and will be removed in a future release. Use vet scan --malware-query to check packages against SafeDep's known malicious packages database.

Production Ready Integrations

GitHub Actions

Zero-config security guardrails in CI/CD:

- uses: safedep/vet-action@v1
  with:
    policy: ".github/vet/policy.yml"

See vet-action documentation.

GitLab CI

Enterprise scanning with vet CI Component:

include:
  - component: gitlab.com/safedep/ci-components/vet/scan@main

Container Integration

Run vet anywhere using our container image:

docker run --rm -v $(pwd):/app ghcr.io/safedep/vet:latest scan -D /app --malware-query

Installation

Homebrew (Recommended)

brew install safedep/tap/vet

npm

npm install @safedep/vet

Direct Download

See releases for pre-built binaries.

Go Install

go install github.com/safedep/vet@latest

Container Image

# Quick test
docker run --rm ghcr.io/safedep/vet:latest version

# Scan local directory
docker run --rm -v $(pwd):/workspace ghcr.io/safedep/vet:latest scan -D /workspace

Verify Installation

vet version
# Should display version and build information

Advanced Features

Learn more in our comprehensive documentation:

Privacy

vet collects anonymous usage telemetry to improve the product. Your code and package information is never transmitted.

# Disable telemetry (optional)
export VET_DISABLE_TELEMETRY=true

Community & Support

<div align="center">

Join the Community

Discord GitHub Discussions Twitter Follow

</div>

Get Help & Share Ideas


<div align="center">

Built With Open Source

vet stands on the shoulders of giants:

OSV • OpenSSF Scorecard • SLSA • OSV-SCALIBR • Syft

Contributors

Thank you to all contributors ❤️

<a href="https://github.com/safedep/vet/graphs/contributors"> <img src="https://contrib.rocks/image?repo=safedep/vet" alt="Contributors to vet" /> </a>
<p><strong>Secure your supply chain today. Star the repo and get started!</strong></p>

Created with love by SafeDep and the open source community

</div> <img referrerpolicy="no-referrer-when-downgrade" src="https://static.scarf.sh/a.png?x-pxid=304d1856-fcb3-4166-bfbf-b3e40d0f1e3b" />

Related MCP servers

MCP Server for TimeZest: manage appointments, pending requests, and ticket schedules in Claude.

1
TypeScript
View repository →

Affiliate API for AI agents -- browse programs, generate tracked links, record conversions.

0
JavaScript
View repository →

Real-time collaborative coding via MCP — two developers, one codebase

0
Python
MIT
View repository →

Fast domain availability checker with RDAP/WHOIS, batch checks, TLD presets, and AI-native MCP server.

301
Rust
View repository →

AI design fidelity — compare Figma designs or screenshots against rendered UI. No API keys.

0
TypeScript
MIT
View repository →

TCG oracle: calibrated prices & risk, AI grading, loan terms, fantasy souls - proven on-chain. 23 to

2
Python
View repository →