Back to Browse

Dep Tools MCP Server

by Rog0x
Developer ToolsLow Risk8.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

License check, outdated deps, security for AI agents

About

License check, outdated deps, security for AI agents

Security Report

8.0
Low Risk8.0Low Risk

Valid MCP server (2 strong, 4 medium validity signals). 2 known CVEs in dependencies (0 critical, 2 high severity) Package registry verified. Imported from the Official MCP Registry.

8 files analyzed · 3 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-rog0x-dep": {
      "args": [
        "-y",
        "@rog0x/mcp-dep-tools"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

mcp-dep-tools

MCP server providing dependency and package management tools for AI agents. Analyze licenses, find outdated packages, visualize dependency trees, estimate bundle sizes, and audit security vulnerabilities — all from your AI assistant.

Tools

dep_check_licenses

Analyze licenses of all dependencies in a project. Lists each dependency's license type, flags copyleft (GPL) and unknown licenses, and checks for compatibility issues.

dep_find_outdated

Check which dependencies are outdated. Compares installed or specified versions against the latest on npm, categorizes updates as major/minor/patch, and shows how many days since the latest version was published.

dep_analyze_tree

Build and display the dependency tree. Shows direct dependencies and their transitive sub-dependencies, calculates maximum depth, detects circular dependencies, and counts total transitive packages.

dep_analyze_size

Estimate total bundle size from package.json without installing node_modules. Queries the Bundlephobia API for each production dependency to get minified and gzipped sizes.

dep_security_audit

Check dependencies for known security vulnerabilities. Runs npm audit when a lockfile is present, otherwise queries the npm registry advisory API directly. Reports severity levels, affected version ranges, and fix recommendations.

Setup

npm install
npm run build

Usage with Claude Desktop

Add to your Claude Desktop config:

{
  "mcpServers": {
    "dep-tools": {
      "command": "node",
      "args": ["path/to/mcp-dep-tools/dist/index.js"]
    }
  }
}

All tools accept a single parameter

  • project_dir (string, required): Absolute path to the project directory containing a package.json.

License

MIT

Reviews

No reviews yet

Be the first to review this server!

Dep Tools MCP Server - License check, outdated deps, security for AI agents | MCP Marketplace