Dep MCP Server

Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis.

Local serverstdioPython

What is the Dep MCP server?

If you already use Dep, the dep mcp server is the piece that lets your assistant work with it directly. Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis.

What the server does

  • Supply chain attacks increased 742% since 2019 (Sonatype 2024 Report)
  • The average npm project pulls in hundreds of transitive dependencies — any one could be compromised
  • npm audit only catches known CVEs — dep-oracle predicts future risks
  • You audit your code. But do you audit your trust?

Credentials and setup notes

Configuration is passed through the environment: GITHUB_TOKEN. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

Installation

Installation goes through your MCP client rather than a global install: point it at dep-oracle on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

Where it fits

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. It is maintained by ertugrulakben; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

How to install the Dep MCP server

{
  "mcpServers": {
    "dep-oracle": {
      "command": "npx",
      "args": ["-y", "dep-oracle"],
      "env": {
        "GITHUB_TOKEN": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

VariableDescriptionRequired
GITHUB_TOKENCredential the server authenticates with.Yes

Frequently asked questions

It connects Dep to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Dep directly.