SafeDep Vet MCP
io.github.safedep/vet-mcp · 1.1k stars · Go · Apache-2.0
MCP server Protect against malicious open source packages 🤖
Install
docker run --rm -v $(pwd):/app ghcr.io/safedep/vet:latest scan -D /app --malware-queryThese repos do not share one command. When an entry shows a command, it was copied as published. Check the repo's README before you run it.
Published as
- Docker
ghcr.io/safedep/vet:v1.20.0stdio
From the server's entry in the official MCP Registry.
Files
[!NOTE]
vetalso runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform.
Why vet?
70-90% of modern software is open source code — how do you know it's safe?
Traditional SCA tools drown you in CVE noise. vet takes a different approach:
- Shadow AI discovery — Discover AI tool usage signals across various tools and configurations
- Catch malware before it ships — Zero-day detection through static and dynamic behavioral analysis (requires SafeDep Cloud access)
- Cut through vulnerability noise — Analyzes actual code usage to surface only the risks that matter
- Enforce policy as code — Express security, license, and quality requirements as CEL expressions
- CI/CD integration — Zero-config security guardrails in CI/CD
Free for open source. Hosted SaaS available at SafeDep.
Quick Start
Install in seconds:
# macOS & Linux
brew install vet
# Using npm
npm install -g @safedep/vet
or download a pre-built binary
Get started immediately:
# Scan for malware in your dependencies
vet scan -D . --malware-query
# Fail CI on critical vulnerabilities
vet scan -D . --filter 'vulns.critical.exists(p, true)' --filter-fail
Architecture
vet follows a pipeline architecture: readers ingest package manifests from diverse sources (directories, repositories, container images, SBOMs), enrichers augment each package with vulnerability, malware, and scorecard data from SafeDep Cloud, the CEL policy engine evaluates security policies against enriched data, and reporters produce actionable output in formats like SARIF, JSON, and Markdown.
graph TB
subgraph "OSS Ecosystem"
R1[npm Registry]
R2[PyPI Registry]
R3[Maven Central]
R4[Other Registries]
end
subgraph "SafeDep Cloud"
M[Continuous Monitoring]
A[Real-time Code Analysis<br/>Malware Detection]
T[Threat Intelligence DB<br/>Vulnerabilities • Malware • Scorecard]
end
subgraph "vet CLI"
S[Source Repository<br/>Scanner]
P[CEL Policy Engine]
O[Reports & Actions<br/>SARIF/JSON/CSV]
end
R1 -->|New Packages| M
R2 -->|New Packages| M
R3 -->|New Packages| M
R4 -->|New Packages| M
M -->|Behavioral Analysis| A
A -->|Malware Signals| T
S -->|Query Package Info| T
T -->|Security Intelligence| S
S -->|Analysis Results| P
P -->|Policy Decisions| O
style M fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
style A fill:#E8A87C,stroke:#B88A5A,color:#1a1a1a
style T fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
style S fill:#90C695,stroke:#6B9870,color:#1a1a1a
style P fill:#E8C47C,stroke:#B89B5A,color:#1a1a1a
style O fill:#B8A3D4,stroke:#9478AA,color:#1a1a1a
Key Features
Malicious Package Detection
Real-time protection against malicious packages powered by SafeDep Cloud. Free for open source projects. Detects zero-day malware through active code analysis.
Vulnerability Analysis
Unlike dependency scanners that flood you with noise, vet analyzes your actual code usage to prioritize real risks. See dependency usage evidence for details.
Policy as Code
Define security policies using CEL expressions to enforce context specific requirements:
# Block packages with critical CVEs
vet scan --filter 'vulns.critical.exists(p, true)' --filter-fail
# Enforce license compliance
vet scan --filter 'licenses.contains_license("GPL-3.0")' --filter-fail
# Require minimum OpenSSF Scorecard scores
vet scan --filter 'scorecard.scores.Maintained < 5' --filter-fail
Multi-Ecosystem Support
Package managers: npm, PyPI, Maven, Go, Ruby, Rust, PHP Container images: Docker, OCI SBOM formats: CycloneDX, SPDX Source repositories: GitHub, GitLab
Malicious Package Detection
Real-time protection against malicious packages by querying SafeDep's threat intelligence database, continuously populated through static and dynamic behavioral analysis.
Quick Setup
# Query known malicious packages (no API key needed)
vet scan -D . --malware-query
[!NOTE] The
--malwareflag is deprecated. Active (on-demand) scanning has been retired in favour of querying SafeDep's threat intelligence database.--malwarenow behaves identically to--malware-queryand is retained for backward compatibility.
Example detections:
- MAL-2025-3541: express-cookie-parser
- MAL-2025-4339: eslint-config-airbnb-compat
- MAL-2025-4029: ts-runtime-compat-check
Key security features:
- Real-time lookups against SafeDep's known malicious packages database
- Behavioral analysis using static and dynamic analysis (performed continuously in SafeDep Cloud)
- Human-in-the-loop triaging for high-impact findings
- Public analysis log for transparency
Advanced Usage
# Specialized scans
vet scan --vsx --malware-query # VS Code extensions
vet scan -D .github/workflows --malware-query # GitHub Actions
vet scan --image nats:2.10 --malware-query # Container images
[!NOTE] The
vet inspect malwarecommand (on-demand analysis of a single package) is deprecated and will be removed in a future release. Usevet scan --malware-queryto check packages against SafeDep's known malicious packages database.
Production Ready Integrations
GitHub Actions
Zero-config security guardrails in CI/CD:
- uses: safedep/vet-action@v1
with:
policy: ".github/vet/policy.yml"
See vet-action documentation.
GitLab CI
Enterprise scanning with vet CI Component:
include:
- component: gitlab.com/safedep/ci-components/vet/scan@main
Container Integration
Run vet anywhere using our container image:
docker run --rm -v $(pwd):/app ghcr.io/safedep/vet:latest scan -D /app --malware-query
Installation
Homebrew (Recommended)
brew install safedep/tap/vet
npm
npm install @safedep/vet
Direct Download
See releases for pre-built binaries.
Go Install
go install github.com/safedep/vet@latest
Container Image
# Quick test
docker run --rm ghcr.io/safedep/vet:latest version
# Scan local directory
docker run --rm -v $(pwd):/workspace ghcr.io/safedep/vet:latest scan -D /workspace
Verify Installation
vet version
# Should display version and build information
Advanced Features
Learn more in our comprehensive documentation:
- AI Usage Discovery - Discover AI tool usage signals across various tools and configurations
- AI Agent Mode - Run vet as an AI agent
- MCP Server - Run vet as an MCP server for AI-assisted code analysis
- Reporting - SARIF, JSON, CSV, HTML, Markdown formats
- SBOM Support - CycloneDX, SPDX import/export
- Query Mode - Scan once, analyze multiple times
Facts
- Kind
- MCP server
- Repo
- io.github.safedep/vet-mcp
- Group
- Uncategorized
- Stars
- 1.1k
- License
- Apache-2.0
- Language
- Go
- Last push
- 2026-10-07
- Forks
- 114
- MCP Registry
- io.github.safedep/vet-mcp
- Homepage
- safedep.io
- Topics
- devsecops, golang, hacktoberfest, npm, policy-as-code, pypi, rubygems, security, software-composition-analysis, static-analysis, supply-chain-security
- 1Everythingmodelcontextprotocol/serversThis MCP server attempts to exercise all the features of the MCP protocol. It is not intended to be a useful server, but rather a test server for builders of MCP clients. It implements prompts, tools, resources, sampling, and more to showcase MCP capabilities.85.8k
- 2Fetchmodelcontextprotocol/serversA Model Context Protocol server that provides web content fetching capabilities. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption.85.8k
- 3Gitmodelcontextprotocol/serversA Model Context Protocol server for Git repository interaction and automation. This server provides tools to read, search, and manipulate Git repositories via Large Language Models.85.8k
- 4Memorymodelcontextprotocol/serversA basic implementation of persistent memory using a local knowledge graph. This lets Claude remember information about the user across chats.85.8k
- 5Sequential Thinkingmodelcontextprotocol/serversAn MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.85.8k
- 6Timemodelcontextprotocol/serversA Model Context Protocol server that provides time and timezone conversion capabilities. This server enables LLMs to get current time information and perform timezone conversions using IANA timezone names, with automatic system timezone detection.85.8k