Getting Started with DepCheck
📄 Prefer offline? Download this guide as a PDF.
DepCheck is a hosted MCP server. You connect your AI client to it once, and from then on the client's agent can call the dependency-check tools whenever it needs them.
There are two ways to run it:
- Hosted (recommended) — connect to
https://mcp.cert-ix.com/depcheckover the network. Nothing to install; always up to date. - Local (stdio) — run the
vuln-mcpbinary next to your agent, so it can read manifests straight off disk. Local does not mean offline: it still looks advisories up over the network.
Prerequisites
- An MCP-capable client: Claude Code, Claude Desktop, Cursor, VS Code (with an MCP extension), or any client that speaks streamable-HTTP MCP.
- A DepCheck API key — free, self-service, no Cert-IX account required.
Request one at cert-ix.com/tools/depcheck-mcp:
confirm your email address and the key arrives by email. A key lasts 90 days;
before it expires you receive an email with a one-click renewal link, and the
same key keeps working. It is sent as a
Bearertoken on every request, so treat it like a password — see Security & data handling.
The hosted endpoint requires an API key. Requests without a valid
Authorization: Bearer <key> header are rejected with 401.
Option 1 — Hosted endpoint
Claude Code (CLI)
Add the server with the claude mcp command:
claude mcp add --transport http depcheck https://mcp.cert-ix.com/depcheck \
--header "Authorization: Bearer YOUR_API_KEY"
Verify it registered and the tools are visible:
claude mcp list
You should see depcheck with five tools: check_package,
scan_dependencies, suggest_safe_version, get_advisory, and
get_cve_intel.
Claude Desktop / Cursor / generic MCP client
Add an entry to your client's MCP configuration. Most clients accept a streamable-HTTP server block like this:
{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
Restart the client after saving. The exact file location varies by client
(Claude Desktop uses claude_desktop_config.json; Cursor uses its MCP settings
panel) — the server block above is the part that matters.
Sanity check with curl
The endpoint is a standard MCP server, so you can confirm reachability and auth
with a raw initialize call:
curl -sS https://mcp.cert-ix.com/depcheck \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize",
"params":{"protocolVersion":"2025-06-18",
"capabilities":{},
"clientInfo":{"name":"curl","version":"1.0"}}}'
A 200 with a JSON-RPC result means auth and connectivity are good. A 401
means the key is missing or wrong; a 429 means you have hit the rate limit
(see Security & data handling).
Option 2 — Local (stdio)
When you want the agent to read manifests straight off disk, run the server
locally over stdio. In this mode scan_dependencies accepts a file path
(manifest_path) in addition to inline content.
{
"mcpServers": {
"depcheck": {
"command": "vuln-mcp"
}
}
}
Local does not mean offline. Configured like this, the server looks advisories up
in the public osv.dev API, and suggest_safe_version reads version lists from
deps.dev; both receive package coordinates — see
Security & data handling.
- Manifests. The hosted server has no access to your filesystem, so its
scan_dependenciestool takes the manifest text (manifest_content+manifest_name) — your agent reads the file and passes the contents. The local stdio server also accepts amanifest_path. - Advisory source. The hosted server answers from Cert-IX's advisory mirror
first and offers
get_cve_intel, which needs the mirror's KEV / EPSS data. A local instance without mirror access queries osv.dev directly and exposes the other four tools.
First call
Once connected, ask your agent something like:
"Before we add it, is
[email protected]safe? If not, what's the newest clean version?"
The agent will call check_package(ecosystem="npm", name="express", version="4.17.1") and, if there are advisories, suggest_safe_version — and
tell you which version to use. That is the whole point: the check happens
before the dependency lands in your manifest.
Continue to the Tools reference for the full parameter set of each tool, or Agent workflows for the check-before-you-add discipline.
War diese Seite hilfreich?