vet MCP: check packages for malware before agents install
SafeDep's open source vet ships an MCP server that checks npm and PyPI packages an agent suggests for malware reports, CVEs, licenses and real versions.
Project and installation docs
View projecthttps://github.com/safedep/vet
When a coding agent says to install some package, that package may not exist, or it may be malware registered under a name models tend to hallucinate, an attack known as slopsquatting. vet is SafeDep’s open source dependency security tool, and its built-in MCP server lets the agent check first: is there a malware report for this package, what vulnerabilities affect this version, what’s the license, what’s the latest release. vet had about 1.1k stars as of 2026-10-06.
What it does
- Malware lookups:
get_package_version_malware_reportqueries SafeDep’s continuously updated threat intelligence; lookups are free and need no API key. - Vulnerabilities and licenses:
get_package_version_vulnerabilitieslists known CVEs andget_package_version_license_inforeturns license details. - Catching hallucinated names:
get_package_latest_versionandget_package_available_versionscheck versions. No latest version usually means the name is wrong. - Popularity:
get_package_version_popularityhelps judge whether a package is widely used. - SQL over scan results:
vet_query_execute_sql_queryqueries vet’s scan data with SQL.
Who it’s for
- Developers who let Claude Code or Cursor install dependencies and worry about pulling in something malicious.
- Security teams adding a supply chain check to AI-assisted development.
Setup
Use the official Docker image; for Claude Code, add this to the project’s .mcp.json:
{
"mcpServers": {
"vet-mcp": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"ghcr.io/safedep/vet:latest",
"server",
"mcp"
]
}
}
}
Or brew install vet and run the binary: vet -l /tmp/vet-mcp.log server mcp --server-type stdio. Keep logs off stdout, or they’ll corrupt the MCP stream.
Our take
vet aims at a risk specific to AI coding: the package name the agent recommends may be invented. The docs include a sample Cursor rule telling the agent to check every package with vet before installing, and that rule-plus-tool pairing is more dependable than the tool alone. The limits: the MCP server covers only npm and PyPI today, malware detection relies on SafeDep’s cloud intelligence so package names are sent to SafeDep, and the Docker image needs regular updates. SafeDep also runs a hosted MCP server with lower latency. Licensed Apache-2.0.