Security#Security scan

vet MCP: check packages for malware before agents install

SafeDep's open source vet ships an MCP server that checks npm and PyPI packages an agent suggests for malware reports, CVEs, licenses and real versions.

Project and installation docs

View project

https://github.com/safedep/vet

When a coding agent says to install some package, that package may not exist, or it may be malware registered under a name models tend to hallucinate, an attack known as slopsquatting. vet is SafeDep’s open source dependency security tool, and its built-in MCP server lets the agent check first: is there a malware report for this package, what vulnerabilities affect this version, what’s the license, what’s the latest release. vet had about 1.1k stars as of 2026-10-06.

What it does

  • Malware lookups: get_package_version_malware_report queries SafeDep’s continuously updated threat intelligence; lookups are free and need no API key.
  • Vulnerabilities and licenses: get_package_version_vulnerabilities lists known CVEs and get_package_version_license_info returns license details.
  • Catching hallucinated names: get_package_latest_version and get_package_available_versions check versions. No latest version usually means the name is wrong.
  • Popularity: get_package_version_popularity helps judge whether a package is widely used.
  • SQL over scan results: vet_query_execute_sql_query queries vet’s scan data with SQL.

Who it’s for

  • Developers who let Claude Code or Cursor install dependencies and worry about pulling in something malicious.
  • Security teams adding a supply chain check to AI-assisted development.

Setup

Use the official Docker image; for Claude Code, add this to the project’s .mcp.json:

{
  "mcpServers": {
    "vet-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/safedep/vet:latest",
        "server",
        "mcp"
      ]
    }
  }
}

Or brew install vet and run the binary: vet -l /tmp/vet-mcp.log server mcp --server-type stdio. Keep logs off stdout, or they’ll corrupt the MCP stream.

Our take

vet aims at a risk specific to AI coding: the package name the agent recommends may be invented. The docs include a sample Cursor rule telling the agent to check every package with vet before installing, and that rule-plus-tool pairing is more dependable than the tool alone. The limits: the MCP server covers only npm and PyPI today, malware detection relies on SafeDep’s cloud intelligence so package names are sent to SafeDep, and the Docker image needs regular updates. SafeDep also runs a hosted MCP server with lower latency. Licensed Apache-2.0.