@guardbee/mcp-dependency-auditor
π¬π§ English | πΉπ· TΓΌrkΓ§e

An MCP server that audits npm and pip manifests against the OSV database for known CVEs. A single-package lookup also covers PyPI, crates.io, Maven, Go, and RubyGems.
This package sends usage telemetry by default (tool name + short parameters β see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.
Features
- OSV API Integration β Google's open-source vulnerability database (free, no authentication required)
- npm Support β reads
package.json and package-lock.json (v1/v2/v3); locked versions preferred
- pip Support β
requirements.txt, requirements/base.txt, requirements/prod.txt, and pyproject.toml
- Severity Scoring β Critical / High / Medium / Low based on CVSS score or a text heuristic
- Fix Version β an
upgrade to X@Y.Z.Z recommendation when available
- CVE Links β direct links to NVD or osv.dev
- 24 Unit Tests β 100% passing test suite
Quick Start
npm install -g @guardbee/mcp-dependency-auditor
Add to claude_desktop_config.json:
{
"mcpServers": {
"guardbee-dependency-auditor": {
"command": "npx",
"args": ["-y", "@guardbee/mcp-dependency-auditor"]
}
}
}
| Tool | Description |
|---|
audit_npm | Audits npm dependencies in package.json / package-lock.json |
audit_pip | Audits Python dependencies in requirements.txt / pyproject.toml |
audit_package | Audits a single package by name, version, and ecosystem |
audit_directory | Auto-detects and audits all supported manifest files |
Example Usage
You can ask Claude:
"Audit my project's npm dependencies: /Users/me/my-app"
"Is there a CVE for lodash 4.17.20?"
"Scan my Python project: /Users/me/django-app"
Example Output
β οΈ Found 3 vulnerabilities in 2/142 npm packages (1243ms)
Critical: 1 High: 1 Medium: 1 Low: 0 Unknown: 0
[CRITICAL] lodash@4.17.20
ID : GHSA-35jh-r3h4-6jhm (CVE-2021-23337)
Summary : Command injection via template
Fix : upgrade to lodash@4.17.21
Details : https://nvd.nist.gov/vuln/detail/CVE-2021-23337
Supported Ecosystems
The audit_package tool can query these ecosystems directly:
| Ecosystem | Parameter |
|---|
| npm | npm |
| Python | PyPI |
| Rust | crates.io |
| Java | Maven |
| Go | Go |
| Ruby | RubyGems |
CLI β CI/CD Integration
In addition to MCP server mode, this can also be used directly as a CLI:
npx @guardbee/mcp-dependency-auditor audit ./my-project
npx @guardbee/mcp-dependency-auditor audit-npm . --fail-on=critical
npx @guardbee/mcp-dependency-auditor audit-pip . --fail-on=high
npx @guardbee/mcp-dependency-auditor audit-pkg lodash 4.17.20 npm
npx @guardbee/mcp-dependency-auditor audit . --format=json
Exit codes: 0 = clean Β· 1 = findings above threshold Β· 2 = error
GitHub Actions
name: Dependency Audit
on: [push, pull_request]
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
- run: npm ci
- name: Audit dependencies
run: npx @guardbee/mcp-dependency-auditor audit . --fail-on=high
GitLab CI
dependency-audit:
image: node:20
script:
- npx @guardbee/mcp-dependency-auditor audit . --fail-on=high
only:
- merge_requests
- main
Pre-commit Hook
npx @guardbee/mcp-dependency-auditor audit . --fail-on=critical || exit 1
Development
npm install
npm test
npm run build
License
MIT β GuardBee