Protect your AI agents and IDEs from malicious open-source packages.
io.github.safedep/vet-mcp (MCP) Server
This Model Context Protocol (MCP) server, io.github.safedep/vet-mcp, is described as protecting AI agents and IDEs from malicious open-source packages. It is associated with software supply chain security, including software composition analysis and static-analysis across ecosystems such as Go (Golang), npm, PyPI, and RubyGems.
🛠️ Key Features
Malicious open-source package detection (implied by the provided description)
Software supply chain security and software composition analysis
Policy-as-code and static-analysis
🚀 Use Cases
Securing AI agents from malicious packages
Securing IDE workflows against untrusted dependencies
Analysis across Golang, npm, PyPI, and Rubygems packages
⚡ Developer Benefits
Support for software composition analysis workflows
Focus on devsecops, security, and supply-chain-security contexts
Topics align with policy-as-code and static-analysis practices
⚠️ Limitations
Provided source material does not include tool count, specific MCP tools, or detailed operational behavior beyond the high-level purpose.
vet also runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform.
Why vet?
70-90% of modern software is open source code — how do you know it's safe?
Traditional SCA tools drown you in CVE noise. vet takes a different approach:
Shadow AI discovery — Discover AI tool usage signals across various tools and configurations
Catch malware before it ships — Zero-day detection through static and dynamic behavioral analysis (requires SafeDep Cloud access)
Cut through vulnerability noise — Analyzes actual code usage to surface only the risks that matter
Enforce policy as code — Express security, license, and quality requirements as CEL expressions
CI/CD integration — Zero-config security guardrails in CI/CD
Free for open source. Hosted SaaS available at SafeDep.
Quick Start
Install in seconds:
bash
# macOS & Linux
brew install vet
# Using npm
npm install -g @safedep/vet
# Scan for malware in your dependencies
vet scan -D . --malware-query
# Fail CI on critical vulnerabilities
vet scan -D . --filter 'vulns.critical.exists(p, true)' --filter-fail
Architecture
vet follows a pipeline architecture: readers ingest package manifests from diverse sources (directories, repositories, container images, SBOMs), enrichers augment each package with vulnerability, malware, and scorecard data from SafeDep Cloud, the CEL policy engine evaluates security policies against enriched data, and reporters produce actionable output in formats like SARIF, JSON, and Markdown.
View architecture diagram
graph TB
subgraph "OSS Ecosystem"
R1[npm Registry]
R2[PyPI Registry]
R3[Maven Central]
R4[Other Registries]
end
subgraph "SafeDep Cloud"
M[Continuous Monitoring]
A[Real-time Code Analysis<br/>Malware Detection]
T[Threat Intelligence DB<br/>Vulnerabilities • Malware • Scorecard]
end
subgraph "vet CLI"
S[Source Repository<br/>Scanner]
P[CEL Policy Engine]
O[Reports & Actions<br/>SARIF/JSON/CSV]
end
R1 -->|New Packages| M
R2 -->|New Packages| M
R3 -->|New Packages| M
R4 -->|New Packages| M
M -->|Behavioral Analysis| A
A -->|Malware Signals| T
S -->|Query Package Info| T
T -->|Security Intelligence| S
S -->|Analysis Results| P
P -->|Policy Decisions| O
style M fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
style A fill:#E8A87C,stroke:#B88A5A,color:#1a1a1a
style T fill:#7CB9E8,stroke:#5A8DB8,color:#1a1a1a
style S fill:#90C695,stroke:#6B9870,color:#1a1a1a
style P fill:#E8C47C,stroke:#B89B5A,color:#1a1a1a
style O fill:#B8A3D4,stroke:#9478AA,color:#1a1a1a
Key Features
Malicious Package Detection
Real-time protection against malicious packages powered by SafeDep Cloud.
Free for open source projects. Detects zero-day malware through active code analysis.
Vulnerability Analysis
Unlike dependency scanners that flood you with noise, vet analyzes your actual code usage to prioritize real risks.
See dependency usage evidence for details.
Policy as Code
Define security policies using CEL expressions to enforce context specific requirements:
bash
# Block packages with critical CVEs
vet scan --filter 'vulns.critical.exists(p, true)' --filter-fail
# Enforce license compliance
vet scan --filter 'licenses.contains_license("GPL-3.0")' --filter-fail
# Require minimum OpenSSF Scorecard scores
vet scan --filter 'scorecard.scores.Maintained < 5' --filter-fail
Real-time protection against malicious packages by querying SafeDep's threat intelligence
database, continuously populated through static and dynamic behavioral analysis.
Quick Setup
bash
# Query known malicious packages (no API key needed)
vet scan -D . --malware-query
NOTE
The --malware flag is deprecated. Active (on-demand) scanning has been retired in favour of
querying SafeDep's threat intelligence database. --malware now behaves identically to
--malware-query and is retained for backward compatibility.
# Specialized scans
vet scan --vsx --malware-query # VS Code extensions
vet scan -D .github/workflows --malware-query # GitHub Actions
vet scan --image nats:2.10 --malware-query # Container images
NOTE
The vet inspect malware command (on-demand analysis of a single package) is deprecated and
will be removed in a future release. Use vet scan --malware-query to check packages against
SafeDep's known malicious packages database.
# Quick test
docker run --rm ghcr.io/safedep/vet:latest version
# Scan local directory
docker run --rm -v $(pwd):/workspace ghcr.io/safedep/vet:latest scan -D /workspace
Verify Installation
bash
vet version
# Should display version and build information
Advanced Features
Learn more in our comprehensive documentation:
AI Usage Discovery - Discover AI tool usage signals across various tools and configurations