SafeDep

Created By
SafeDep4 months ago
SafeDep MCP Server protects AI coding agents from supply chain attacks by checking every open source package before installation. When your AI suggests a package, SafeDep validates it against our threat intelligence database, built from continuous scanning, behavioral analysis, and human security researcher verification. Malicious packages are blocked instantly. Safe packages install without friction. We detect threats in hours, not the 24-48 hours it takes for public disclosure. Same intelligence that caught Shai-Hulud and S1ngularity.
Overview

SafeDep MCP Server

SafeDep MCP Server protect AI coding workflows from supply chain attacks. Every npm, PyPI, and open source package is checked against real-time threat intelligence before installation.

The problem: AI coding tools install packages without the scrutiny a human would apply. One malicious package can steal AWS keys, GitHub tokens, and API secrets from the environment.

The solution: SafeDep validates every package that the AI suggests with the agent loop before installation. Malicious packages are blocked with clear explanations. Safe packages install invisibly. Zero friction when there's no threat.

Key Features

  • Real-time detection — SafeDep scan packages as they're published to public open source registries, detecting threats in hours, not days
  • Zero friction — Invisible when packages are safe.
  • Broad ecosystem coverage — npm, PyPI, and expanding to more registries

Supported Tools

  • Claude Code
  • Cursor
  • Windsurf
  • Zed
  • Gemini CLI
  • OpenAI Codex
  • Any MCP-compatible IDE

Getting Started

  1. Sign up at app.safedep.io
  2. Get your API key from Settings → API Keys
  3. Configure your IDE with the MCP endpoint

Endpoint: https://mcp.safedep.io/model-context-protocol/threats/v1/mcp

Full setup instructions: docs.safedep.io/apps/mcp/overview

Server Config

{
  "mcpServers": {
    "safedep": {
      "url": "https://mcp.safedep.io/model-context-protocol/threats/v1/mcp",
      "headers": {
        "Authorization": "",
        "X-Tenant-ID": ""
      }
    }
  }
}
Project Info
Created At
4 months ago
Updated At
4 months ago
Author Name
SafeDep
Star
-
Language
-
License
-
Category

Recommend Servers

View All
Bring your real authenticated browser session to AI coding agents. Local-first MCP server + Chrome MV3 extension. No cloud. No telemetry.
@Cubenest

peek records the user's actual logged-in browser (DOM via rrweb, console events, network metadata, optional response bodies via opt-in Deep capture) through a Chrome MV3 extension. The extension ships events through a native-messaging stdio bridge to a local MCP server (peek-mcp), which persists them to a SQLite database at ~/.peek/sessions.db. AI coding agents (Claude Code, Cursor, Cline, Windsurf) read sessions from the database via 10 MCP tools: Tool What it does list_recent_sessions List recently recorded sessions (id, origin, ts, event count). get_session_summary LLM-readable narrative summary of a session. get_session_console_errors Console errors recorded in a session. get_session_network_errors Failed/notable network requests in a session. get_user_action_before_error Last N user actions before a console error. generate_playwright_repro Generate a runnable Playwright test from a session. get_dom_snapshot Reconstruct the DOM at a given timestamp. query_dom_history Timeline of attribute/text changes for a selector. request_authorization Side-panel consent for write actions (Level 3). execute_action Dispatch a UI action (gated by permission level + destructive blocklist). Why local-first matters Every other "browser session for AI" tool ships to a vendor cloud. peek's SQLite + extension live on the user's machine — no remote endpoints, no telemetry. The privacy policy (docs/peek/PRIVACY_POLICY.md) is the source of truth. Install # 1. Add the MCP server to Claude Code claude mcp add peek -- npx -y @peekdev/mcp # 2. Install the Chrome extension from the Chrome Web Store # (link added once the CWS listing is approved)

a day ago