Hound
Hound is a supply chain security tool that gives coding agents comprehensive dependency analysis capabilities. It scans packages for known vulnerabilities via OSV, checks license compliance, inspects full dependency trees, and detects potential typosquatting attacks. The server uses only free, unauthenticated public APIs (Google's deps.dev and OSV) requiring no API keys or configuration. It provides 12 specialized tools including project-wide lockfile audits, security scoring, upgrade recommendations, package comparisons, and pre-installation safety checks across npm, PyPI, Go, Maven, Cargo, NuGet, and RubyGems ecosystems.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-19.
Scan details: Circle-IR · 2026-09-19 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- security
- Source
- PulseMCP
- Repository
- github.com/tiluckdave/hound-mcp
- Author type
- human
- Last scanned
- 2026-09-19
- Updated
- 2026-09-19
Use via MCP
Resolve Hound from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.