# Hound

> Use this tool when you need to analyze and secure your software supply chain by identifying vulnerabilities, ensuring license compliance, and detecting potential attacks in your dependencies. Hound scans packages and provides comprehensive insights, including security scoring and upgrade recommendations, across multiple ecosystems such as npm, PyPI, and Go. It offers a range of specialized tools and interfaces, including project-wide lockfile audits and pre-installation safety checks, to help you make informed decisions about your dependencies.

Canonical page: https://skillsregistry.net/skills/gh-tiluckdave-hound  
JSON: https://api.skillsregistry.net/v1/skills/gh-tiluckdave-hound

## Description

Hound is a supply chain security tool that gives coding agents comprehensive dependency analysis capabilities. It scans packages for known vulnerabilities via OSV, checks license compliance, inspects full dependency trees, and detects potential typosquatting attacks. The server uses only free, unauthenticated public APIs (Google's deps.dev and OSV) requiring no API keys or configuration. It provides 12 specialized tools including project-wide lockfile audits, security scoring, upgrade recommendations, package comparisons, and pre-installation safety checks across npm, PyPI, Go, Maven, Cargo, NuGet, and RubyGems ecosystems.

## Trust

- **Trust score (0–1):** 0.96
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/gh-tiluckdave-hound)
- **Repository:** <https://github.com/tiluckdave/hound-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "gh-tiluckdave-hound"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/gh-tiluckdave-hound` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/gh-tiluckdave-hound/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
