Socket Security
Socket MCP server provides AI assistants with access to Socket's dependency security and quality scoring API for analyzing package ecosystems including npm and PyPI. Built by Socket Inc using TypeScript with comprehensive transport support (stdio, HTTP with SSE), the implementation offers a single depscore tool that accepts arrays of packages with ecosystem, name, and version parameters, returning detailed security and quality metrics from Socket's vulnerability database. The server includes robust error handling, API key authentication, configurable endpoints for local development, extensive logging with pino, and Docker containerization support, making it valuable for developers integrating dependency analysis into AI workflows, security teams performing automated package audits, and development environments where conversational access to package risk assessment enhances code review and dependency management decisions.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Repository
- github.com/socketdev/socket-mcp
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve Socket Security from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.