MCP server that stops AI coding agents from installing vulnerable packages. Checks any package against OSV.dev, or scans an entire lockfile (npm, PyPI, Cargo, Go & more) in one call — with severity thresholds, banned packages and triaged-CVE waivers.
1
Users / 90d
1
Runs / 30d
—
Rating