Developer Tools · Security

Socket MCP

socketdev/socket-mcp

Socket MCP server is a Model Context Protocol service for dependency security scanning, providing security scores and vulnerability detection for package ecosystems such as npm and PyPI, supporting AI assistant integration and multiple deployment methods.

Install

Client configuration

{
  "mcpServers": {
    "socket-mcp": {
      "url": "https://mcp.socket.dev/"
    }
  }
}

Environment variables

SOCKET_API_TOKENSOCKET_OAUTH_INTROSPECTION_CLIENT_IDSOCKET_OAUTH_INTROSPECTION_CLIENT_SECRET
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

About Socket MCP

Socket MCP lets AI assistants query Socket's dependency security scores and metadata through the Model Context Protocol (MCP). Use it to score a package, audit a package.json, or identify risky dependencies in a conversation. Connect your MCP client to the hosted server at https://mcp.socket.dev/, or run the npm package yourself.

Features

  • Dependency Security Scanning - Get comprehensive security scores for npm, PyPI, cargo, Maven, NuGet, RubyGems, Go Modules, and more (supported ecosystems)

  • Public Hosted Service - Use our public server at https://mcp.socket.dev/; sign in once via OAuth, no self-hosting

  • Multiple Deployment Options - Run locally via stdio, HTTP, or use our service

  • AI Assistant Integration - Works seamlessly with Claude, VS Code Copilot, Cursor, and other MCP clients

  • Batch Processing - Check multiple dependencies in a single request

  • OAuth Sign-In - Public server authenticates through your MCP client's OAuth flow; no API key to copy or manage

Tools (15)

  • packages

    Array of package objects to analyze

  • platform

    OS-architecture hint (linux-x64, darwin-arm64, win32-x64) applied to every package in the request.

  • org_slug

    Organization slug (get it from the organizations tool)

  • severity

    Comma-separated subset of low,medium,high,critical

  • category

    Comma-separated subset of supplyChainRisk,maintenance,quality,license,vulnerability

  • artifact_type

    Comma-separated ecosystems: npm,pypi,gem,maven,golang,nuget,cargo,chrome,openvsx

  • artifact_name

    Restrict to a single package name

  • alert_type

    Comma-separated Socket alert types (e.g. usesEval,unmaintained)

  • repo_slug

    Comma-separated repository slugs

  • per_page

    Results per page (1–5000)

  • cursor

    Pagination cursor - the endCursor from a previous response

  • threat_feed

    Look up items in a Socket organization's threat feed: packages recently flagged as malware, typosquats, obfuscated code, and similar.

  • package_files

    List the files published in a package: a tree of file paths, each with its size and blob hash, for any package on a supported ecosystem.

  • package_file_contents

    Read a single file from a package.

  • package_file_grep

    Search a single file from a package for lines matching a JavaScript regular expression, returning matches with line numbers (grep -n style).

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux
Windsurf logo

Windsurf

Desktop · Freemium · Proprietary

The first agentic IDE. The Windsurf editor truly merges how developers and AI work together.

WindowsMacOSLinux
VS Code GitHub Copilot logo

VS Code GitHub Copilot

Desktop · Freemium · MIT

VS Code integrates MCP with GitHub Copilot through agent mode, allowing direct interaction with MCP-provided tools in your agentic coding workflow. Configure servers in Claude Desktop, workspace, or user settings, with guided MCP installation and secure handling of secrets in input variables to avoid leaking hardcoded keys.

WindowsMacOSLinuxWeb

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools