Socket Security
Integrates with Socket's dependency security API to analyze npm and PyPI packages, returning detailed security and quality metrics
Socket MCP server provides AI assistants with access to Socket's dependency security and quality scoring API for analyzing package ecosystems including npm and PyPI. Built by Socket Inc using TypeScript with comprehensive transport support (stdio, HTTP with SSE), the implementation offers a single depscore tool that accepts arrays of packages with ecosystem, name, and version parameters, returning detailed security and quality metrics from Socket's vulnerability database. The server includes robust error handling, API key authentication, configurable endpoints for local development, extensive logging with pino, and Docker containerization support, making it valuable for developers integrating dependency analysis into AI workflows, security teams performing automated package audits, and development environments where conversational access to package risk assessment enhances code review and dependency management decisions.
Source
Repository: https://github.com/socketdev/socket-mcp
Maintain Socket Security?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[](https://getagentictools.com/mcp/socketdev-socket-mcp?ref=badge)