Skip to content
appsgit

SafeDep Vet MCP

SafeDep Vet MCP is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Protect your AI agents and IDEs from malicious open-source packages. It has 1,110 GitHub stars, is released under the Apache-2.0 license and runs locally with docker run -i --rm ghcr.io/safedep/vet:v1.19.1.

github.com/safedep/vet (opens in a new tab)

Install SafeDep Vet MCP

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "safedep-vet-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/safedep/vet:v1.19.1"
      ]
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --transport stdio safedep-vet-mcp -- docker run -i --rm ghcr.io/safedep/vet:v1.19.1

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "safedep-vet-mcp": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/safedep/vet:v1.19.1"
      ]
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "servers": {
    "safedep-vet-mcp": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/safedep/vet:v1.19.1"
      ]
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

About SafeDep Vet MCP

70-90% of modern software is open source code — how do you know it's safe? Traditional SCA tools drown you in CVE noise. vet takes a different approach:

  • devsecops
  • security
  • supply-chain-security
  • policy-as-code
  • software-composition-analysis
  • golang
  • npm
  • pypi
  • rubygems
  • static-analysis

FAQ

SafeDep Vet MCP FAQ

Still curious? Email info@appsgit.com.

What is SafeDep Vet MCP?

SafeDep Vet MCP is an MCP server that adds developer tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Protect your AI agents and IDEs from malicious open-source packages. It has 1,110 GitHub stars, is released under the Apache-2.0 license and runs locally with docker run -i --rm ghcr.io/safedep/vet:v1.19.1. The source code is at github.com/safedep/vet.

How do I install the SafeDep Vet MCP MCP server?

Add the command docker run -i --rm ghcr.io/safedep/vet:v1.19.1 to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is SafeDep Vet MCP free?

The server is open source under the Apache-2.0 license, so running it is free. It does not declare any required API key.

Is SafeDep Vet MCP actively maintained?

The most recent commit was on Oct 6, 2026. The latest release is v1.20.0, published Oct 7, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.