DepScout
Check npm, PyPI, Go, Maven, crates.io and NuGet packages for known vulnerabilities and malware, find the minimum safe version, and audit pinned dependency lists, using OSV.dev and deps.dev.
- Brand
- Unknown
- Category
- Pending
- Primary Subcategory
- Pending
Integration details
Description
DepScout checks open-source packages against live vulnerability and malware data, so answers about whether a package is safe, and which version to use, come from current advisories instead of model memory. What it does: - Checks one package (npm, PyPI, Go, Maven, crates.io or NuGet) at a given version or its latest release. It flags malicious packages and compromised releases first, then lists known vulnerabilities with severity, CVE IDs and the version that fixes each one, plus the minimum version that clears them all. - Reports the latest stable version, whether a version is outdated or deprecated, the last release date, licences, and the source repository's OpenSSF Scorecard. - Checks up to 50 pinned dependencies at once (for example from package.json, requirements.txt, go.mod or pom.xml) and returns only the ones with problems, with an upgrade target for each. - Explains a single advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC or MAL): severity, affected and fixed version ranges, and references. Who it's for: developers using Claude, Claude Code or other AI assistants who want to vet a dependency before installing it, triage an audit, or pick a safe version. Limitations: data comes from OSV.dev and deps.dev. A clean result means no known advisory for that exact version, not a guarantee of safety, and newly published malware may not be listed yet. Only the packages you list are checked, not their transitive dependencies. Version ranges are checked at the version written in them. DepScout is read-only and is not affiliated with OSV.dev, deps.dev, Google, the OpenSSF, GitHub or any package registry.
- Integration type
- Connector
- Verification status
Community connector- Platform
- Claude
- Category
- Pending
- Primary Subcategory
- Pending
- Secondary Subcategories
- None listed
- Brand
- Unknown
- Access
- No account required
- First tracked
- 2026-10-02
- Tool count
- 3
- Geography
- US
The broad Category that contains the Primary Subcategory.
The Primary Subcategory used for this profile’s headline score.
Other Subcategories where the Integration is listed.
Claude Connector discovery is coming soon
Community Connectors only appear in Claude’s registry.Once verified, organic discovery begins and we can calculate your score.Read more about Community Connector verification.
No spam. Unsubscribe any time.
No spam. Unsubscribe any time.
What discovery looks like

Claude can surface verified Connectors when they match a user’s Prompt.
How Claude Connector discovery works
Your Connector will compete to appear for users’ Prompts once Claude verifies it
Competitive lineup
3 tools agents can invoke
How do I improve a Community connector's discoverability?
The levers are the listing surface agents actually read: names, descriptions, keywords, tool metadata, and registry health. Which lever matters depends on where discovery breaks, which is what continuous measurement shows.
Where is this profile measured?
This profile uses the geography attached to the latest public registry snapshot: US. Locale tags are intentionally omitted.