deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, Rub...
Copy the install, test the workflow, then decide if it earns a permanent slot.
Fresh repo activity plus visible builder pull. This is the kind of tool people test before it turns obvious.
Copy the install, test the workflow, then decide if it earns a permanent slot.
You can test this quickly and remove it cleanly if it misses.
GitHub health 37/100. no security policy. 0 open issues make this testable, but not something to trust blind.
AI Agent
Universal
Model
Multiple
Fastest way to find out if deptrust belongs in your setup.
Copy the install command, run a real test, and back it out cleanly if it slows you down.
claude mcp add deptrust -- npx deptrustRun this first. You will know quickly if the workflow earns a permanent slot.
claude mcp remove deptrustNo messy cleanup loop. If it misses, remove it and keep moving.
Install Location
~/ └─ .claude.json └─ mcp_servers/ └─ deptrust ← registers here
deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server, comes with a skill, and a hook.
Source: GitHub repository
Source check: July 23, 2026
Upstream commit: July 23, 2026
Repository state: Not marked archived
Honeystax upvotes are community interest signals, not star ratings. GitHub stars and repository health are source measurements; editorial risk and trial-cost notes are Honeystax analysis.