Socket MCP
未认领Model Context Protocol server for socket.dev integration
安装
claude mcp add --transport http socket-mcp https://mcp.socket.dev/更多AI & ML服务器
浏览完整目录安全概况
已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理
7 个工具中显示 7 个
文档中列出的工具 (7)
内容来自项目文档。服务器握手不会验证每个工具的说明或行为。
alerts
List the latest security alerts for one Socket organization: supply-chain, vulnerability, quality, license, and maintenance issues across the org's monitored packages. Backed by GET /v0/orgs/{orgslug}/alerts. Results are paginated; pass the previous response's endCursor as cursor to fetch the next p
depscore
Query the Socket API for dependency scoring information. Returns supply chain, quality, maintenance, vulnerability, and license scores per package.
organizations
List the Socket organizations the authenticated user belongs to. Takes no parameters. Use it to discover the orgslug value that the org-scoped tools (alerts, threatfeed) require.
package_file_contents
Read a single file from a package. Pass the hash printed next to an entry in packagefiles output. Returns up to 1 MB of UTF-8 text; binary files return metadata only.
package_file_grep
Search a single file from a package for lines matching a JavaScript regular expression, returning matches with line numbers (grep -n style). Each blob is fetched once and held in a process-wide cache, so repeated reads and greps of the same hash skip the network.
package_files
List the files published in a package: a tree of file paths, each with its size and blob hash, for any package on a supported ecosystem. Use it to inspect what a dependency ships before installing it. Pass a file's hash to packagefilecontents or packagefilegrep.
threat_feed
Look up items in a Socket organization's threat feed: packages recently flagged as malware, typosquats, obfuscated code, and similar. Backed by GET /v0/orgs/{orgslug}/threat-feed. The response carries a nextPageCursor; pass it as cursor to page forward.