AI Developer Tools

deptrust

A CLI tool that checks package versions for known vulnerabilities across npm, PyPI, and many other ecosystems, designed for AI agents to avoid using outdated packages.

What is deptrust?

deptrust is a CLI tool that checks package versions for known vulnerabilities across multiple package ecosystems. It runs locally as a CLI and as an MCP server, calling public registries and OSV APIs directly without a hosted service.

deptrust vs Similar AI Tools

Pricing ModelFreeFreeCustom PricingFree, Paid
Free Credits
Key Features
  • Checks packages across 15+ ecosystems including npm, PyPI, Cargo, Go, RubyGems, NuGet, Maven, and more
  • Reports known vulnerabilities with severity, recommendation, and risk score
  • Suggests safe versions by checking provider-reported fixes and version history
  • GitHub Pages hosting
  • Jekyll integration
  • Markdown content support
  • Workload monitoring and anomaly detection
  • Slow query identification and optimization
  • Natural language querying to SQL translation
  • Scans skills and MCP servers against ATR rules before loading
  • Real-time runtime protection against prompt injection and hijacks
  • Signed audit-ready evidence for compliance (EU AI Act, NYDFS, DORA)
Pros
  • Supports a wide range of package ecosystems
  • Runs locally with fast parallel queries to public APIs
  • Free hosting with custom domain support
  • Easy setup via Git
  • Quick one-line installation and setup in 15 minutes
  • Self-hosted ensures data stays within your infrastructure
  • Open source with MIT license
  • Real-time detection and prevention
Cons
  • Only checks known vulnerabilities, does not perform code analysis
  • Requires MCP setup for AI agent integration, which may be complex
  • Limited to static content
  • No server-side processing
  • Requires self-hosting and VPC setup
  • No free tier or trial mentioned
  • Enterprise features require paid tiers
  • Setup may require technical expertise
Best For
  • AI developers building agentic workflows
  • Developers who want to prevent vulnerable dependency picks
  • Developers
  • Open source projects
  • Database administrators
  • Data engineers
  • Developers building and deploying AI agents
  • Enterprises needing audit-ready AI security

How to use deptrust?

  1. 1Install with npx @clidey/deptrust install. Run checks like 'deptrust check npm lodash 4.17.20' or 'deptrust check pypi requests latest'. For AI agent integration, configure MCP with 'deptrust mcp'. Use JSON output with '--json' flag.

deptrust Key Features

  • Checks packages across 15+ ecosystems including npm, PyPI, Cargo, Go, RubyGems, NuGet, Maven, and more
  • Reports known vulnerabilities with severity, recommendation, and risk score
  • Suggests safe versions by checking provider-reported fixes and version history
  • Compares two versions to show risk improvement
  • Integrates as MCP server for AI agents (Codex, Claude Code)
  • Runs entirely locally with no external service dependency
  • Outputs JSON with advisory coverage details

deptrust Use Cases

  • AI agents checking package versions before recommending updates
  • Developers auditing project dependencies for vulnerabilities
  • CI/CD pipelines enforcing package version policies
  • Security teams reviewing dependency risk scores

deptrust Pricing & Free Credits

deptrust currently operates on a Free model.

This tool is completely free to use

Free

$0

Open source and free to use under MIT license.

deptrust Pros & Cons

Pros

  • Supports a wide range of package ecosystems
  • Runs locally with fast parallel queries to public APIs
  • Integrates seamlessly with AI agents via MCP protocol
  • Provides clear recommendations (allow/block/review) and risk scores
  • Open source and no need for account or API keys

Cons

  • Only checks known vulnerabilities, does not perform code analysis
  • Requires MCP setup for AI agent integration, which may be complex
  • Depends on OSV and GitHub Advisory Database coverage per ecosystem
  • Some ecosystems have partial advisory coverage (e.g., CocoaPods, Hackage)

What is deptrust best for?

  • AI developers building agentic workflows
  • Developers who want to prevent vulnerable dependency picks
  • DevSecOps teams needing a lightweight vulnerability checker
  • Anyone using package managers in automated environments

deptrust FAQ

Top free alternatives to deptrust

B

Personal GitHub Pages site by Basert, currently displaying default welcome content and instructions for using GitHub Pages with Jekyll.

Free
Termaxa logo

A cooperative gate for shell commands that AI agents run, providing previews, backups, policy enforcement, and audit for tools like Claude Code and Cursor.

Free
Agentcard logo

Agentcard provides agent-friendly card issuing and payment infrastructure for AI agents, enabling 5-minute setup and autonomous purchases.

Free
Oodle AI logo

Oodle AI provides agent observability with fast trace search, S3-based storage, and out-of-the-box insights to detect silent failures in AI agents.

Free
Jacquard logo

Jacquard is a small programming language designed for running, reviewing, and trusting programs written by machine-learning models and reviewed by people.

Free
Perfai Security logo

Autonomous security testing platform that finds and fixes access control vulnerabilities in live AI-built apps.

Free
Octolens logo

AI-powered social listening tool that monitors Reddit, X, LinkedIn, and 10+ other platforms, filters mentions with AI, and delivers them to your stack via API, Slack, or webhooks.

Free
Opper AI logo

A unified AI gateway providing access to 300+ leading models through one EU-hosted, GDPR-compliant API with an OpenAI SDK-compatible interface.

Free

Best alternatives AI Tools to deptrust

B

Personal GitHub Pages site by Basert, currently displaying default welcome content and instructions for using GitHub Pages with Jekyll.

Free
DeepSQL logo

DeepSQL is an AI DBA that monitors workloads, optimizes slow queries, and cuts database costs via a self-hosted agent with MCP and Slack integration.

Panguard AI logo

Open-source platform for real-time AI agent security, auditing skills and runtime with community-driven threat rules.

OpenSEO logo

OpenSEO is an open source SEO platform that integrates with AI agents via MCP to provide real SEO data for keyword research, competitor analysis, backlinks, and more.

SureWire Beta logo

SureWire Beta is an AI agent validation platform that helps ensure your AI agents are safe and reliable through comprehensive testing.

FlexInference logo

A deadline-aware LLM router that reduces AI inference costs by automatically finding cheaper service tiers within a user-specified time window.

Shikigami logo

Run multiple AI coding agents in parallel on isolated git worktrees with a full editor and built-in developer tools.

LoopGain logo

An open-source cost controller for AI agent loops that stops loops when converged and rolls back before degradation.