Atlas / MCP servers / safedep / Vet

VetBLOCK

mcp/safedep/vet

Protect against malicious open source packages 🤖

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
1,107
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Quick Start • Documentation • Community

[](https://goreportcard.com/report/github.com/safedep/vet) [](https://github.com/safedep/vet/blob/main/LICENSE) [](https://github.com/safedep/vet/releases) [](https://api.securityscorecards.dev/projects/github.com/safedep/vet) [](https://slsa.dev) [](https://github.com/safedep/vet/actions/workflows/codeql.yml)

[](https://deepwiki.com/safedep/vet) [](https://mcptoplist.com/server/io.github.safedep%2Fvet-mcp)

[!NOTE] vet also runs in the cloud. Point it at your GitHub repositories and get continuous scanning, malware detection, and policy enforcement without managing any infrastructure. See SafeDep Cloud for the end-to-end software supply chain security platform.

Why vet?

**70-90%
Read from source at commit 3261a9719523OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (oci)
claude mcp add vet:vVERSION_FROM_ENV -- docker run -i --rm ghcr.io/safedep/vet:vVERSION_FROM_ENV:None -s /tmp/vet-mcp.log server mcp
03

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (9 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ent/codesignaturematch_create.go:204
func (_c *CodeSignatureMatchCreate) Exec(ctx context.Context) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ent/codesignaturematch_create.go:418
func (_c *CodeSignatureMatchCreateBulk) Exec(ctx context.Context) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ent/codesignaturematch_delete.go:29
func (_d *CodeSignatureMatchDelete) Exec(ctx context.Context) (int, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ent/codesignaturematch_delete.go:71
func (_d *CodeSignatureMatchDeleteOne) Exec(ctx context.Context) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ent/codesignaturematch_update.go:323
func (_u *CodeSignatureMatchUpdate) Exec(ctx context.Context) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cmd/server/mcp.go:52
"List of allowed origin prefixes for SSE connections. By default, we allow http://localhost:, http://127.0.0.1: and https://localhost:.",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/auth/auth_test.go:111
return &Config{ApiKey: "test-api-key-from-config"}
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pkg/code/testdata/test_javascript_capabilities/main.js:66
const md5 = crypto.createHash('md5');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
pkg/code/testdata/test_python_capabilities/main.py:65
hashlib.md5(b"test").digest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
signatures/lang/python/crypto.yaml:201
value: "Crypto.Cipher.DES.new"
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
signatures/lang/python/crypto.yaml:205
value: "Cryptodome.Cipher.DES.new"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/scenarios/all.sh:6
export E2E_ROOT="$E2E_THIS_DIR/../../"
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
pkg/reporter/gitlab_test.go:231
Details: "Found suspicious eval usage and data exfiltration attempts",
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
pkg/reporter/gitlab_test.go:265
assert.Equal(t, "Package contains malicious code\n\nFound suspicious eval usage and data exfiltration attempts", vuln.Description)
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
pkg/reporter/sync_test.go:361
Summary: "Suspicious code detected that attempts to exfiltrate sensitive data",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp.md:62
- **Allowed origin prefixes**: `http://localhost:`, `http://127.0.0.1:`, `https://localhost:`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp.md:85
--sse-allowed-origins "http://localhost:,http://127.0.0.1:,https://localhost:"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp.md:95
--sse-allowed-origins "http://localhost:,http://127.0.0.1:,https://localhost:"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp/server/guard_test.go:119
"http://127.0.0.1:",
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pkg/parser/fixtures/bom-maven.json:71
"content" : "QXBhY2hlIExpY2Vuc2UKVmVyc2lvbiAyLjAsIEphbnVhcnkgMjAwNApodHRwOi8vd3d3LmFwYWNoZS5vcmcvbGljZW5zZXMvCgpURVJNUyBBTkQgQ09ORElUSU9OUyBGT1IgVVNFLCBSRVBST0RVQ1RJT04sIEFORCBESVNUUklCVVRJT04KCjEuIER
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pkg/parser/fixtures/bom-maven.json:133
"content" : "RWNsaXBzZSBQdWJsaWMgTGljZW5zZSAtIHYgMi4wClRIRSBBQ0NPTVBBTllJTkcgUFJPR1JBTSBJUyBQUk9WSURFRCBVTkRFUiBUSEUgVEVSTVMgT0YgVEhJUyBFQ0xJUFNFIFBVQkxJQyBMSUNFTlNFICjigJxBR1JFRU1FTlTigJ0pLiBBTlkgVVN
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
pkg/parser/fixtures/bom-maven.json:195
"content" : "QXBhY2hlIExpY2Vuc2UKVmVyc2lvbiAyLjAsIEphbnVhcnkgMjAwNApodHRwOi8vd3d3LmFwYWNoZS5vcmcvbGljZW5zZXMvCgpURVJNUyBBTkQgQ09ORElUSU9OUyBGT1IgVVNFLCBSRVBST0RVQ1RJT04sIEFORCBESVNUUklCVVRJT04KCjEuIER

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 3261a9719523full audit observations/trust-audit/mcp-server/safedep__vet.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-253261a9719523BLOCKF54first audit
05

Questions

What is the Vet MCP server?

Protect against malicious open source packages 🤖

Is Vet safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Vet need?

No credential environment variables were found in its source, so it appears to need none.

How does Vet run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as express at 4.18.2.

How current is this page?

The grade is for one exact copy of the source (3261a9719523), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement