Use Socket.dev with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Protect your software supply chain by scanning dependencies, checking package security scores, and monitoring threat feeds directly from your AI agent.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 10 capabilities
The complete Socket.dev capability set.
These are the exact actions your AI can choose when you ask it to work with Socket.dev.
01-04
4 capabilities in this set.
Part of 10 available through Socket.dev.
- 01
Delete scan
Delete a scan
- 02
Get package issues
G., pkg:npm/babel). Get issues/alerts for a specific package
- 03
Create scan
Provide manifest files data (e.g., package.json, requirements.txt). Create a new scan by uploading manifest files
- 04
Get package score
G., pkg:npm/babel). Get the security score for a specific package
05-07
3 capabilities in this set.
Part of 10 available through Socket.dev.
- 05
Get quota
Check remaining API quota
- 06
Get report
Get detailed report data
- 07
Get scan
Get scan metadata and status
08-10
3 capabilities in this set.
Part of 10 available through Socket.dev.
- 08
Get threat feed
Access the real-time threat feed
- 09
List organizations
List organizations the token has access to
- 10
List reports
List reports
Observed, not estimated
952ms average. Fast in production.
Socket.dev is checked daily against the live service.
- Fastest day
- 736ms
- Slowest day
- 1127ms
- 14-day trend
- Slowing+31%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Socket.dev, so you can see the experience inside your AI.
It does not authenticate your account with Socket.dev. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Socket.dev Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_R4rzC31YO5lAo6xekKbMZrPuutcnC2L5364MbwbS/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Socket.dev capabilities are ready to use.
{
"mcpServers": {
"socketdev-dependency-security-mcp": {
"url": "https://edge.vinkius.com/vk_preview_R4rzC31YO5lAo6xekKbMZrPuutcnC2L5364MbwbS/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions Socket.dev owners ask.
- 01
How can I check if a specific npm package is safe to use?
You can use the get_package_score capability by providing the Package URL (PURL), such as pkg:npm/lodash. The agent will return a security score and risk assessment.
- 02
Can I scan my entire project's dependencies at once?
Yes! Use the create_scan capability and provide the content of your manifest files (like package.json). Socket will analyze all dependencies and generate a report.
- 03
How do I see the specific security issues found in a package?
Use the get_package_issues capability with the package's PURL. It will list all alerts, such as telemetry, install scripts, or known vulnerabilities associated with that package.
Explore
More in Fort Knox
Dependency Impact Analyzer AI Connector
Analyzes the security, legal, and structural impact of adding or updating dependencies.
ViewFile Change Impact Assessor AI Connector
Quantifies the blast radius and risk of file modifications through deterministic dependency tracing.
ViewOpenAPI Context Window Packer AI Connector
Prune massive OpenAPI specs to fit within LLM context windows.
ViewAnnotation Extractor and Tracker AI Connector
Automatically detect, track, and report code annotations like FIXME, HACK, and XXX in your codebase.
View
Suggestions
SBOM Dependency Risk Scorer AI Connector
Analyze SBOM files to quantify supply chain risk through dependency structure, package staleness, and vulnerab
ViewSensitive Data Exposure Detector AI Connector
Intercepts and redacts sensitive information from file reads and tool outputs.
ViewClaim Substantiation Checker AI Connector
Scans marketing copy for factual and numeric claims requiring substantiation.
ViewOutbound Network Firewall Validator AI Connector
Validates outbound network requests against allowed domains and ports to prevent data exfiltration.
View
