Docs & AI · Official remote MCP server

The Dependency Trust MCP server,
connected in one click.

Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems. Connect the official Dependency Trust MCP server to Claude, ChatGPT, or Cursor through gate — one gateway URL, no config files, security-checked.

Free to start · No credit card · No hosting needed

Use this server

Add Dependency Trust to your AI in one minute

Pick your client. Copy, paste, done — or let gate handle sign-ins and policies for you.

claude mcp add --transport http dependency-trust https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d

Run in your terminal, then restart Claude Code.

Dependency Trust · https://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d

What you can do

What your AI can do with Dependency Trust

Real prompts you can type the moment it's connected — no setup, no docs to read.

Use “get_advisory”: Get a security advisory (vulnerability) by its key. Returns a security advisory by key — e.g. a GHSA id taken from a version's advisoryKeys.

Use “get_dependencies”: Get the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version —.

Use “get_package”: List every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-.

Use “get_package_version”: Get license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses,.

Security check

How secure is the Dependency Trust MCP server?

Every server in the gate directory has to pass the same four checks before your AI can touch it. Here's how Dependency Trust holds up.

Verified directory serverDependency Trust · kaiv.ai

Official endpoint

Operated by Dependency Trust (kaiv.ai) at its documented MCP endpoint — not a third-party mirror or community re-host.

No sign-in needed

This server only exposes public data — no account and no credentials are involved when you connect.

Scanned before it goes live

gate checks every tool for prompt injection, hidden instructions, data-exfiltration hints, and over-broad permissions before the server is available through your gateway.

Watched for drift

If Dependency Trust adds or changes tools later, gate re-scans and alerts you — before your AI acts on the change.

How it works

Connected in three steps

01

Connect your gate

Add one gateway URL to Claude, ChatGPT, or any MCP client. One-time setup, about two minutes.

02

Pick Dependency Trust

Choose Dependency Trust in the gate directory. No sign-in needed.

03

Use it anywhere

Dependency Trust's tools are live in every AI client you've connected — with rules and logging built in.

Connect Dependency Trust free

Free to start · No credit card · No hosting needed

Straight from the server

The actual tools Dependency Trust exposes

Fetched live from the official endpoint and re-checked daily by gate — not marketing copy.

get_advisoryGet a security advisory (vulnerability) by its key. Returns a security advisory by key — e.g. a GHSA id taken from a version's advisoryKeys

get_dependenciesGet the resolved dependency graph for one package version. Returns the full resolved dependency graph (direct and indirect) for a version —

get_packageList every version of a package and whether each is deprecated. Returns all published versions of a package with publish date, the default-

get_package_versionGet license, security advisories, and source links for one package version. Returns detailed metadata for a single version: SPDX licenses,

get_project_healthGet a project's OpenSSF Scorecard security posture and maintenance signals. THE trust check. Returns supply-chain trust signals for a packa

Author

Who runs the Dependency Trust MCP server?

Server facts

The Dependency Trust MCP server at a glance

Endpointhttps://api.kaiv.ai/api/bridge/mcp/dependency-trust-f1aaf06d
Operated byDependency Trust (kaiv.ai)
CategoryDocs & AI
Sign-inNone — public data only
Available in gateYes — one-click connect
Works withClaude, ChatGPT, Cursor & any MCP client
FAQ

Questions, answered

Is there an official Dependency Trust MCP server?

Yes — Dependency Trust operates its own remote MCP server at api.kaiv.ai. gate connects you to that official endpoint and adds security scanning, per-tool access rules, and an activity log on top.

How do I connect Dependency Trust to Claude or ChatGPT?

Add gate's gateway URL to your AI client once, then pick Dependency Trust in the directory. No account or sign-in is needed. From then on, Dependency Trust's tools are available in every client you've connected to gate.

Do I need to host anything?

No. Dependency Trust runs the server, and gate is fully managed. You just connect one URL — there's nothing to install, deploy, or maintain.

Is the Dependency Trust MCP server safe to connect?

It's the vendor's official endpoint, and gate scans its tools for prompt injection and hidden instructions before it goes live, re-checks it whenever it changes, and lets you allow, block, or require approval for every single tool.

Is it free?

Yes — you can get started with gate for free and connect Dependency Trust in minutes. No credit card required.

More servers

Connect more than just Dependency Trust

Every server below works through the same gateway URL — connect once, add tools anytime.

Set up Dependency Trust in: Claude · Claude Code · ChatGPT · Cursor · VS Code

Give your AI Dependency Trust — safely.

One URL. All MCPs. Full control. Free to start.

Get started free