Socket

MCP-Server von Socket

Check supply-chain security scores for npm, PyPI, Maven, Go and other packages, and inspect package files before installing.

Ohne Anmeldung (Kein Konto und kein Schlüssel nötig)Streamable HTTP

Mit Socket verbinden

Keine Anmeldung nötig. Verbinde dich mit der eigenen URL von Socket:

https://mcp.socket.dev/

Füg sie in jeden Client ein, der Remote-MCP-Server unterstützt. Dein Client spricht direkt mit Socket, nicht über mcp.tc.

Diesen Server teilen

Öffnet diese Seite, mit der URL und den Einrichtungsschritten.

mcp.tc/i/socket

Über den Server

Socket connects your assistant to Socket's dependency security data. It scores packages for vulnerabilities, malware, supply chain risk, quality, maintenance and license issues across ecosystems such as npm, PyPI, Cargo, Maven, NuGet, RubyGems and Go. It can also list organization alerts, read the threat feed, and browse or grep the files a package ships.

A hosted endpoint is available at https://mcp.socket.dev/ over streamable HTTP, and the README describes an OAuth sign-in through your MCP client. You can also self-host the npm package @socketsecurity/mcp with a Socket API token and Node.js 24 or later. Sessions on the hosted server may occasionally need a fresh initialize.

Was du damit machen kannst

  • Score packages for security, quality and maintenance
  • Audit dependencies found in manifests and code imports
  • List Socket organizations you belong to
  • List security alerts with severity and status filters
  • Browse the threat feed for malware and typosquats
  • List files published in a package
  • Read or grep a single file inside a package

Tools 7

  • depscoreNur lesen

    Get dependency quality and security scores for packages; use 'unknown' when the version is not…

  • organizationsNur lesen

    List the Socket organizations the signed-in user belongs to and their org_slug values.

  • alertsNur lesen

    List latest security alerts for an organization with filters and pagination.

  • threat_feedNur lesen

    Look up recently flagged packages such as malware and typosquats, with filters and pagination.

  • package_filesNur lesen

    List the files and sizes published in a package across supported ecosystems.

  • package_file_contentsNur lesen

    Read a single file from a package, up to 1 MB of text.

  • package_file_grepNur lesen

    Search a package file for lines matching a JavaScript regular expression.

Am 3. Okt. 2026 vom laufenden Server gelesen. Nur lesen, Schreibt und Kann löschen sind Hinweise, die der Server selbst angibt; dein Client entscheidet, ob er vor dem Ausführen eines Tools nachfragt.

Beispiel-Prompts

  • Check the security score for express version 4.18.2

  • Audit the dependencies in my package.json for risky packages

  • Show the latest high severity alerts for my Socket organization

  • List the files in the npm package left-pad before I install it

Einrichtung

Jeder Client verbindet sich mit mcp.socket.dev. Wähl deinen; die Seite merkt sich deine Wahl.

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http socket https://mcp.socket.dev/
  1. Start Claude Code and type /mcp. socket should show as connected.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Open Settings → Connectors and click Add custom connector.
  2. Name it Socket and paste this URL:
https://mcp.socket.dev/
  1. Click Add. Its tools appear in the chat’s tools menu.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

claude.ai

  1. Open the connector form on claude.ai. This button fills in the name and URL for you:
  1. Check that the URL reads https://mcp.socket.dev/ and click Add.
  2. Turn it on in a chat from the tools menu.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under Organization settings → Connectors.

ChatGPT

  1. On chatgpt.com, open Settings → Security and login and turn on Developer mode.
  2. Go to chatgpt.com/plugins and click + to create an app for a remote MCP server.
  3. Paste https://mcp.socket.dev/ as the server URL and choose No authentication.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "socket": {
      "url": "https://mcp.socket.dev/"
    }
  }
}

VS Code

Or from a terminal:

code --add-mcp '{"name":"socket","type":"http","url":"https://mcp.socket.dev/"}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "socket": {
      "type": "http",
      "url": "https://mcp.socket.dev/"
    }
  }
}

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "socket": {
      "serverUrl": "https://mcp.socket.dev/"
    }
  }
}
  1. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add socket --url https://mcp.socket.dev/

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.socket]
url = "https://mcp.socket.dev/"

Gemini CLI

gemini mcp add --transport http socket https://mcp.socket.dev/

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI’s settings file.

{
  "mcpServers": {
    "socket": {
      "type": "http",
      "url": "https://mcp.socket.dev/"
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.socket.dev/.

Häufige Fragen

Can I paste mcp.tc/i/socket into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://mcp.socket.dev/, so your client talks to Socket directly. The quick link is for sharing: it opens this page, with setup steps for every client.

Does Socket need an API key or a sign-in?

No. Socket doesn’t ask for an account or key.

Is Socket a remote or a local server?

Remote. Socket hosts it at https://mcp.socket.dev/, and it speaks Streamable HTTP. There’s nothing to install.

What can Socket do?

It has 7 tools, including depscore, organizations und alerts. You can Score packages for security, quality and maintenance, Audit dependencies found in manifests and code imports und List Socket organizations you belong to.

Which clients can use it?

Any client that supports remote MCP servers: Claude Code, Claude Desktop, claude.ai, ChatGPT in developer mode, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. The setup steps cover each one.

Who wrote this page?

mcp.tc’s robot read Socket’s own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

Einbinden

Zeig Socket in einem README oder auf deiner Website. Jede Einbindung verlinkt auf diese Seite, nutzt die eigene URL des Servers und setzt keine Cookies. So funktionieren Einbindungen

README-Badge

Badge-Vorschau, hellBadge-Vorschau, dunkel
Markdown
[![Socket on mcp.tc](https://mcp.tc/i/socket/badge.svg)](https://mcp.tc/i/socket)
HTML
<a href="https://mcp.tc/i/socket"><img src="https://mcp.tc/i/socket/badge.svg" alt="Socket on mcp.tc" height="20"></a>

Es folgt dem hellen oder dunklen Modus der Lesenden. Hänge ?theme=light oder ?theme=dark an, um ihn festzulegen, oder ?style=compact, um das Zeichen ohne Schriftzug zu zeigen.

Website-Karte

HTML
<script src="https://mcp.tc/w/socket.js" async></script>

Die Karte erscheint dort, wo das Tag steht. Füge dem Tag data-theme="dark" oder data-size="compact" hinzu, um sie zu ändern. Die Datei enthält alles, was sie braucht, stellt also keine weiteren Anfragen und setzt keine Cookies.

iframe

HTML
<iframe src="https://mcp.tc/embed/socket" title="Socket on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

Nutze es auf Seiten, die keine Skripte erlauben. Hänge ?theme=light oder ?theme=dark an die Adresse an, um die Farben festzulegen.

JSON

Der Eintrag als Daten für deine eigenen Seiten und Tools: Name, Kurzbeschreibung, die eigene URL des Servers, Tools und die „Add to“-Links. Jede Website kann ihn lesen (CORS ist offen).

https://mcp.tc/i/socket.json

Was jedes Feld bedeutet

mcp.tc ist nicht mit Socket verbunden. Diese Seite entstand aus den öffentlichen Metadaten von Socket, zuletzt geprüft am 3. Okt. 2026, und ein KI-Modell hat die Beschreibung geschrieben, sie kann also Fehler enthalten. Namen und Marken gehören ihren Inhabern. Stimmt etwas nicht? Eintrag melden.