# Socket MCP server

> Check supply-chain security scores for npm, PyPI, Maven, Go and other packages, and inspect package files before installing.

- Listing: https://mcp.tc/i/socket
- Connect: use the server's own URL `https://mcp.socket.dev/` (no sign-in); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: none
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Socket
- Homepage: <https://docs.socket.dev/docs/guide-to-socket-mcp>
- Docs: <https://github.com/SocketDev/socket-mcp?tab=readme-ov-file>
- Repository: <https://github.com/SocketDev/socket-mcp>
- Package: npm `@socketsecurity/mcp`

## About

Socket connects your assistant to Socket's dependency security data. It scores packages for vulnerabilities, malware, supply chain risk, quality, maintenance and license issues across ecosystems such as npm, PyPI, Cargo, Maven, NuGet, RubyGems and Go. It can also list organization alerts, read the threat feed, and browse or grep the files a package ships.

A hosted endpoint is available at https://mcp.socket.dev/ over streamable HTTP, and the README describes an OAuth sign-in through your MCP client. You can also self-host the npm package @socketsecurity/mcp with a Socket API token and Node.js 24 or later. Sessions on the hosted server may occasionally need a fresh initialize.

## What it can do

- Score packages for security, quality and maintenance
- Audit dependencies found in manifests and code imports
- List Socket organizations you belong to
- List security alerts with severity and status filters
- Browse the threat feed for malware and typosquats
- List files published in a package
- Read or grep a single file inside a package

## Tools (7)

- `depscore`: Get dependency quality and security scores for packages; use 'unknown' when the version is not… (read-only)
- `organizations`: List the Socket organizations the signed-in user belongs to and their org\_slug values. (read-only)
- `alerts`: List latest security alerts for an organization with filters and pagination. (read-only)
- `threat_feed`: Look up recently flagged packages such as malware and typosquats, with filters and pagination. (read-only)
- `package_files`: List the files and sizes published in a package across supported ecosystems. (read-only)
- `package_file_contents`: Read a single file from a package, up to 1 MB of text. (read-only)
- `package_file_grep`: Search a package file for lines matching a JavaScript regular expression. (read-only)

## Example prompts

- "Check the security score for express version 4.18.2"
- "Audit the dependencies in my package.json for risky packages"
- "Show the latest high severity alerts for my Socket organization"
- "List the files in the npm package left-pad before I install it"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http socket https://mcp.socket.dev/
```

2. Start Claude Code and type `/mcp`. **socket** should show as connected.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **Socket** and paste this URL:

```url
https://mcp.socket.dev/
```

3. Click **Add**. Its tools appear in the chat’s tools menu.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=Socket&connectorUrl=https%3A%2F%2Fmcp.socket.dev%2F>) (opens connector settings)

2. Check that the URL reads `https://mcp.socket.dev/` and click **Add**.

3. Turn it on in a chat from the tools menu.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.socket.dev/` as the server URL and choose **No authentication**.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=socket&config=eyJ1cmwiOiJodHRwczovL21jcC5zb2NrZXQuZGV2LyJ9>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "socket": {
      "url": "https://mcp.socket.dev/"
    }
  }
}
```

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=socket&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.socket.dev%2F%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"socket","type":"http","url":"https://mcp.socket.dev/"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "socket": {
      "type": "http",
      "url": "https://mcp.socket.dev/"
    }
  }
}
```

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "socket": {
      "serverUrl": "https://mcp.socket.dev/"
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add socket --url https://mcp.socket.dev/
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.socket]
url = "https://mcp.socket.dev/"
```

### Gemini CLI

```bash
gemini mcp add --transport http socket https://mcp.socket.dev/
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "socket": {
      "type": "http",
      "url": "https://mcp.socket.dev/"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.socket.dev/`.

## Details

- Server version: 0.0.20
- MCP protocol version: 2025-11-25
- Last checked: 2026-10-03 (reachable)
- Listed: 2026-10-03
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/socket (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
