DepScout

Is this package safe? Ask your AI assistant.

DepScout lets ChatGPT, Claude and other AI assistants check open-source packages against live vulnerability and malware data while you work, so answers don't rely on what a model remembers. It covers npm, PyPI, Go, Maven, crates.io and NuGet.

Malicious-package flags

Packages and versions reported as malware (OSV MAL- advisories and GitHub malware advisories) are flagged first.

Known vulnerabilities

CVE and GHSA advisories for a specific version, with severity, the version that fixes each one, and the minimum version that clears them all.

Freshness and health

Latest stable version, whether your version is outdated or deprecated, last release date, licences and the repository's OpenSSF Scorecard.

Whole dependency lists

Paste up to 50 entries from package.json, requirements.txt, go.mod or similar and get back only the ones with problems.

Try asking

Good to know

A clean result means no advisory is known in OSV.dev for that exact version; it isn't a guarantee of safety. Newly published malware can take time to be reported. DepScout checks the packages you list, not their transitive dependencies.