safedep vet
https://github.com/safedep/vet/blob/main/docs/mcp.md
Visit Project →vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.