Safety
Safety gives security teams real-time visibility and governance over every AI tool, package, MCP server, and IDE extension across their developer fleet.
Opens ChatGPT on the web or desktop and asks it to use the WebMCP tools available here.
Connect straight to this server’s public endpoint.
https://mcp.safetycli.com/mcpWe add this server to your workspace, then open Studio — saved access, one connection to many servers, with a history of what ran.
Last probed Sep 14, 2026 · mcp.safetycli.com
4tools discovered
Check Package Security
Check if packages contain vulnerabilities. Args: packages: A list of packages to check, in the format:: [ {"name": "package1", "version": "1.0.0", "ecosystem": "pypi"}, {"name": "package2", "version": "", "ecosystem": "maven"}, {"name": "express", "version": "4.17.1", "ecosystem": "npm"} ] • "ecosystem" **must** be "pypi", "maven", or "npm". • If "version" is an empty string, the latest version w
Get Recommended Version
Get the recommended version for package(s). Args: packages: A list of packages to check, in the format:: [ {"name": "package1", "ecosystem": "pypi"}, {"name": "package2", "ecosystem": "maven"}, {"name": "express", "ecosystem": "npm"} ] ``ecosystem`` must be "pypi", "maven", or "npm". Returns: Recommended version information as a dict with a "packages" array. Each package object accepts the same ``ec
List Vulnerabilities Affecting Version
List vulnerabilities that affect the specified (or latest) version of each package. This tool should only be used if a user specifically asks for more detail about a vulnerability. Args: packages: A list of packages with optional version and ecosystem fields. Returns: Dict with ``packages`` key containing per-package vulnerability information.
Get Package Health
Get package health: Safety's weighted-average health score plus the per-category and per-signal OpenSSF Scorecard breakdown (supply-chain hygiene, code-quality practices, maintenance, and licensing). Health is version-agnostic: it reflects the package's latest OpenSSF Scorecard snapshot (repo-level), not any specific release. Any ``version`` supplied in the input is ignored. Args: packages: A list of packages to check, in the format:: [ {"name": "requests", "eco
Get your MCP into directories
A working endpoint is step one. Directory coverage is the coordinated launch across ChatGPT, Claude, Cursor, the MCP Registry, and community indexes.
Directory coverage for brandsSafety gives security teams real-time visibility and governance over every AI tool, package, MCP server, and IDE extension across their developer fleet.
Use the MCP endpoint listed on this page in your MCP client configuration. One-click install pills support Claude, Cursor, VS Code, and other hosts. Copy the remote MCP URL if your client needs a manual entry.
Operate Safety? Verify ownership to take over this directory entry.
This server appears in the MCPBundles directory. Verify you operate it to take over the listing — name, description, logo, contact email, and skill content. We email a 6-digit code to a maintainer address your server publishes in /.well-known/security.txt or /.well-known/mcpbundles.json. Free, takes about a minute.
MCPBundles probed 4 tools on the live server. The tool list on this page reflects what was discovered at the last refresh — connect your client to see the full set available to your session.
No provider sign-in was required during MCPBundles' probe. Your client may still need MCPBundles credentials depending on how you connect.
MCPBundles is an independent platform built on the open Model Context Protocol standard. Not affiliated with Anthropic PBC or Claude.