MCP server
dagsec is an MCP server at https://app.dagsec.net/mcp (Streamable HTTP, JSON responses). Any MCP client can use it to check packages; install blocking needs a hook, as in the Claude Code plugin, Cursor or Gemini CLI.
Connect
Authenticate with an API key as a bearer token.
Claude Code without the plugin:
claude mcp add --scope user --transport http dagsec https://app.dagsec.net/mcp --header "Authorization: Bearer YOUR_DAGSEC_API_KEY"Cursor, Windsurf and other clients that take a JSON config:
{
"mcpServers": {
"dagsec": {
"url": "https://app.dagsec.net/mcp",
"headers": { "Authorization": "Bearer YOUR_DAGSEC_API_KEY" }
}
}
}The server sends instructions telling the agent to call check_package before adding or upgrading a dependency, and how to act on the answer.
Tools
check_package
Checks a package before it is added or upgraded. Read-only.
| Argument | Required | Values |
|---|---|---|
name | Yes | Package name, up to 214 characters: axios, requests, serde, github.com/gin-gonic/gin, org.apache.logging.log4j:log4j-core (Maven is groupId:artifactId), Newtonsoft.Json |
ecosystem | Yes | npm, pypi, crates, go, maven or nuget |
version | No | Exact version to check; omitted means the latest release |
The answer is plain text whose first line is the verdict:
| First line | Meaning |
|---|---|
DO NOT INSTALL: <name> does not exist on <ecosystem> | Not in the registry: misspelled, hallucinated, or a squatting target |
DO NOT USE <name>@<version>: N critical/high vulnerabilities. Use <name>@<fix> or later. | Serious vulnerabilities; the fix is named when there is one |
RISKY: <name> scores N/100 | Health score below 40 |
OK WITH CAUTION: … | Only moderate or low vulnerabilities |
OK: <name>@<version> has no known vulnerabilities; health N/100. | Fine |
Below it: the checked and latest versions, up to 15 vulnerabilities with severity, ID and fixed version, and the six health categories with their details.
check_install
Used by the Claude Code plugin's hook. Takes command (a shell command such as npm install [email protected]) and returns a Claude Code hook decision. Agents should call check_package instead.
Limits
Each tool call counts as one agent check. When the month's checks are used up, check_package answers with an error saying so, and check_install lets installs through unchecked. See Plans and limits.