hound-mcp
MCP Servertiluckdave/hound-mcp
Hound MCP is a free, zero-configuration security guard dog designed specifically for AI coding agents to scan dependencies and prevent vulnerabilities. It integrates smoothly across seven major programming ecosystems using public unauthenticated APIs.
Overview
Hound MCP acts as an autonomous dependency bloodhound that equips AI coding agents with powerful security, license checking, and package evaluation tools. By leveraging free public APIs like Google OSV and deps.dev, it scans lockfiles, detects typosquatting, evaluates upgrade paths, and provides clear pre-installation verdicts without requiring accounts or API keys.
Capabilities
- ▸Scan lockfiles for known vulnerabilities across multiple ecosystems
- ▸Evaluate packages with a GO, CAUTION, or NO-GO pre-installation verdict
- ▸Perform side-by-side package comparisons and recommendation scoring
- ▸Detect typosquatting variants of package names
- ▸Audit license compliance against corporate policies
- ▸Inspect transitive dependency trees and suggest safe version upgrades
Best for
Auditing project dependencies for security vulnerabilities before merging pull requests, checking packages with a pre-installation verdict to avoid malicious libraries, scanning for license compliance in commercial codebases, and executing automated project security audits via AI assistants.
Works with
実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 — AIによるcapabilities/use-cases解析
実装・指示の品質。 — AIによるSKILL.md/README解析
リポジトリがどれだけ活発に保守されているか。 — GitHub 最終push日時の新しさ
ドキュメントの充実度・分かりやすさ。 — README/独自要約の情報量
危険・不審な挙動が無いか。 — AIによるセキュリティレビュー
ありふれたラッパーではない独自性。 — AIによる独自性判定
コミュニティの採用度。 — GitHub Stars/Forks(対数スケール)
対応AIエージェントの広さ。 — AIによる対応エージェント判定
ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →
Security considerations
Hound MCP performs read-only security audits and vulnerability checks against open-source dependency trees using unauthenticated public APIs, maintaining privacy and requiring no sensitive credentials.
Categories
Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.