@gardera/gardwatch-mcp
v0.1.6
Published
GardWatch MCP server — dependency health checks for AI coding assistants
Maintainers
Readme
@gardera/gardwatch-mcp
An MCP server that lets AI coding assistants check dependencies for supply chain risks using GardWatch.
What it does
gardwatch_scan— Scans lockfiles for malicious or suspicious packages. Runs automatically after dependency changes.gardwatch_check_package— Checks a single package before installing it. Blocks critical packages, warns on suspicious ones.
Supports: package-lock.json, yarn.lock, pnpm-lock.yaml, Pipfile.lock, poetry.lock, Cargo.lock, go.sum
Setup
Claude Code (recommended)
One command sets up everything: OAuth login, local lockfile parsing, and automatic scanning:
npx @gardera/gardwatch-mcp setup-claudeThen run /mcp in Claude Code and complete the browser login. After that, every package manager command automatically triggers a dependency scan. Lockfiles are parsed locally; only package identifiers are sent to Gardera.
Other AI assistants
Add to your MCP configuration with an API key:
{
"mcpServers": {
"gardera-gardwatch": {
"command": "npx",
"args": ["-y", "@gardera/gardwatch-mcp"],
"env": {
"GARDERA_API_KEY": "your-api-key"
}
}
}
}Get an API key at app.gardera.io.
| Assistant | Config file |
|-----------|------------|
| Cursor | ~/.cursor/mcp.json |
| Windsurf | ~/.codeium/windsurf/mcp_config.json |
| Cline | .cline/mcp_settings.json |
Or use the Gardera VS Code extension to configure it automatically.
How it works
- AI assistant installs a package → lockfile is parsed → package identifiers are sent to the GardWatch API → trust scores are returned
- Packages scoring below threshold are flagged as CRITICAL or SUSPICIOUS
- The AI warns you before proceeding
