Sato Hub
Security Tool

Socket

Dependency and package analysis from Socket, with a CLI and an MCP server that returns package scores to an AI assistant.

ActiveUnverified

No code activity tracked

Listed from socket.dev on 2026-10-08. Install: not attempted — no install path on record. Not checked by Sato Hub yet: every row below is as listed. Evidence →

Next step

Watch Socket

One email if what we observe changes — its repo goes quiet or disappears, or the listing is retired. Nothing else.

Check it from your agent

Add Sato Hub’s MCP server (no key), then ask:

https://satohub.ai/api/mcp
Run Sato Hub Preflight on socketdev/socket-cli before I use it.
Full setup: Claude Code, Cursor, others →

Your project?

Prove you control the domain and correct this page — description, links, tags, chains. A claim proves control, not verification: it never changes the Sato Score.

Claim this listing →

Overview

Socket analyses open-source packages across npm, PyPI, Cargo, Maven, NuGet, RubyGems, Go and other ecosystems. Its MCP server (SocketDev/socket-mcp, npm @socketsecurity/mcp, MIT) lets an assistant score a package or audit a package.json in conversation, hosted at mcp.socket.dev or run locally; the CLI is @socketsecurity/cli (MIT). For an agent builder it is a pre-install look at the npm and PyPI dependencies a project pulls in. It reads package metadata and code signals; it does not assess what a crypto agent does with keys or funds. The platform is a commercial service, the CLI and MCP server are open source.

Evidence — listed vs checked · what the words mean

Listed from socket.dev on 2026-10-08. Install: not attempted — no install path on record. Not checked by Sato Hub yet: every row below is as listed.

ClaimValueEvidenceSourceChecked
Chains supportednot statedself-reporteddocs.socket.devas of 2026-10-08
Verification statusUnverified — not independently reviewedself-reportedsocket.devas of 2026-10-08

Self-reported rows are the project’s own words, dated when we recorded them — not a check. Only reproduced and reviewed rows carry a mark. None of these rows is a safety or quality rating.

Details

Chains
Unknown
Agent types
Dependency Analysis, Developer Tool
Open source
Partial
Deploys as
npm, mcp server, hosted
Last checked
2026-10-08

Marketplace Signals

No marketplace signals recorded for this resource yet.

Verification status reflects evidence reviewed by Sato Hub. Self-reported claims are never presented as verified.

#dependency-analysis#supply-chain#npm#pypi#package-scores#mcp#cli
See something inaccurate or outdated?Submit a correction →

Compared with

Appears in

Related Resources

Reference

QuestionsShowHide

Questions people ask about Socket

Is Socket open source?
Partly. Some of Socket is published as source (https://github.com/SocketDev/socket-cli) and some is not. Checked as of 2026-10-08.
Which chains does Socket support?
Sato Hub has no confirmed chain list for Socket as of 2026-10-08; treat chain support as unknown.
Is Socket still maintained?
Sato Hub tracks no commit or release for Socket; it cannot say whether it is maintained.
How do I install or run Socket?
Sato Hub has no deploy spec for Socket; follow the project's own documentation at https://docs.socket.dev.
Is Socket verified on Sato Hub?
No independent verification is on record for Socket; its verification status is "Unverified". Self-reported is not verified, and the score is not a safety, quality or returns grade.
Cite this pageShowHide

Cite this page

Sato Hub. "Socket — Sato Hub." Sato Hub, updated 2026-10-08, accessed 2026-10-08. https://satohub.ai/resources/socket

Data last refreshed 2026-10-08; this page is rebuilt daily. Citations carry the date so a reader can tell which snapshot a claim came from. Catalog data is licensed CC-BY-4.0.

Join the Sato Hub Briefing

Sign up for the Briefing: the agents, tools, and infrastructure that actually shipped, and why they matter.