# install_command

Canonical install command(s) across every package manager of the ecosystem (npm/pnpm/yarn/bun, pip/uv/poetry, cargo, go, composer, maven+gradle, nuget, …). USE WHEN: emitting an install line and you want correct flags. RETURNS: {primary, variants[]}.

Agent View of the PolicyLayer registry record for `install_command`. HTML page: https://policylayer.com/tools/dev-depscope-mcp/install-command

## Facts

- Tool: `install_command`
- Server: Depscope (`cuttalo/depscope-mcp`) — https://policylayer.com/tools/dev-depscope-mcp.md
- Homepage: https://github.com/cuttalo/depscope-mcp
- Risk category: Read (Low risk)
- Registry record: grade D, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 3 (2 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `package` | string | yes |  |
| `version` | string | no | Optional explicit version; defaults to latest. |
| `ecosystem` | string | yes |  |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "install_command",
    "arguments": {
      "package": "<package>",
      "ecosystem": "<ecosystem>"
    }
  }
}
```

## Why install_command is rated Low

This tool retrieves and returns the correct install command syntax for various package managers. It does not execute any commands, modify any data, or trigger any external operations. It is purely informational, generating text that a user or agent could then choose to run separately. The blast radius of misuse is very low since no action is taken automatically.

From the tool's own definition: "'Canonical install command(s) across every package manager' and 'RETURNS: {primary, variants[]}' — the tool returns formatted install command strings, it does not execute them"

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call install_command to retrieve information from Depscope without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Depscope:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "install_command": {}
  }
}
```

## Other tools on Depscope (21)

- `check_bulk` — Read — https://policylayer.com/tools/dev-depscope-mcp/check-bulk.md
- `check_compatibility` — Read — https://policylayer.com/tools/dev-depscope-mcp/check-compatibility.md
- `check_malicious` — Read — https://policylayer.com/tools/dev-depscope-mcp/check-malicious.md
- `check_package` — Read — https://policylayer.com/tools/dev-depscope-mcp/check-package.md
- `check_typosquat` — Read — https://policylayer.com/tools/dev-depscope-mcp/check-typosquat.md
- `compare_packages` — Read — https://policylayer.com/tools/dev-depscope-mcp/compare-packages.md
- `find_alternatives` — Read — https://policylayer.com/tools/dev-depscope-mcp/find-alternatives.md
- `get_breaking_changes` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-breaking-changes.md
- `get_health_score` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-health-score.md
- `get_known_bugs` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-known-bugs.md
- `get_latest_version` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-latest-version.md
- `get_migration_path` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-migration-path.md
- `get_package_prompt` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-package-prompt.md
- `get_trending` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-trending.md
- `get_trust_signals` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-trust-signals.md
- `get_vulnerabilities` — Read — https://policylayer.com/tools/dev-depscope-mcp/get-vulnerabilities.md
- `package_exists` — Read — https://policylayer.com/tools/dev-depscope-mcp/package-exists.md
- `resolve_error` — Read — https://policylayer.com/tools/dev-depscope-mcp/resolve-error.md
- `scan_project` — Read — https://policylayer.com/tools/dev-depscope-mcp/scan-project.md
- `contact_depscope` — Write — https://policylayer.com/tools/dev-depscope-mcp/contact-depscope.md
- `pin_safe` — Write — https://policylayer.com/tools/dev-depscope-mcp/pin-safe.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-depscope-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-depscope-mcp
