
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
dendro-react-mcp
Advanced tools
MCP server for React and React Native codebase analysis — 34 free tools: component trees, per-component complexity, prop flow, rerender risk (React Compiler aware), navigation graphs (Expo Router / Next.js / Remix / React Navigation), context maps, live r
The standalone MCP server from Dendro React — 34 free tools that give AI agents deep visibility into React and React Native codebases. Analysis runs locally; your code never leaves your machine.
Add to your MCP client config (Claude Code, Cursor, etc.):
{
"mcpServers": {
"dendro-react": {
"command": "npx",
"args": ["-y", "dendro-react-mcp"]
}
}
}
The server treats its working directory as the workspace root. To point it elsewhere (or to
restrict file access explicitly), set the DENDRO_WORKSPACE_ROOT environment variable.
First call to make: get_usage_guide — returns the full tool index, sequencing rules, and the
running build's version stamp.
open_visualizer, visualize_*) and sidebar features light up when the
Dendro React VS Code extension is installed and running; every analysis tool works standalone.MIT © Rooney Industries LLC
FAQs
React codebase semantics for AI agents — component contracts, blast radius, rerender risk, effect hygiene, navigation graphs, health audits — plus a VS Code visualizer you both share. Free, local-only.
The npm package dendro-react-mcp receives a total of 48 weekly downloads. As such, dendro-react-mcp popularity was classified as not popular.
We found that dendro-react-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.