Pod

Yes, this is on purpose. Pod is built for agents, so the default page is plain HTML.
Human? View the normal website.
Agent? You probably prefer /mcp/hound/issues.md or /mcp/hound/issues.json, or Pod over MCP.

Reported issues for hound

Pod holds 19 of 27 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.

Back to hound.

Most discussed

Add JSDoc comments to API client functions

Summary

Add JSDoc documentation comments to all exported functions in the API client files (src/api/depsdev.ts and src/api/osv.ts).

Why

Good documentation helps new contributors understand the codebase. JSDoc comments:

Implementation

Add JSDoc comments following this pattern:

/**
 * Fetch package

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/66) · 2026-05-23 · open · 6 comments

### Add `composer.lock` parser for PHP projects

## Summary

Add support for parsing `composer.lock` files from PHP projects that use [Composer](https://getcomposer.org/) for dependency management.

## Why

Composer is the standard package manager for PHP. Adding `composer.lock` support enables vulnerability scanning for PHP/Laravel/Symfony projects.

## Implementation

1. Add `parseComposerLock()` function in `src/parsers/index.ts`
2. Add ecosystem `"packagist"` to the `ParsedDep` type (Composer uses Packagist registry)
3. Add dispatch in `pa

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/60) · 2026-05-23 · closed · 6 comments

### Add double-character typos to typosquat detection

## Summary

Enhance the \`hound_typosquat\` tool to detect double-character typos, such as:
- \`lodash\` → \`llodash\` (doubled first letter)
- \`lodash\` → \`loddash\` (doubled middle letter)
- \`express\` → \`expresss\` (doubled last letter)

## Why

Accidentally holding a key too long is a common typing mistake. Attackers exploit this by registering packages like \`expresss\` or \`llodash\`.

## Implementation

Edit the \`generateTypos()\` function in \`src/tools/typosquat.ts\`:

\`\`\`typesc

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/68) · 2026-05-23 · closed · 5 comments

### Add `gradle.lockfile` parser

### What problem does this solve?

Adds support for Gradle (Java/Android) ecosystem

### Proposed solution

New parser for `gradle.lockfile`

### Type of request

New lockfile parser

### Compatibility check

- [x] This does not require an API key or account
- [x] This does not require a paid service

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/33) · 2026-03-14 · closed · 5 comments

### MCP tools should not be named with prefix `hound`

### What happened?

Most MCP clients already prefix tools with the MCP server name. Just a UX thing, but it would be prefered if the tools do not come with `hound_` already prefixed to it.

### What did you expect?

Tool names should not have the `hound_` prefix.
For example `hound_audit` should be just `audit`

### Steps to reproduce

1. Install MCP in the cursor
2. Call any tool
3. Tool name comes with hound prefixed twice

### Which tool?

Not tool-specific / general

### Node.js version

NA

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/9) · 2026-03-11 · open · 5 comments

### Add example lockfiles for Python, Rust, and Go ecosystems

## Summary

Add example projects with lockfiles for Python, Rust, and Go ecosystems to help users understand how to use Hound with different languages.

## Why

Currently, the `examples/` folder only has npm examples (`examples/audit-npm-project/`). Adding examples for other ecosystems:
- Helps users see Hound in action with their preferred language
- Provides test fixtures for manual testing
- Improves documentation

## Implementation

Create the following example directories:

### 1. Python (r

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/65) · 2026-05-23 · open · 4 comments

### Add `pubspec.lock` parser for Dart/Flutter projects

## Summary

Add support for parsing `pubspec.lock` files from Dart/Flutter projects.

## Why

Flutter is extremely popular for mobile app development. Adding `pubspec.lock` support enables vulnerability scanning for the Dart/Flutter ecosystem.

## Implementation

1. Add `parsePubspecLock()` function in `src/parsers/index.ts`
2. Add ecosystem `"pub"` to the `ParsedDep` type (Dart uses pub.dev registry)
3. Add dispatch in `parseLockfile()`:
   ```typescript
   if (base === "pubspec.lock") return p

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/62) · 2026-05-23 · closed · 4 comments

### Add `bun.lockb` parser

### What problem does this solve?

Extends functionality with also support for bun ecosystem

### Proposed solution

New parser for `bun.lockb`

### Type of request

New lockfile parser

### Compatibility check

- [x] This does not require an API key or account
- [x] This does not require a paid service

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/32) · 2026-03-14 · closed · 4 comments

## Most recent

### Docs: add a "How to add a lockfile parser" checklist

Nearly every parser PR misses a step (tests, or the tool descriptions, or the ecosystem enum), costing a review round-trip each time. A short checklist would prevent it.

Add a "Adding a lockfile parser" section to `CONTRIBUTING.md` (or `CLAUDE.md`) covering:
1. `parseXxx()` in `src/parsers/index.ts` + dispatch in `parseLockfile()`.
2. Add the ecosystem to `src/constants/ecosystems.ts` if new.
3. Update the supported-format strings/descriptions in `src/tools/audit.ts` and `src/tools/license-chec

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/95) · 2026-07-03 · closed · 2 comments

### Add `packages.lock.json` parser for NuGet/.NET projects

We support npm, pip/poetry/pipenv, Cargo, Go, RubyGems, and Dart — but not NuGet (.NET), a major ecosystem. Both OSV (`NuGet`) and deps.dev (`nuget`) support it.

`packages.lock.json` is JSON: `dependencies` → per-target-framework map of `{ "<name>": { "resolved": "<version>" } }`.

**Acceptance**
- `parseNuGetLock()` added and dispatched for `packages.lock.json`, ecosystem `nuget`.
- `nuget` present in `src/constants/ecosystems.ts` (`ECOSYSTEM_VALUES`).
- Added to the supported-format strings i

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/94) · 2026-07-03 · closed · 0 comments

### Single source of truth for supported lockfile formats

The supported-lockfile list is duplicated across the dispatch in `src/parsers/index.ts` and the tool descriptions + "unsupported format" error strings in `src/tools/audit.ts` and `src/tools/license-check.ts`. They drift — several recent parser PRs added a parser but forgot to update the descriptions, so the tools advertised the wrong set.

**Proposal:** derive the supported-format list from one exported constant/registry and build the descriptions + error messages from it.

**Acceptance**
- One 

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/93) · 2026-07-03 · open · 0 comments

### Refactor: split `src/parsers/index.ts` into per-format modules

`src/parsers/index.ts` now holds ~10 lockfile parsers (package-lock, yarn, pnpm, requirements, Cargo, go.sum, Gemfile, pubspec, Pipfile, poetry) plus the `parseLockfile()` dispatch — all in one file. Every new parser PR piles into it, causing repeated merge conflicts.

**Proposal:** move each parser into `src/parsers/<format>.ts` and keep `parseLockfile()` as a thin dispatcher (a small registry mapping basename → parser fn). No behaviour change.

**Acceptance**
- Each parser in its own file unde

[Read the thread](https://github.com/tiluckdave/hound-mcp/issues/92) · 2026-07-03 · open · 1 comment

### Improve error message when lockfile format is unrecognized

## Summary

When a user provides an unsupported lockfile name, the error message should be more helpful by suggesting similar supported formats.

## Current Behavior

Unsupported lockfile format: package.json

Supported formats: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, Cargo.lock, go.sum


## Desired Behavior

Unsupported lockfile format: package.json

Did you mean: package-lock.json?

Supported formats: • package-lock.json (npm) • yarn.lock (npm/Yarn) • p

Read the thread · 2026-05-23 · closed · 3 comments

Add unit tests for generateTypos() function

Summary

Add dedicated unit tests for the generateTypos() helper function in src/tools/typosquat.ts.

Why

The generateTypos() function is a critical piece of the typosquat detection logic, but it's only tested indirectly through the tool handler. Direct unit tests would:

Current State

The existing tests in tests/tools/typosquat.test.ts mock the

Read the thread · 2026-05-23 · closed · 2 comments

Add character substitution (leet-speak) to typosquat detection

Summary

Enhance the hound_typosquat tool to detect character substitution attacks (leet-speak), such as:

Why

Character substitution is a common typosquatting technique that the current implementation doesn't detect. Attackers publish packages like 1odash hoping developers mistype the package name.

Implementation

Edit the `gene

Read the thread · 2026-05-23 · closed · 2 comments

Add retry with exponential backoff to API clients

What problem does this solve?

Both API clients make a single attempt and fail immediately. A transient 429 or 503 from deps.dev/OSV kills the whole tool response.

Proposed solution

Failed requests retry up to 2 times with exponential backoff (100ms, 400ms). Retry-After headers are honored. Add tests with mocked failures.

Type of request

Performance improvement

Compatibility check

Read the thread · 2026-03-18 · closed · 3 comments

Inconsistent default version fallback across tools

What happened?

hound_compare and hound_preinstall pick versions[versions.length - 1] (last), but hound_popular picks versions[0] (first). If the API changes sort order, one of these silently breaks.

What did you expect?

A shared getDefaultVersion(versions) utility is used by all three tools. Add a unit test for the helper.

Steps to reproduce

NA

Which tool?

Not tool-specific / general

Node.js version

NA

hound-mcp version

NA

MCP client

Other

Relevant l

Read the thread · 2026-03-18 · closed · 0 comments

Add integration test that all 12 tools are registered

What problem does this solve?

If someone creates a tool but forgets to call register() in server.ts, it silently doesn't exist. No test catches this.

Proposed solution

Create tests/server.test.ts Test creates a server via createServer(), lists registered tools, and asserts all 12 expected tool names are present.

Type of request

Other

Compatibility check

Read the thread · 2026-03-18 · closed · 2 comments

Add Gemfile.lock parser

What problem does this solve?

rubygems is listed as a supported ecosystem, but there's no lockfile parser for it. hound_audit can't scan Ruby projects.

Proposed solution

parseLockfile("Gemfile.lock", content) returns parsed deps with ecosystem: "rubygems". Add tests.

Type of request

New lockfile parser

Compatibility check

Read the thread · 2026-03-18 · closed · 0 comments

The remaining reports are on the project's issue tracker.