What’s New

Coding agents now handle dependency work on data science and AI projects. You describe what the project needs, and the agent picks packages, pins versions, and runs the installer.

The agent makes those choices without access to the facts required: which packages exist in conda, which versions solve together, which ones carry open vulnerabilities, and which channels your organization has approved. It fills the gap from training data. A script imports cv2, and the agent tries to install cv2 instead of opencv. It pulls from conda-forge when your organization allows only main. You end up checking the dependency work by hand, or you find the problem later in a failed build or an audit.

Invented package names are a documented problem. A peer reviewed document presented at USENIX Security 2025 found that across 16 code-generating models, 19.7% of the packages those models suggested did not exist. When they reran prompts that had produced a fake name, 43% of those came back in all 10 attempts. The study covered PyPI and npm, using models from early 2024. Names that repeat are names an attacker can predict and register.

In January 2026, Aikido Security researcher Charlie Eriksen found that an LLM had merged two real npm packages, jscodeshift and react-codemod, into a package that didn’t exist, react-codeshift, and wrote it into a batch of generated agent skills. By the time Eriksen registered the empty name himself, 237 GitHub repositories were telling agents to install it, and agents kept downloading it afterward. This particular one and similar supply-chain attacks against coding agents were reported in CSO Online in May.

Anaconda MCP is now generally available

Our remote Model Context Protocol (MCP) server gives your agent four read-only tools:

  • package facts and dependencies
  • curated Common Vulnerabilities and Exposures (CVE) data and versions with fixes
  • your organization’s channel and policy configuration
  • community forum search capabilities

Your agent still does the work, but it checks the package facts, vulnerabilities, and policy before it chooses. Anaconda builds and maintains ~20,000 conda packages across our main and main-x channels and curates their vulnerability data. You authenticate once, and it works with the agent you already use, like Kilo by Anaconda.

Enkrypt AI, now part of Anaconda, researches security risks in MCP servers. In two months, the team scanned 268,000+ tools across 25,000 MCP servers and found 143,000+ vulnerabilities, affecting 73% of those servers. Before launch, the same team scanned Anaconda MCP. The scan found no vulnerabilities.

What changed since the beta

During the beta, the tool ran locally and took actions on your machine. Anaconda MCP now runs remotely and only returns data. When an environment needs to change, your agent runs conda, following the permission settings you’ve configured for it. The server can’t install, delete, or modify anything on your machine.

No local package to install or upgrade. The server runs at https://anaconda.com/api/mcp, and updates take effect there. You can connect to it via the Anaconda CLI, Kilo Marketplace if you use Kilo, or by adding the server address to your agent’s MCP configuration.

If you installed the beta, we recommend removing the anaconda-mcp package from your machine.

Let’s Dig Deeper

Getting authenticated

Every tool requires authentication. Sign in to your account on anaconda.com. The server identifies your organization from your account. If you don’t belong to an organization, tools return results without policy information.

Anaconda Intelligence Skill

Anaconda Intelligence is a free agent Skill that ships with the server. It works with any MCP client that supports remote servers, including Kilo, Claude Code, Cursor and Codex. It tells your agent which tool to call and when, for example calling org_config at the start of a session. If you connect the server manually, add the skill text from our documentation.

package_info

Returns details for one named package: available versions, dependency constraints, supported platforms, build variants, download counts, and a CVE summary. Your agent can check a package before choosing it for a new project, or confirm dependencies and platform support for packages with GPU builds, such as PyTorch. Available on all plans. Without a Business or Enterprise plan, policy_status and policy_detail return null.

package_security

Returns vulnerability details for one exact package version: severity, status, the Common Vulnerability Scoring System (CVSS) vector, the Common Weakness Enumeration (CWE) category, an Anaconda analyst’s comment with the date it was curated, and a version that includes the fix, written as a conda MatchSpec your agent can use directly. Your agent can use it to compare packages that do similar things, or to fix an environment carrying vulnerabilities. Requires a Business or Enterprise subscription.

The response includes only active and reported vulnerabilities, short enough for your agent’s context window; cleared, disputed, and mitigated CVEs are excluded, and cleared_cve_count reports how many were cleared.

org_config

Returns your organization’s channels and policy configuration. When a package isn’t available, your agent can tell you which policy blocks it and what to ask your admin for. Requires a Business or Enterprise subscription; on other tiers the call returns no_subscription.

Each channel has at most one policy, and a channel with no policy (null) has no policy restrictions. These are policies set in Package Security Manager (PSM), not AI guardrail policies.

search_forum

Searches the Anaconda community forum by keyword and returns matching forum threads, workarounds, and discussions. Available on all tiers.

Why this matters

If you build with an agent. Your agent chooses packages with Anaconda’s data in hand: which packages exist in the channels you can use, what they depend on, and which have open critical vulnerabilities. You still review what it proposes. Your organization’s policy follows your work, so the agent picks from approved channels.

If you run the platform or own package policy. The US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA) and their Five Eyes partners have advised organizations to maintain trusted registries of approved third-party components and restrict agents to allow-listed tools and versions. If you manage Anaconda channels with policies in PSM, you already maintain that registry. Anaconda MCP lets your developers’ agents read it. The agent checks policy before it proposes a package. When a package is blocked, it tells the developer which policy applies and what to request from you.

What you need

Anaconda MCP runs at https://anaconda.com/api/mcp over streamable HTTP. It works with any MCP client that supports remote servers, including Kilo, Claude Code, Cursor, and Codex.

ToolAvailability
package_infoAll users with an Anaconda account
search_forumAll users with an Anaconda account
package_securityBusiness and Enterprise tiers
org_configBusiness and Enterprise tiers
Anaconda Intelligence SkillAll users with an Anaconda account

Policy fields reflect the channel policies your organization has set up in Package Security Manager.

Give it a shot

  • Use Kilo: Install Anaconda MCP and the Anaconda Intelligence Skill from the Kilo Marketplace (only inside VSCode and Jetbrains UI).
  • Use Anaconda CLI: Using your terminal, install anaconda CLI and run the setup wizard with: ana mcp setup, and follow the instructions
  • Ask your agent: Simply ask your agent to install the Anaconda MCP.

To confirm it’s working, ask your agent: “What versions of numpy are available?” or “What policies are applied to our channels?”

If something doesn’t work, open a request in the Anaconda Support Center.