MCP serverio.github.salemalem/npmscan
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Overview
Score?
UNRATED 0.824
of what a free look can see, on 32 looks
Looks
35
last 13 hr ago
Tools
23
changed 13 hr ago
More info
URL
npmscan.com/api/mcp
streamable-http
Says it is
npmscan 3.0.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.824 · highest on record 0.8561
Toolsfrom sha256:5b4b70d16f…e0b9fc · +0 −0 13 hr ago
| Tool | Schema |
|---|---|
| analyze_install_script Statically scans a package's preinstall/install/postinstall/prepare lifecycle scripts AND the file(s) they reference — fetched directly from the published tarball, not just the com |
input · output |
| analyze_transitive_dependencies Recursively resolves one or more direct/root packages' dependency graphs — e.g. the "dependencies" section of a package.json — up to maxDepth levels deep (default 2, max 3) and bat |
input · output |
| audit_github_repository Given a GitHub repository URL, fetches its package.json (and, if present, a pnpm-lock.yaml/package-lock.json/yarn.lock — first one found wins, in that priority order) straight from |
input · output |
| batch_query_vulnerabilities Query OSV.dev for known vulnerabilities across a whole npm dependency inventory at once: either pass a flat {packages:[...]} list, or paste raw package.json / lockfile / CycloneDX |
input · output |
| check_license_compliance Given a list of packages (name + optional exact version or semver range — e.g. straight from a package.json "dependencies" object) and an optional allow/deny license policy, resolv |
input · output |
| check_maintainer_blast_radius Given an npm username, lists the packages npm's maintainer:<username> search index returns for that account and looks for a tight cluster of packages whose latest version was publi |
input · output |
| check_maintainer_changes Reconstructs a package's maintainer-change history straight from the npm packument — every published version carries the maintainers-list SNAPSHOT as it stood at that publish plus |
input · output |
| check_package_provenance Checks whether a package version was published with npm's own Sigstore-backed publish provenance (`npm publish --provenance`), and cross-checks that provenance against reality rath |
input · output |
| compare_packages Given 2-5 candidate packages for the same job (e.g. "axios vs got vs node-fetch"), fetches the same registry/popularity/maintenance/vulnerability enrichment get_package computes fo |
input · output |
| diff_dependencies Compares two raw snapshots of a package.json, package-lock.json (npm v1-v3), yarn.lock (classic v1 or Berry), or pnpm-lock.yaml — e.g. before/after a PR — and reports which package |
input · output |
| enrich_npm_audit Given the raw output of `npm audit --json` (npm 7+'s `{vulnerabilities: {...}}` format, or legacy npm 6's `{advisories: {...}}`), parses it directly — no need to re-paste package.j |
input · output |
| generate_sbom Given the same inputs batch_query_vulnerabilities accepts — either a flat {packages:[...]} list, or raw package.json / lockfile / CycloneDX JSON / SPDX JSON content via `content` — |
input · output |
| get_cve Look up authoritative NIST NVD data for one exact CVE ID (e.g. "CVE-2026-2950"), or browse/search NVD by keyword, CVSS severity, CWE, or a publication-date range. Every result is e |
input · output |
| get_latest_advisories Browse recently published npm security advisories and known-malicious-package findings. Three disjoint sources, selected via type: "reviewed" (default) is GitHub's curated, mostly |
input · output |
| get_maintainer_profile Given an npm username, returns every package npm's own maintainer:<username> search index currently returns for that account (registry.npmjs.org's /-/v1/search — the public registr |
input · output |
| get_package Fetch npm registry metadata for a package: latest version, install scripts (preinstall/postinstall are a key risk signal), maintainers, license, recent version history, weekly down |
input · output |
| get_package_version Fetch registry metadata for one exact version of a package (dependencies, install scripts, tarball) AND check that exact version against OSV.dev for known vulnerabilities — isVulne |
input · output |
| get_remediation_playbook Maps a finding's `rule` value from analyze_install_script, check_maintainer_changes, or check_package_provenance to the matching human-authored incident-response playbook (the same |
input · output |
| prioritize_remediation Given a batch of vulnerability findings already flagged elsewhere (e.g. from batch_query_vulnerabilities, analyze_transitive_dependencies, or query_vulnerabilities across a whole p |
input · output |
| query_vulnerabilities Query OSV.dev for known vulnerabilities affecting an npm package, optionally scoped to one exact version (e.g. to check whether a version pinned in a lockfile is safe). Returns isV |
input · output |
| search_packages Search the npm registry by name or keywords. Each result includes its current weekly/monthly download counts, dependentsCount (how many other npm packages depend on it), topPackage |
input · output |
| simulate_dependency_upgrade Given a package and a current/target version, tells you whether that specific upgrade is a safe patch/minor bump or a likely-breaking major bump, before you actually run npm instal |
input · output |
| suggest_alternative Given a package that looks deprecated, vulnerable, abandoned, or suspicious, suggest better-maintained alternatives in the same category. This tool first checks the source package' |
input · output |
Verify it yourself
npx teppi-check https://npmscan.com/api/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2N0CWP29Q0Z51F36AJ2P