Presend dependency checks
Server Details
Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
- Repository
- presendapp/presend-source
- GitHub Stars
- 0
- Server Listing
- presend-mcp
TDQS
Scored across 5 tools
Each tool targets a distinct risk signal (maintainer changes, repo health, typosquatting, vulnerabilities), and supply_chain_check is an explicit aggregator whose description clarifies when to use it versus the individual tools. The aggregator-overlap is intentional and well-documented, though it introduces slight redundancy about when to call which.
All five tools follow the same noun_phrase_check convention (maintainer_change_check, repo_health_check, supply_chain_check, typosquat_check, vulnerability_check). The pattern is fully predictable.
Five tools is well-scoped for a dependency-risk server: four focused single-signal checks plus one combined verdict. Each tool clearly earns its place without bloat.
The surface covers the core pre-install risk workflow (existence, age, vulnerabilities, typosquatting, maintainer change, repo health) and offers an aggregated verdict. However, vulnerability_check references a cve_lookup tool that does not exist, a dead-end reference, and maintainer checks are npm-only, leaving minor gaps.
Available Tools
5 toolsmaintainer_change_checkARead-onlyIdempotentInspect
Publisher-change analysis is npm only. Also reports whether the package exists (found) and its age (first_published, package_age_days, new_package if first published less than 30 days ago), for npm and for PyPI; on PyPI only existence and age are available. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Package name, e.g. lodash | |
| ecosystem | Yes | npm (full analysis) or pypi (existence and age only). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes far beyond the annotations (which only cover read-only/idempotent/open-world safety). It discloses what is flagged (unseen human publisher after 180+ days inactivity within 365 days), what is deliberately reported but not flagged (trusted publishing, pre-release, established maintainers), the ecosystem-specific capability gap, and the key limitation that it does not detect hijacked existing accounts and is a heuristic for review, not proof.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
It is a dense, information-rich block where nearly every clause carries distinct behavioral meaning (flag rules, exceptions, limitations). The one weak spot is front-loading a scope caveat instead of the tool's primary action, but overall it is efficient rather than padded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description carries the full burden and does so well: it names the returned fields (found, first_published, package_age_days, new_package), explains the 30-day new-package threshold, the 180/365-day flag windows, and clearly scopes what is and is not detectable. An agent has everything needed to call and interpret it.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with only two parameters, and the ecosystem description in the schema already states 'npm (full analysis) or pypi (existence and age only)', which the description merely echoes. The description adds no syntax, format, or validation detail beyond the structured fields, so baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The tool's core function (publisher-change analysis for supply-chain risk) is clear, and it enumerates the specific signals it computes (publisher takeover, inactivity window, package age). However, the description opens with a scope limitation ('npm only') rather than a clean verb+resource statement, and it never names or distinguishes itself from plausible siblings like supply_chain_check or typosquat_check.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage context is implied through the ecosystem split ('npm (full analysis) or pypi (existence and age only)') and the described detection scenario, but there is no explicit 'use this when...' guidance and no alternatives named. An agent can infer applicability but is not routed against other security tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
repo_health_checkARead-onlyIdempotentInspect
Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.
| Name | Required | Description | Default |
|---|---|---|---|
| repo | Yes | GitHub repository in owner/name format, e.g. lodash/lodash. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint=false, so the safety profile is covered. The description adds valuable behavioral details beyond annotations: it lists the exact signals returned and states that missing or private repositories return found:false, which is not inferable from the annotations. No contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three compact sentences, each earning its place: the first enumerates outputs, the second states the intended use case, and the third handles scope and edge behavior. No filler or redundant phrasing; the most important information is front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only tool with a single well-documented parameter and no output schema, the description adequately substitutes for return-format documentation by naming all returned signals and the found:false edge case. The annotations cover safety, and the description covers behavior and usage completely.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already fully documents the single param 'repo' as a GitHub repository in owner/name format with the lodash/lodash example. The description merely repeats this format and adds no new semantic meaning beyond the schema, so the baseline of 3 for 100% schema coverage is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: it returns maintenance signals for a GitHub repository, enumerating exact data points such as stars, forks, open issues, license, flags, dates, and topics. It also differentiates itself from supply_chain_check by scope, making it clear this is the GitHub-only variant.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly says when to use the tool: to judge whether a dependency looks maintained or abandoned. It names the alternative supply_chain_check for npm/PyPI packages with unknown repos, and clarifies the GitHub-only constraint and the found:false result for missing/private repos. This gives agents clear routing guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
supply_chain_checkARead-onlyIdempotentInspect
Call this before installing or adding a package (npm install, pip install, a new entry in a manifest), especially one whose name you recalled or that a model suggested. One-call risk check: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. A package that does not exist on npm or PyPI gets overall_risk 'package_not_found': the name may be invented, do not install it. A package first published less than 30 days ago gets the 'new_package' flag and overall_risk 'review_recommended': new packages are where invented and look-alike names get registered, so confirm the name against the project's own documentation before installing (on PyPI the age is that of the oldest release still published; being new does not make a package malicious). Use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'.
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Package name to check. | |
| version | No | Exact version to check for known vulnerabilities. Optional: defaults to the latest published version (npm and PyPI). | |
| ecosystem | Yes | Package ecosystem, e.g. npm. maintainer-change-check only runs for npm. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With readOnlyHint/idempotentHint already covering the safety profile, the description still adds substantial behavior: it enumerates the possible overall_risk outcomes (package_not_found, review_recommended, incomplete, no_signals_found), the 30-day new_package threshold, the PyPI oldest-release nuance, and version_checked/version_source semantics for when a check could not run. It leaks some of its own vocabulary, but the agent gains a clear picture of failure modes and verdicts.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Well front-loaded: the call-to-action ('call this before installing...') opens the description. The prose is dense with load-bearing detail rather than filler, though the parenthetical on PyPI age and the 'being new does not make it malicious' caveat stretch the length beyond the essential triggers.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, yet the description documents the return contract in enough detail for an agent to act on it: what package_not_found implies (do not install), what new_package/review_recommended mean, and how a partial run surfaces as incomplete. Nothing needed to call or interpret the tool correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds real meaning beyond the schema by explaining how version is resolved (version_checked, version_source, latest fallback) and that maintainer_change_check only runs for npm. That is more than the schema's bare field descriptions offer.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('risk check') and resource (package supply chain) and explicitly defines itself as an aggregate of four named sibling tools (vulnerability_check, typosquat_check, maintainer_change_check, repo_health_check). An agent can distinguish it from the individual signal tools without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
States the trigger condition precisely ('before installing or adding a package... especially one whose name you recalled or that a model suggested') and names the alternative path ('Use the individual tools to investigate one signal'). It routes the agent between aggregate and per-signal usage without inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
typosquat_checkARead-onlyIdempotentInspect
Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Package name to check for likely typosquatting of a well-known package in the given ecosystem. | |
| ecosystem | Yes | Package ecosystem, e.g. npm or PyPI. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive behavior, so the bar is lower, yet the description still adds substantive behavior: an edit-distance threshold scaled to name length, a >=3-character matching cutoff, and a curated-list limitation warning that a clean result does not prove safety. It also discloses a negative scope (does not verify existence), which is exactly the kind of boundary an agent needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three sentences, each earning its place: the first is the call trigger, the second the mechanism, the third the caveat plus the hand-off to supply_chain_check. Front-loaded with the action, no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter, read-only lookup with no output schema, the description supplies everything an agent needs: when to call, how the check works, its precision limits, and where to go for the complementary existence check. Return-value semantics are implied ('a clean result does not prove a package is safe').
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% for both parameters, so the baseline is 3; the description earns a step above by naming the concrete ecosystems ('npm or PyPI') and framing the package parameter as the name to be fuzzy-matched in that ecosystem, which reinforces the pairing between the two required params.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource (checks whether a package name is a near-miss of a well-known package, i.e. typosquatting) and scopes it to npm or PyPI. It also explicitly demarcates itself from the sibling supply_chain_check, so an agent can route without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit trigger ('Call before installing a package whose name you typed or recalled'), a when-not edge case (names of 3 characters or fewer are not fuzzy-matched), and names the alternative tool for the adjacent question (existence) via supply_chain_check. Nothing is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
vulnerability_checkARead-onlyIdempotentInspect
Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Package name to check against OSV.dev for known CVEs. | |
| version | No | Omit to check all versions of the package. | |
| ecosystem | Yes | Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, openWorldHint=true, idempotentHint=true, and destructiveHint=false, so the safety profile is covered. The description adds valuable behavioral context beyond annotations by naming the external data source (OSV.dev) and clarifying that it checks for known vulnerabilities, which sets expectations about external dependency and scope. It does not mention return format or rate limits, but that is not critical given the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with zero filler. The first sentence front-loads the core function and scope, and the second sentence provides routing to alternatives. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only query tool with three well-documented parameters and safety annotations, the description is nearly complete. It covers purpose, supported ecosystems, optional version behavior, and alternatives. The only minor gap is that it does not hint at the return value shape (e.g., list of CVEs or severity), but that is not essential for correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the input schema already documents all three parameters (package, version, ecosystem) with clear descriptions. The description adds minimal extra meaning beyond the schema, mostly restating the optional version behavior and listing ecosystem examples. Baseline 3 is appropriate because the schema carries the semantic load.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Checks'), a clear resource ('a package against OSV.dev'), and the exact scope ('known vulnerabilities') with an explicit list of supported ecosystems. It also names sibling tools (cve_lookup, supply_chain_check) to distinguish itself, so an agent can tell them apart immediately.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly tells the agent when to use this tool versus alternatives: 'Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.' This is direct routing guidance with no ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
5 tool updates
- First observed
maintainer_change_check - First observed
repo_health_check - First observed
supply_chain_check - First observed
typosquat_check - First observed
vulnerability_check
Related MCP Connectors
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables AI coding agents to automatically verify npm packages against the live registry before installation, flagging hallucinated, slopsquatted, or otherwise suspicious packages with risk verdicts.6 npmMIT
- AlicenseAqualityAmaintenanceEnables AI coding agents and CI to vet npm dependencies before they reach the lockfile, flagging hallucinated, slopsquatted, or otherwise risky packages with evidence-backed verdicts.368 npm4MIT
- AlicenseAqualityFmaintenanceDependency security & health auditing for AI agents with no account or API key required.22MIT
- AlicenseNot gradedqualityCmaintenanceValidates and checks packages across 19 ecosystems to prevent AI agents from installing hallucinated, deprecated, or malicious packages.63 npmAGPL 3.0
Glama MCP Gateway
Add one secure layer between your agents and this server.