scan_package
Scan a npm package for MCP security issues. Evaluates install scripts, prompt injection patterns, suspicious URLs, source code patterns, dependency count, metadata completeness, and publisher provenance. Returns a score (0-100), risk level, and detailed findings to identify potential threats.
Instructions
Scan an npm package for MCP security issues. Checks install scripts, prompt injection patterns, suspicious URLs, source code patterns, dependency count, metadata completeness, and publisher provenance. Returns score (0-100), risk level, and detailed findings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| npm | Yes | npm package name (e.g. 'exa-mcp-server', '@modelcontextprotocol/server-github') |