pkgproof
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PKGPROOF_BASE_PRIVATE_KEY | No | Throwaway EVM wallet holding USDC on Base, 0x-prefixed. Used when no Algorand key is set. | |
| PKGPROOF_ALGORAND_PRIVATE_KEY | No | Throwaway Algorand account holding USDC on Mainnet, base64. Preferred for payment when set. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| verify_packageA | Verify an npm package before installing it. Runs eight checks covering advisories, install scripts, typosquat and combosquat names, scope, repository provenance and maintainer reputation, and answers safe, caution, block or does_not_exist with every reason labelled as fact or heuristic against its source. One call is one verification: the first each day is free, and later ones cost $0.05 in USDC when a wallet is configured. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
Only one tool exists, so there is no possibility of confusion or overlap.
The single tool name 'verify_package' follows a clear verb_noun pattern.
While the server has a narrow focus, having only one tool feels thin; however, the tool is comprehensive and covers many verification aspects, so it is borderline acceptable.
The single tool appears to fully cover the intended domain of package verification, including security, provenance, and reputation checks, with no obvious missing functionality.