package-risk MCP connector
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@package-risk MCP connectorCheck the risk and advisories for the Python package 'requests' before I add it."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
package-risk MCP connector
MCP tools for checking a package's maintenance status, licence, and security
advisories before you depend on it - package_risk, package_licence,
package_advisories. Paid per call in USDC on Base mainnet via x402.
No subscription, no API key. You pay from your own wallet, per call, only for what you use.
What this is (and isn't)
This is a thin client. The actual service is a stateless HTTP API at
x402-package-risk.x402-package-risk.workers.dev. This connector never sees,
holds, or forwards anyone else's funds - it only ever spends the wallet key
you configure below, and only when you call one of its tools.
Related MCP server: gatefareio/mcp-server
Setup
You need an EVM wallet with a small amount of USDC on Base mainnet (calls cost $0.005-$0.01 each). Never use a wallet holding significant funds for an automated agent key - keep this one funded lightly.
Add to your MCP client config (Claude Desktop, Claude Code, Cursor, etc.):
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": ["-y", "@makosdav/package-risk-mcp"],
"env": {
"EVM_PRIVATE_KEY": "0xyour-private-key-here"
}
}
}
}Tools
Tool | Price | What it returns |
| $0.01 | Full verdict: maintenance, licence, advisories, deprecation |
| $0.005 | Licence expression and closed-source safety |
| $0.005 | Open OSV advisories for the resolved version |
All three take system (npm/pypi/go/maven/cargo/nuget), name, and an
optional version.
How payment works
Your agent calls a tool.
This connector requests the resource; the server replies
402 Payment Required.@x402/fetchbuilds and signs a payment authorisation with your key.The request retries with payment attached; the server verifies via Coinbase CDP, returns the result, and settles on-chain.
No approval prompt happens here beyond what your MCP client itself asks for - if you want per-call confirmation, configure that in your agent framework, not here.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceMCP server for pay-per-call DeFi and crypto data via x402 micropayments on Base. 8 endpoints: token prices, TVL, funding rates, token security, gas tracker, whale monitoring, wallet profiling, and yield scanning.846MIT

gatefareio/mcp-serverofficial
Alicense-qualityBmaintenanceMarketplace MCP for paid HTTP APIs. Pay per call in USDC on Base via the open x402 standard — non-custodial. 13 tools for discovery, buying, and publishing APIs.512MIT- AlicenseAqualityDmaintenanceThe x402 ecosystem's read MCP for Base. Verify on-chain USDC settlements, parse publisher manifests, and audit x402 payment receipts from any MCP-compatible AI agent.112112MIT
- Alicense-qualityCmaintenanceMCP server that provides AI agents with pay-per-call access to a suite of tools (honeypot check, token market, DeFi yields, etc.) via USDC on Base using the x402 protocol.23MIT
Related MCP Connectors
Check a Base contract, transaction or web page before you act. Free pricing, paid per call in USDC.
Monetize any MCP server: x402 paywall, pay-per-call billing in USDC on Base, agent marketplace.
Reputation oracle for AI agents on Base: SAFE/CAUTION/BLOCK + 0-100 score before you pay. x402+MCP
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/makosdDavid/package-risk-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server