scan_package
Scan npm MCP server packages for security risks like backdoors, dangerous code, and supply chain vulnerabilities. Download and analyze packages to generate detailed security reports with severity ratings before installation.
Instructions
Download an npm MCP server package and scan it for backdoors, exfiltration code, obfuscation, dangerous code execution, and supply chain risks. Returns a full security report with severity ratings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package_name | Yes | npm package name (e.g. 'some-mcp-server') | |
| version | No | Specific version to scan (defaults to latest) |