Check MCP server packages (npm/PyPI)
check_supply_chainAudit npm and PyPI packages for npx/uvx MCP servers via registries and OSV to detect vulnerabilities, malicious releases, typosquats, install scripts, and deprecation or publisher changes.
Instructions
For servers launched with npx/uvx and similar, checks the package on its registry and in the OSV database: known vulnerabilities, known malicious versions, typosquats of popular MCP packages, non-existent names, very new packages or releases, install scripts, deprecation and npm publisher changes. Sends package names and versions to registry.npmjs.org, pypi.org and api.osv.dev; nothing else leaves the machine.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| servers | No | Server names, or ["*"] for all. | |
| project_dir | No | ||
| scan_images | No | Also scan container images of Docker-based servers with Trivy or Grype if installed (may pull images and the scanner database). | |
| confirm_network | Yes | Must be true: package names and versions are sent to the registries and OSV. |