Skip to main content
Glama
97,619 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

  • A
    license
    Not graded
    quality
    C
    maintenance
    Audits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for searching, inspecting, and evaluating NPM packages through health scoring and license risk assessments. It provides comprehensive package analysis including maintenance status, popularity trends, and security vulnerability reports to help users make informed dependency decisions.
    3
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI-powered JavaScript package management including search, install, update, remove, and security auditing across npm, yarn, and pnpm.
    546 npm
    9
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server providing npm registry search, package details, dependency auditing, bundle size estimation, and package comparison tools for AI agents.
    5
    43 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    A Model Context Protocol server that enables AI-powered analysis of NPM packages through multiple tools for security vulnerability scanning, dependency analysis, package comparison, and quality assessment.
    19
    710 npm
    18
    TypeScript
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables MCP-compatible AI applications to perform read-only npm package and project dependency safety scans, returning proceed, caution, or block verdicts without executing package code.
    63 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables auditing package.json files for real npm supply-chain attack mechanisms — typosquatted dependency names, malicious preinstall/install/postinstall scripts that pipe downloads into a shell or decode base64 payloads, and unpinned versions — plus live npm registry lookups that flag nonexistent, brand-new, deprecated, or typosquatted packages. It exposes dedicated tools for full manifest audits and single-name typosquat checks.
    MIT
  • F
    license
    Not graded
    quality
    Not graded
    maintenance
    Provides comprehensive Python code refactoring capabilities including AST-based analysis, automated refactoring, and performance optimization through the Model Context Protocol.
    -