Skip to main content
Glama
59,754 servers. Last updated

Matching MCP tools:

Matching MCP Connectors:

"npm" matching MCP servers:

  • A
    license
    -
    quality
    C
    maintenance
    Audits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.
    Last updated
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Model Context Protocol server for npm registry. Enables searching packages, checking security, comparing versions, and validating compatibility.
    Last updated
    13
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A Model Context Protocol server providing utility tools for development and testing, offering functionalities like personalized greetings, random card drawing, and datetime formatting with an extensible architecture.
    Last updated
    4
    19
    450
    18
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    A Model Context Protocol server that enables AI-powered analysis of NPM packages through multiple tools for security vulnerability scanning, dependency analysis, package comparison, and quality assessment.
    Last updated
    19
    450
    18
    TypeScript
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Visual CVE audit dashboard for npm, Python, Go, and Rust projects. Scans your project manifests (package-lock.json, requirements.txt, go.sum, Cargo.lock) against OSV.dev live data, opens a browser dashboard for human review, then applies fixes only after explicit confirmation. Supports multi-service monorepos in one command.
    Last updated
    4
    31
    4
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
    Last updated
    9
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Automatically scans project dependencies (npm, Composer) for security vulnerabilities using the OSV.dev database, providing real-time alerts and detailed remediation guidance directly in your IDE.
    Last updated
    1
    8
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Lightweight Node.js dependency vulnerability audit tool with CLI and MCP Server modes. Supports npm/pnpm, full dependency chain tracing, remote GitHub repo auditing, and generates Markdown/HTML reports.
    Last updated
    1
    23
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Tenant-bound MCP server for agent spend authorization, policy guardrails, evidence, escrow settlement, and portable receipts. Works with Cursor and Claude Code via stdio; npm (@paybond/kit) and Python (paybond-kit).
    Last updated
    31
    996
    1
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.
    Last updated
    8
    155
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables local npm supply-chain inspection through tools for repository scanning, SBOM generation, dependency audit, and evidence reporting. Uses deterministic mock data and does not query live APIs.
    Last updated
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.
    Last updated
    2
    6
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time data from MITRE CWE and npm audit. It enables deep analysis of authentication, API security, and dependencies to provide structured findings and remediation steps.
    Last updated
    2
    6
    1
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Acts as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.
    Last updated
    7
    2
    4
    MIT