Retrieve Python package metadata from PyPI, including version, license, and Python compatibility. Use to evaluate library maintenance and compatibility before integration.
Look up one exact PyPI package, current version, license, Python requirements and recent releases. maxItems caps releases and dependency strings at 50. No maintainers, contacts, long description, package downloads or PyPI search crawl. Price: $0.01 USDC per successful call on Base. Requires an x402-capable wallet client.
Compare two published npm or PyPI versions to reveal registry metadata changes—including yanks, exports, module format, and licenses—so you can assess an upgrade before committing.
A security-focused MCP server that enables AI assistants to search PyPI packages, scan for vulnerabilities, audit dependencies, and ensure security across Python projects.
Fetch the SPDX licence identifier for an open source package version to verify licence compatibility before adding a dependency. Supports PyPI, npm, Maven, Go, Cargo, NuGet, and RubyGems.
Check developer laptops for any installs of a PyPI package to identify potential exposure. Searches all enrolled dev machines, returning all installs or filter by versions. Complements CI checks for comprehensive malicious package incident response.
Check whether a software package or infrastructure product version has known CVEs or supply chain compromises. Use this before adding, updating, or recommending dependencies.
Checks monitored GitHub repositories within an organization for usage of a specified PyPI package at given versions, identifying affected CI pipelines. Use with developer machine checks for full coverage.
Retrieve full details of a security threat incident, including compromised package names, versions, and C2 domains/IPs. After listing incidents, use this to extract concrete IOCs and determine which exposure checks to run based on the ecosystem (npm or pypi).
Scan a project's npm/PyPI dependencies to identify hallucinated packages, typosquats, suspiciously new releases, and known vulnerabilities for reliable supply chain security.
Retrieve PyPI package details: version, summary, license, runtime dependencies, release dates, and more. Verify Python package metadata before integrating into your projects.
Run a multi-source intelligence report by searching up to 18 platforms (HN, GitHub, npm, PyPI, X, Reddit, YouTube, and more) in parallel. Choose a focus preset—balanced (14 free APIs), trending, or comprehensive—or specify exact sources. Requires a query; returns structured JSON results.
Resolve fuzzy or partial package names into real, ranked candidates using live registry search for npm and Cargo, with clear guidance when PyPI search is unavailable.
Check if an exact package or runtime release works with another exact release, based on official dependency evidence, returning supported, unsupported, or unknown verdicts with sources.