Skip to main content
Glama
649,985 tools. Updated 2026-10-10 18:03

"pnpm" matching MCP tools:

  • Scan a project directory with Syft to generate a Software Bill of Materials (SBOM). Get an inventory of all software components and dependencies for compliance and vulnerability scanning.
    MIT No Attribution
  • Scan project lockfiles for OSV.dev vulnerabilities, including transitive dependencies, with fix versions and where each is pinned. Check security, CVEs, or a single package before adding a dependency.
    Apache 2.0
  • Search Forge's stored patterns to find previously learned conventions, failure modes, and successful approaches for project guidance and debugging.
    MIT
  • Scan project dependencies to identify licenses and validate them against a policy file, flagging disallowed or unknown licenses for compliance checks before releases or when adding new packages.
    MIT
  • Save learned patterns like test commands and failure diagnostics to persistent memory for future project runs, preventing duplicate entries to maintain efficiency.
    MIT

Matching MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables LLM clients to inspect local development environment, including Docker container health, pnpm workspace integrity, and stuck process diagnosis.
    4
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Audits package lockfiles for vulnerabilities, supporting npm, yarn, and pnpm. Runs via CLI or as an MCP server over stdio.
    1
    11 npm
    83
    MIT

Matching MCP Connectors

  • npm package trends and weekly downloads over time. Free key at trendsmcp.ai

  • Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.

  • Apply the OpenCode Workbench profile to a local or SSH target: clones repo, installs missing components, and overwrites config; preview by omitting confirm.
    MIT
    Destructive
  • Executes the project's build command for the specified project, returning success status and truncated output. Auto-detects build tool based on project platform.
    MIT
  • Verifies npm package names before install, checking for existence, typosquatting, and security issues. Returns allow, warn, or block to prevent malicious or hallucinated packages.
    Apache 2.0
  • Get the correct shell command to install UploadKit packages based on your project's package manager. Supports pnpm, npm, yarn, and bun.
    MIT
  • Scan a public git repository for vulnerable dependencies, secret leaks, and configuration problems, returning a structured JSON report with severity, file, and fixed versions.
    MIT
  • Audit a lockfile to confirm installed versions against OSV advisories, returning the lead finding and direct-versus-transitive dependency split.
    MIT
  • Inspect FPGA workflow tooling on local or remote machines—checking available simulators, compilers, PDS paths, and license configuration.
    Apache 2.0
  • Uninstall one OpenCode Workbench component by id from a local or SSH target; previews changes unless confirm is true, and reports absent or manual when not removable.
    MIT
    Destructive
  • Identifies the package manager in use by analyzing lockfiles and package.json, then provides the correct commands for installing dependencies, running scripts, and executing packages.
    MIT
  • Retrieve npm package metadata such as version, license, dependencies, and download statistics to verify package maintenance and assess risk before adding it as a dependency.
    MIT
  • Check versions of globally installed CLI tools, compare installed vs latest, and get update commands. Filter by category for package managers, build tools, dev tools, or CLI tools.
    MIT
  • Verify the packages a shell command would install against npm and PyPI registries before running it, flagging hallucinated, slopsquatted, or risky packages.
    MIT
  • Scan project dependencies for known vulnerabilities using npm audit and the GitHub Advisory Database. Returns CVEs, severity levels, and patched versions to identify security risks.
    MIT