Server data from the Official MCP Registry
Package risk checks: maintenance, licence, advisories. Paid per call in USDC, no signup.
About
Package risk checks: maintenance, licence, advisories. Paid per call in USDC, no signup.
Security Report
Valid MCP server (3 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.
4 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: EVM_PRIVATE_KEY
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-makosddavid-package-risk": {
"env": {
"EVM_PRIVATE_KEY": "your-evm-private-key-here"
},
"args": [
"-y",
"@makosdav/package-risk-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
package-risk MCP connector
MCP tools for checking a package's maintenance status, licence, and security
advisories before you depend on it - package_risk, package_licence,
package_advisories. Paid per call in USDC on Base mainnet via x402.
No subscription, no API key. You pay from your own wallet, per call, only for what you use.
What this is (and isn't)
This is a thin client. The actual service is a stateless HTTP API at
x402-package-risk.x402-package-risk.workers.dev. This connector never sees,
holds, or forwards anyone else's funds - it only ever spends the wallet key
you configure below, and only when you call one of its tools.
Setup
You need an EVM wallet with a small amount of USDC on Base mainnet (calls cost $0.005-$0.01 each). Never use a wallet holding significant funds for an automated agent key - keep this one funded lightly.
Add to your MCP client config (Claude Desktop, Claude Code, Cursor, etc.):
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": ["-y", "@makosdav/package-risk-mcp"],
"env": {
"EVM_PRIVATE_KEY": "0xyour-private-key-here"
}
}
}
}
Tools
| Tool | Price | What it returns |
|---|---|---|
package_risk | $0.01 | Full verdict: maintenance, licence, advisories, deprecation |
package_licence | $0.005 | Licence expression and closed-source safety |
package_advisories | $0.005 | Open OSV advisories for the resolved version |
All three take system (npm/pypi/go/maven/cargo/nuget), name, and an
optional version.
How payment works
- Your agent calls a tool.
- This connector requests the resource; the server replies
402 Payment Required. @x402/fetchbuilds and signs a payment authorisation with your key.- The request retries with payment attached; the server verifies via Coinbase CDP, returns the result, and settles on-chain.
No approval prompt happens here beyond what your MCP client itself asks for - if you want per-call confirmation, configure that in your agent framework, not here.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
