Back to Browse

Presend Source MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.

About

Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.

Remote endpoints: streamable-http: https://presend.pages.dev/mcp-deps

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

5 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Found in Source Code

Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-presendapp-presend-deps": {
      "url": "https://presend.pages.dev/mcp-deps"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Presend — Free Privacy Tools, a Security API, and an MCP Server for AI Agents

Open in GitHub Codespaces Live Site

Tools API MCP Server npm GitHub Marketplace Run in Postman License PWA Privacy

Presend checks npm and PyPI packages before they are installed: typosquats, known vulnerabilities of the version you use, publisher changes (npm), and names that do not exist or were first published in the last 30 days. It is available as a free API, an MCP server for AI agents and a GitHub Action. The site also has free browser tools; the file tools process files locally.

Open Presend · API docs · OpenAPI spec · MCP server · Measurements · For teams

Why Presend?

  • Before an agent installs a package -- the MCP tool supply_chain_check reports package_not_found for a name that does not exist on npm or PyPI (it may be invented by a model) and new_package for one first published less than 30 days ago.
  • Measured false alarms -- the typosquat check is measured on the most downloaded PyPI packages and the npm-high-impact list, with the scripts to reproduce it: see the measurements page.
  • Real supply-chain signal (API) -- maintainer-change-check flags a package recently taken over by a previously unseen publisher after a long dormancy (the event-stream pattern; it does not detect hijacked existing accounts).
  • What it is not -- not a malware scanner: it reports signals worth a look before installing, it does not analyse package code.
  • No account -- the API and the MCP server are free, with no signup and no key; per-minute rate limits apply. A paid offer for teams is being tested: Presend for teams.
  • Browser file tools -- the file tools (EXIF, PDF, images, office files) run locally with Web Crypto, Canvas and FileReader. A few other tools rely on a network service (speech recognition, password breach lookup, link preview...); the privacy page lists each one.
  • PWA -- install on mobile or desktop.

API & MCP Server

  • REST API -- free endpoints: supply-chain checks (typosquat, vulnerabilities of a given version, maintainer change, repository health, and a combined supply-chain check), DNS and WHOIS lookups, email checks, JWT decode and verify, file and image processing, and everyday utilities. Full OpenAPI 3.0 spec.
  • MCP server -- the same checks as tools over Streamable HTTP, no signup, no key; listed in the official MCP registry as io.github.presendapp/presend-mcp.
  • npm client -- npm install presend-api, zero-dependency.
  • GitHub Action -- checks the dependencies of package.json or requirements.txt in CI (npm and PyPI).
  • Code examples -- working Python for LangChain, CrewAI, LlamaIndex, OpenAI Agents SDK, Google ADK, and plain REST.
  • MCP config guides -- copy-paste setup for Claude Desktop, Claude Code, Cursor, and Windsurf, no code required.
  • Browser extension -- "Presend — Clean Photos", strips EXIF/GPS on right-click.

Python: Cloudflare rejects the default urllib User-Agent (Python-urllib/3.x) with 403 error code: 1010. Set an explicit one, e.g. urllib.request.Request(url, headers={"User-Agent": "my-app/1.0"}). requests, curl and Node are not affected.

Browser Tools (48 total, 22 shown below)

ToolWhat it doesLink
EXIF RemoverStrip GPS, camera model, timestamps from photosOpen
PDF Metadata RemoverRemove author, software, dates from PDFsOpen
Image CompressorShrink JPG/PNG/WebP with quality previewOpen
PDF CompressReduce PDF file size without quality lossOpen
PDF MergerCombine multiple PDFs into one documentOpen
Image ResizerResize to exact dimensions (Instagram, LinkedIn, Twitter)Open
HEIC to JPG ConverterConvert iPhone photos to universal JPGOpen
Video Metadata RemoverStrip GPS and device data from MP4/MOVOpen
Office Metadata RemoverClean Word, Excel, PowerPoint hidden dataOpen
File Hash CheckerVerify SHA-256, SHA-1, SHA-512 checksumsOpen
Password GeneratorCreate cryptographically secure passwordsOpen
Password StrengthAnalyze password entropy and crack timeOpen
QR Code GeneratorGenerate QR codes for URLs, WiFi, textOpen
URL CleanerRemove tracking parameters (UTM, fbclid, gclid)Open
Email List CleanerDeduplicate, validate, clean email listsOpen
JSON to CSV ConverterConvert between JSON and CSV instantlyOpen
Image to Base64Encode images for embedding in HTML/CSSOpen
Text DiffCompare two texts side by sideOpen
Text FormatterBold, italic, stylized text for social mediaOpen
Thread SplitterSplit long text into Twitter/X threadsOpen
Word CounterCount words, characters, reading timeOpen
Color ContrastCheck WCAG accessibility contrast ratiosOpen

SEO and Performance

Presend is built for search engines and AI assistants:

  • Schema.org: structured data on the pages (Organization, FAQPage, BreadcrumbList...)
  • Sitemap: a static sitemap.xml covering the tools, blog and guides in 8 languages
  • Dynamic OG Images: API generates social preview images per tool
  • Core Web Vitals: Preconnect, DNS-prefetch, CSS preload, zero render-blocking JS
  • PWA: Service worker + manifest for offline use and installability
  • Privacy-First Analytics: Cloudflare Web Analytics (no cookies, no IP tracking)

Embed on Your Site

Add a Presend tool to your website or link back to us:

See all embed options

Tech Stack

  • Frontend: Vanilla HTML5, CSS3, ES6 (zero build step)
  • Hosting: Cloudflare Pages (200+ edge locations)
  • APIs: Cloudflare Workers (share links, analytics, sitemap, OG images)
  • Storage: Cloudflare KV (share links, 30-day TTL)
  • PWA: Service Worker + Web App Manifest

License

MIT — free to use, modify, and embed.

Open Presend

Reviews

No reviews yet

Be the first to review this server!