Back to Browse

Npm Supply Chain Audit MCP Server

Developer ToolsLow Risk8.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.

About

Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.

Remote endpoints: streamable-http: https://npm-supply-chain-audit-mcp.mcpize.run/mcp

Security Report

8.2
Low Risk8.2Low Risk

This is a well-designed npm supply-chain audit tool with proper input validation, reasonable scope, and legitimate security-focused functionality. The code is clean with good error handling. Minor concerns around timeout configuration and broad exception handling in network calls do not significantly impact security posture. Permissions (network_http, file operations via parameters) align with the tool's stated purpose of analyzing packages and querying the npm registry.

4 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

npm-supply-chain-audit-mcp

License: MIT Live on MCPize

An MCP server that audits package.json for the real mechanisms behind actual npm supply-chain incidents — typosquatting and malicious install scripts — not a generic vulnerability-database lookup.

What it catches

Typosquatting. Dependency names within 1-2 character edit distance of one of the npm registry's most-depended-on packages (lodash, express, react, axios, and ~90 others) — the actual real targets of typosquat campaigns, since attackers go after the packages with the largest install base. lodahs, expres, reqeust all flag; an unrelated, genuinely distinct package name doesn't.

Malicious install scripts. preinstall/install/postinstall hooks run automatically on npm install, before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents (event-stream 2018, ua-parser-js 2021, and others since). Flags scripts that pipe a remote download directly into a shell, and scripts that decode an obfuscated base64 payload before running it.

Unpinned versions. Dependencies on * or latest pull in whatever gets published next, silently, with no diff in your repo to explain why your dependency tree changed.

Tools

audit_package_json

Full audit of a package.json file.

check_package_name

Focused typosquat check on a single package name.

Use it

Hosted (recommended): MCPize — free tier, $7/mo Pro.

Self-host:

npm install
node server.js

Part of a small suite

secrets-leak-audit-mcp, mcp-trust-audit-mcp, github-actions-audit-mcp, dockerfile-audit-mcp.

License

MIT

Update 1.1.0 (2026-10-01)

  • New tools inspect_package_live and audit_dependencies_live: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.

Reviews

No reviews yet

Be the first to review this server!