pkgxray runs on your own machine — the client starts it, so there is no endpoint to ping. 92 installs a week from npm. Last commit 19 Aug 2026.
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
We read the source, 21 h ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
{ rel: ".aws/credentials", slug: "aws", build: (t) =>
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
const file = path.join(CACHE_DIR, cacheKeyFor(name, version));
const child = spawn(command, args, { stdio: ["ignore", "pipe", "pipe"], ...options });
/(?:^|\/)\.npmrc$/
"webhook.site", "pastebin.com", "hastebin", "transfer.sh",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch pkgxray and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add pkgxray -- npx -y pkgxray
{
"mcpServers": {
"pkgxray": {
"args": [
"-y",
"pkgxray"
],
"command": "npx"
}
}
}
[mcp_servers.pkgxray]
command = "npx"
args = ["-y", "pkgxray"]
{
"mcpServers": {
"pkgxray": {
"args": [
"-y",
"pkgxray"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"pkgxray": {
"args": [
"-y",
"pkgxray"
],
"command": "npx"
}
}
}
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Security scanner for AI agent skills and MCP servers
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.
Answers built from our own checks of this server.