lurq is answering right now. Last checked 10 min ago. It exposes 16 tools. Last commit 17 Sep 2026.
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 16 September 2026. No other catalogue keeps this.
We read the source, 5 min ago · tools taken from the live server · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
/~\/\.ssh\b|\bid_(?:rsa|ed25519|ecdsa)\b|\.aws\/credentials|(?:^|[\s"'`(/])\.env\b|\bmcp\.json\b|\.claude\.json\b|\.npmrc\b|\.netrc\b|\.git-credentials\b|\/etc\/(?:passwd|shadow)\b|\bprivate[_\s-]key\b/i;
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
spawn(
/~\/\.ssh\b|\bid_(?:rsa|ed25519|ecdsa)\b|\.aws\/credentials|(?:^|[\s"'`(/])\.env\b|\bmcp\.json\b|\.claude\.json\b|\.npmrc\b|\.netrc\b|\.git-credentials\b|\/etc\/(?:passwd|shadow)\b|\bprivate[_\s-]key\b/i;
/https?:\/\/[^\s"')]*(?:ngrok(?:-free)?\.(?:io|app|dev)|webhook\.site|requestbin|pipedream\.net|burpcollaborator|interact\.sh|oast\.(?:fun|live|site|pro|online|me))/i;
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch lurq and you get told the day something new turns up.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add lurq --transport http https://api.lurq.run/mcp
{
"mcpServers": {
"lurq": {
"url": "https://api.lurq.run/mcp"
}
}
}
[mcp_servers.lurq]
url = "https://api.lurq.run/mcp"
{
"mcpServers": {
"lurq": {
"url": "https://api.lurq.run/mcp"
}
}
}
{
"mcpServers": {
"lurq": {
"url": "https://api.lurq.run/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
mcp_drift
mcp_stack
mcp_surface
audit
capabilities
compare
compat
connect_check
diagram
diff_surface
evaluate
policy
report_outcome
resolve_surface
usage
verify
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://api.lurq.run/mcp | streamable-http | answering | 440 ms | 10 min ago |
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Catch AI-hallucinated (slopsquatted) npm imports in generated code before npm install.
Check the trust/security score of MCP servers, agents, skills & CLIs before you install them.
Install + verify the panini-connector SDK on self-hosted sites, driven by AI agents.
Answers built from our own checks of this server.