pkg-oracle — Dependency Trust Oracle is answering right now. Last checked 16 min ago. It exposes 1 tools.
Pay-per-call dependency trust oracle: verifies npm/PyPI packages before an AI agent installs them.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 16 min ago.
claude mcp add pkg-oracle --transport http https://mcp-snowy-dew-9447.fly.dev/mcp
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
[mcp_servers.pkg-oracle]
url = "https://mcp-snowy-dew-9447.fly.dev/mcp"
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
verify_package
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp-snowy-dew-9447.fly.dev/mcp | streamable-http | answering | 317 ms | 16 min ago |
Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Check the trust/security score of MCP servers, agents, skills & CLIs before you install them.
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
A verified dependency-audit verdict any AI agent can call over MCP, not a raw scan.
Stdio MCP: 17 verifiable AIMarket oracles, 35 pay-per-call tools for AI agents.
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
Answers built from our own checks of this server.