pkg-oracle — Dependency Trust Oracle is answering right now. Last checked 13 min ago. It exposes 1 tools.
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
Today is the operative word: we check pkg-oracle — Dependency Trust Oracle every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 13 min ago.
claude mcp add pkg-oracle --transport http https://mcp-snowy-dew-9447.fly.dev/mcp
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
[mcp_servers.pkg-oracle]
url = "https://mcp-snowy-dew-9447.fly.dev/mcp"
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
verify_package
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp-snowy-dew-9447.fly.dev/mcp | streamable-http | answering | 183 ms | 13 min ago |
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Catch AI-hallucinated (slopsquatted) npm imports in generated code before npm install.
Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages
Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.
x402-gated safety checker for npm/PyPI packages before you npm install / pip install.
Answers built from our own checks of this server.