mcpbeat Sign in

pkg-oracle — Dependency Trust Oracle MCP Server

by julian-martin89 Your server? Claim it
answering

pkg-oracle — Dependency Trust Oracle is answering right now. Last checked 13 min ago. It exposes 1 tools.

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

Uptime history 49 days of history
49 days agonow
100.0%
Uptime 24h
91 of 91 checks
1
Tools
read from the server
184 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check pkg-oracle — Dependency Trust Oracle every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 13 min ago.

run in your terminal
claude mcp add pkg-oracle --transport http https://mcp-snowy-dew-9447.fly.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "pkg-oracle": {
      "url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.pkg-oracle]
url = "https://mcp-snowy-dew-9447.fly.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "pkg-oracle": {
      "url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "pkg-oracle": {
      "url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

verify
verify_package
Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.

Endpoints

URLTransportStateLatencyChecked
https://mcp-snowy-dew-9447.fly.dev/mcp streamable-http answering 183 ms 13 min ago

Alternatives to pkg-oracle — Dependency Trust Oracle

same job, measured the same way
Pkgtruth
by hxckya

Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.

60 installs/wk local only
lurq
by jadenryu

Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.

16 tools answering
Vdb
by ai-vdb

Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.

70 installs/wk local only
Jeevesus — DugganUSA Threat Intelligence MCP
by pduggusa

check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.

6 tools answering
Import Guardian
by baneado98

Catch AI-hallucinated (slopsquatted) npm imports in generated code before npm install.

38 installs/wk local only
Freshdeps MCP
by solvohq

Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages

local only
pkgproof
by pkgproof

Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.

443 installs/wk local only
PackageGuard
by dankaten

x402-gated safety checker for npm/PyPI packages before you npm install / pip install.

1 tools answering

pkg-oracle — Dependency Trust Oracle — questions

Answers built from our own checks of this server.

What can pkg-oracle — Dependency Trust Oracle do?
It exposes 1 tools, read directly from the server on our last check. Among them: verify_package. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is pkg-oracle — Dependency Trust Oracle working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 184 ms. The bar chart above shows every period we have measured.
How do I connect pkg-oracle — Dependency Trust Oracle?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does pkg-oracle — Dependency Trust Oracle need an API key?
No. pkg-oracle — Dependency Trust Oracle completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is pkg-oracle — Dependency Trust Oracle?
It answers our handshake in 184 ms on average, which is faster than 73% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.