UpgradeLens is answering right now. Last checked 16 min ago. It exposes 4 tools. Last commit 9 Sep 2026.
npm/PyPI/Django dependency upgrades: security, runtime compatibility, migration, package ranking.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 29 August 2026. No other catalogue keeps this.
Today is the operative word: we check UpgradeLens every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 16 min ago.
claude mcp add upgradelens --transport http https://upgradelens.mattpicone.workers.dev/mcp
{
"mcpServers": {
"upgradelens": {
"url": "https://upgradelens.mattpicone.workers.dev/mcp"
}
}
}
[mcp_servers.upgradelens]
url = "https://upgradelens.mattpicone.workers.dev/mcp"
{
"mcpServers": {
"upgradelens": {
"url": "https://upgradelens.mattpicone.workers.dev/mcp"
}
}
}
{
"mcpServers": {
"upgradelens": {
"url": "https://upgradelens.mattpicone.workers.dev/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_dependency_upgrade
plan_dependency_upgrade
review_dependency_upgrade
find_safe_upgrade_target
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://upgradelens.mattpicone.workers.dev/mcp | streamable-http | answering | 148 ms | 16 min ago |
MCP server for npm package management, security analysis, and compatibility checking
npm registry MCP server — package intelligence, security audits, dependency analysis
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Dependency graph + 24 MCP tools. Impact analysis, simulation, security, agent coordination
Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.
Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
MCP runtime security. 22µs validation, 97% self-healing. Detects RCE, SSRF, credential hijacking.
This package is intended for demonstration only. Maintained by JFrog Security.
Answers built from our own checks of this server.