NPMScan is answering right now. Last checked moments ago. It exposes 23 tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
The linked repository no longer exists on GitHub — it was deleted or made private.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 1 September 2026. No other catalogue keeps this.
Quiet is not dead — but it is worth knowing when it wakes up, or when someone else takes it over. We watch the repository and tell you either way.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 0 min ago.
claude mcp add npmscan --transport http https://npmscan.com/api/mcp
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
[mcp_servers.npmscan]
url = "https://npmscan.com/api/mcp"
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
{
"mcpServers": {
"npmscan": {
"url": "https://npmscan.com/api/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_maintainer_blast_radius
check_maintainer_changes
get_maintainer_profile
check_package_provenance
get_package
get_package_version
analyze_install_script
analyze_transitive_dependencies
audit_github_repository
batch_query_vulnerabilities
compare_packages
get_cve
diff_dependencies
enrich_npm_audit
generate_sbom
get_latest_advisories
check_license_compliance
search_packages
prioritize_remediation
get_remediation_playbook
simulate_dependency_upgrade
suggest_alternative
query_vulnerabilities
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://npmscan.com/api/mcp | streamable-http | answering | 318 ms | 0 min ago |
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
PQC scanner for GitHub repos and smart contracts. Detects quantum-vulnerable ECDSA/RSA.
Defensive vulnerability intelligence search across public CVE/NVD and GitHub advisory APIs with CVSS
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
Dev-registry data: npm/PyPI/Docker/VS Code packages, dep graphs, vulns, 50+ ecosystems.
Auto-detect stubbable packages for Python exe builds and generate minimal stub code
FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality
Access GitHub repos, npm/PyPI packages, Stack Overflow, arXiv, and Google Scholar
Answers built from our own checks of this server.