npm-supply-chain-audit-mcp logo

npm-supply-chain-audit-mcp

by Tyler FrancisUpdated Oct 1, 2026

Check npm packages before an agent or a teammate installs them. Live registry lookups catch hallucinated package names, brand-new low-traffic packages, install scripts and typosquats, plus static package.json checks.

security
npm
supply-chain
+6
|

How to pay

Subscribe

Monthly billing

$12/month

Predictable monthly cost with included usage. Best for steady, high-volume traffic.

  • Unlimited tools within plan limits
  • One API key, billed once a month
  • Cancel any time

Check a dependency before you npm install it

AI assistants invent package names, and attackers register those names with malicious code. Typosquats and malicious install scripts reach developers the same way. This checks both the package.json text and the live npm registry, without installing anything.

What it catches

  • Package does not exist: a hallucinated or mistyped name (the "slopsquatting" setup).
  • Brand-new, low-traffic packages, especially ones that run install scripts.
  • Typosquatting of the most-depended-on npm packages.
  • Malicious install-script patterns: curl-pipe-shell, obfuscated base64 payloads.
  • Deprecated releases, single-maintainer young packages, no repository link.
  • Unpinned dependency versions that let a bad release land automatically.

Tools

  • inspect_package_live: age, weekly downloads, maintainers, install scripts and ranked flags for one package, from the live registry.
  • audit_dependencies_live: every dependency in a package.json checked live, returning only what needs attention.
  • audit_package_json: static audit of a package.json.
  • check_package_name: offline typosquat check for one name.

Useful as a guard step whenever an AI agent proposes a new dependency.

Pricing

Free: 10 audits a day. Pro: unlimited. Static, deterministic checks, no LLM calls, no data stored. Your input is analysed in memory and discarded.