Developer-security MCP for npm package health, OSV vulnerability lookup, and dependency-risk analysis with x402 USDC payments on Base.
npm
security
osv
+5
|Developer Risk Intelligence for AI Agents
Ops Control HQ Developer Risk MCP gives AI agents direct access to three production developer-security tools:
npm_health
Check npm package health including current version, publish age, downloads, maintainers, dependencies, deprecation status, and deterministic risk flags.
osv_vulnerabilities
Query exact package versions against OSV.dev for vulnerability IDs, aliases, affected packages, and remediation information.
npm_dependency_risk
Get a compact dependency-risk brief combining npm metadata with exact-version OSV vulnerability intelligence and package-specific fixed versions.
Agent-native payments
Tool calls use x402 with USDC on Base.
- No traditional API-key signup for paid tool calls
- Machine-readable payment requirements
- Designed for autonomous AI agents and MCP clients
- Production endpoint already live and independently used by repeat machine buyers
Best for
- AI coding agents
- Dependency review workflows
- Package-security checks
- Automated software supply-chain analysis
- Pre-install package evaluation
- Vulnerability triage