MCP server
io.github.mikusnuz/npm
MCP server for npm package management — publish, version, search, audit, and more
- Version
- 1.3.0
- Analysed
- Last observed
What the code does
- Brings outside content into the agent Tools that return web pages, search results, documentation or messages written by others. That text reaches the model, and instructions planted in it can steer the agent (indirect prompt injection). Treat what these tools return as untrusted input.
- Evaluates code at runtime Code that builds and runs code while it executes.
- Reads AI and developer logins Code that refers to AI tool credentials or publishing tokens, such as .npmrc.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Complete static analysis
Detailed report
4 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment