- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Topics declared
- ✓Documented (README)
- !No description
git clone https://github.com/tylerscomic-lab/npm-supply-chain-audit-mcp{
"mcpServers": {
"npm-supply-chain-audit-mcp": {
"command": "node",
"args": ["/path/to/npm-supply-chain-audit-mcp/dist/index.js"]
}
}
}Resumen de MCP Servers
# npm-supply-chain-audit-mcp [](LICENSE) [](https://mcpize.com/mcp/npm-supply-chain-audit-mcp) An MCP server that audits `package.json` for the real mechanisms behind actual npm supply-chain incidents — typosquatting and malicious install scripts — not a generic vulnerability-database lookup. ## What it catches **Typosquatting.** Dependency names within 1-2 character edit distance of one of the npm registry's most-depended-on packages (`lodash`, `express`, `react`, `axios`, and ~90 others) — the actual real targets of typosquat campaigns, since attackers go after the packages with the largest install base. `lodahs`, `expres`, `reqeust` all flag; an unrelated, genuinely distinct package name doesn't. **Malicious install scripts.** `preinstall`/`install`/`postinstall` hooks run automatically on `npm install`, before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents (`event-stream` 2018, `ua-parser-js` 2021, and others since). Flags scripts that pipe a remote download directly into a shell, and scripts that decode an obfuscated base64 payload before running it. **Unpinned versions.** Dependencies on `*` or `latest` pull in whatever gets published next, silently, with no diff in your repo to explain why your dependency tree changed. ## Tools ### `audit_package_json` Full audit of a package.json file. ### `check_package_name` Focused typosquat check on a single package name. ## Use it **Hosted (recommended):** [MCPize](https://mcpize.com/mcp/npm-supply-chain-audit-mcp) — free tier, $7/mo Pro. **Self-host:** ```bash npm install node server.js ``` ## Part of a small suite [secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp), [mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp), [github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp), [dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp). ## License MIT ## Update 1.1.0 (2026-10-01) - New tools `inspect_package_live` and `audit_dependencies_live`: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
Lo que la gente pregunta sobre npm-supply-chain-audit-mcp
¿Qué es tylerscomic-lab/npm-supply-chain-audit-mcp?
+
tylerscomic-lab/npm-supply-chain-audit-mcp es mcp servers para el ecosistema de Claude AI con 0 estrellas en GitHub.
¿Cómo se instala npm-supply-chain-audit-mcp?
+
Puedes instalar npm-supply-chain-audit-mcp clonando el repositorio (https://github.com/tylerscomic-lab/npm-supply-chain-audit-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar tylerscomic-lab/npm-supply-chain-audit-mcp?
+
Nuestro agente de seguridad ha analizado tylerscomic-lab/npm-supply-chain-audit-mcp y le ha asignado un Trust Score de 85/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene tylerscomic-lab/npm-supply-chain-audit-mcp?
+
tylerscomic-lab/npm-supply-chain-audit-mcp es mantenido por tylerscomic-lab. La última actividad registrada en GitHub es del 2026-10-01, con 0 issues abiertos.
¿Hay alternativas a npm-supply-chain-audit-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega npm-supply-chain-audit-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/tylerscomic-lab-npm-supply-chain-audit-mcp)<a href="https://claudewave.com/repo/tylerscomic-lab-npm-supply-chain-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-npm-supply-chain-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/npm-supply-chain-audit-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.