Skip to main content
ClaudeWave
tylerscomic-lab avatar
tylerscomic-lab

npm-supply-chain-audit-mcp

View on GitHub
MCP ServersOfficial Registry0 stars0 forks● JavaScriptMITUpdated today
ClaudeWave Trust Score
85/100
✓ Trusted
Passed
  • ✓Open-source license (MIT)
  • ✓Actively maintained (<30d)
  • ✓Topics declared
  • ✓Documented (README)
Flags
  • !No description
Last scanned: 10/2/2026
Install in Claude Code / Claude Desktop
Method: Manual
Claude Code CLI
git clone https://github.com/tylerscomic-lab/npm-supply-chain-audit-mcp
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "npm-supply-chain-audit-mcp": {
      "command": "node",
      "args": ["/path/to/npm-supply-chain-audit-mcp/dist/index.js"]
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Clone https://github.com/tylerscomic-lab/npm-supply-chain-audit-mcp and follow its README for install instructions.
Use cases

MCP Servers overview

# npm-supply-chain-audit-mcp

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Live on MCPize](https://img.shields.io/badge/Live%20on-MCPize-6d28d9)](https://mcpize.com/mcp/npm-supply-chain-audit-mcp)

An MCP server that audits `package.json` for the real mechanisms behind actual npm supply-chain incidents —
typosquatting and malicious install scripts — not a generic vulnerability-database lookup.

## What it catches

**Typosquatting.** Dependency names within 1-2 character edit distance of one of the npm registry's
most-depended-on packages (`lodash`, `express`, `react`, `axios`, and ~90 others) — the actual real targets of
typosquat campaigns, since attackers go after the packages with the largest install base. `lodahs`, `expres`,
`reqeust` all flag; an unrelated, genuinely distinct package name doesn't.

**Malicious install scripts.** `preinstall`/`install`/`postinstall` hooks run automatically on `npm install`,
before any of the package's own code is ever reviewed — the actual delivery mechanism behind real incidents
(`event-stream` 2018, `ua-parser-js` 2021, and others since). Flags scripts that pipe a remote download directly
into a shell, and scripts that decode an obfuscated base64 payload before running it.

**Unpinned versions.** Dependencies on `*` or `latest` pull in whatever gets published next, silently, with no
diff in your repo to explain why your dependency tree changed.

## Tools

### `audit_package_json`
Full audit of a package.json file.

### `check_package_name`
Focused typosquat check on a single package name.

## Use it

**Hosted (recommended):** [MCPize](https://mcpize.com/mcp/npm-supply-chain-audit-mcp) — free tier, $7/mo Pro.

**Self-host:**
```bash
npm install
node server.js
```

## Part of a small suite

[secrets-leak-audit-mcp](https://github.com/tylerscomic-lab/secrets-leak-audit-mcp),
[mcp-trust-audit-mcp](https://github.com/tylerscomic-lab/mcp-trust-audit-mcp),
[github-actions-audit-mcp](https://github.com/tylerscomic-lab/github-actions-audit-mcp),
[dockerfile-audit-mcp](https://github.com/tylerscomic-lab/dockerfile-audit-mcp).

## License

MIT

## Update 1.1.0 (2026-10-01)
- New tools `inspect_package_live` and `audit_dependencies_live`: look packages up on the live npm registry. Flags names that do not exist (hallucinated or mistyped), brand-new low-traffic packages, install scripts, deprecated releases and typosquats.
mcpmcp-servermodel-context-protocolnpmsecuritysupply-chain-security

What people ask about npm-supply-chain-audit-mcp

What is tylerscomic-lab/npm-supply-chain-audit-mcp?

+

tylerscomic-lab/npm-supply-chain-audit-mcp is mcp servers for the Claude AI ecosystem with 0 GitHub stars.

How do I install npm-supply-chain-audit-mcp?

+

You can install npm-supply-chain-audit-mcp by cloning the repository (https://github.com/tylerscomic-lab/npm-supply-chain-audit-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is tylerscomic-lab/npm-supply-chain-audit-mcp safe to use?

+

Our security agent has analyzed tylerscomic-lab/npm-supply-chain-audit-mcp and assigned a Trust Score of 85/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.

Who maintains tylerscomic-lab/npm-supply-chain-audit-mcp?

+

tylerscomic-lab/npm-supply-chain-audit-mcp is maintained by tylerscomic-lab. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.

Are there alternatives to npm-supply-chain-audit-mcp?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy npm-supply-chain-audit-mcp to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: tylerscomic-lab/npm-supply-chain-audit-mcp
[![Featured on ClaudeWave](https://claudewave.com/api/badge/tylerscomic-lab-npm-supply-chain-audit-mcp)](https://claudewave.com/repo/tylerscomic-lab-npm-supply-chain-audit-mcp)
<a href="https://claudewave.com/repo/tylerscomic-lab-npm-supply-chain-audit-mcp"><img src="https://claudewave.com/api/badge/tylerscomic-lab-npm-supply-chain-audit-mcp" alt="Featured on ClaudeWave: tylerscomic-lab/npm-supply-chain-audit-mcp" width="320" height="64" /></a>