‹ The Index

NPM Sentinel

npm

Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability

Category: Security — see all ranked ›

Install (Claude Code):

claude mcp add npm-sentinel -- npx -y @nekzus/mcp-server

Security audit

scanned 2026-07-30

Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.

No known advisoriesclearchecked against OSV for 1.26.0
Makes network requestsfrom declared dependencies
Can carry remote content into your agentit can pull third-party text into the model's context — treat what it returns as untrusted input
Signed build provenancepublished from public CI with an attestation

npm ↗  ·  source ↗  ·  pkg:@nekzus/mcp-server

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›

Measured 2026-08-03  ·  scorer s5  ·  how  ·  something wrong here?