NPM Sentinel MCP

NPM Sentinel MCP is an MCP server that provides deep inspection of NPM packages, dependencies, security vulnerabilities, and ecosystem metrics directly to AI agents. It connects LLM-driven developer environments like Claude and Cursor to the NPM registry, Google deps.dev, OSV.dev, OpenSSF Scorecard, and npms.io. Software engineers, security auditors, and system architects use this server to audit JavaScript and TypeScript software supply chains, evaluate new third-party libraries, inspect transitive dependency trees, and track bundle performance. The integration enables AI models to verify release integrity hashes, resolve semver shorthands, detect package deprecations, and check for known CVEs across package manifests without manual terminal queries. Designed with defensive security measures, it incorporates OWASP LLM01 indirect prompt injection protections by wrapping untrusted external documentation and README contents in dedicated demarcation tags. It also features automated lockfile-aware cache management, making it an effective tool for keeping AI coding workflows grounded in verifiable registry metadata.

Category: Developer Tools & Code Intelligence

Tags: dependencies, javascript, npm, supply-chain, vulnerability

Visit NPM Sentinel MCP

How to install and configure NPM Sentinel MCP

To configure NPM Sentinel MCP in your MCP client, follow these steps: 1. In your Claude Desktop configuration (claude_desktop_config.json) or Cursor MCP configuration, add the server under the mcpServers block: json { "mcpServers": { "npm-sentinel": { "command": "npx", "args": ["-y", "@nekzus/mcp-server@latest"] } } } 2. If using HTTP mode on platforms like Smithery.ai, set the configuration type to http with the endpoint https://smithery.ai/server/@Nekzus/npm-sentinel-mcp. 3. Save the configuration and restart your client to initialize the server tools.

What you can do with NPM Sentinel MCP

  • Scanning NPM packages and recursive dependencies for known vulnerabilities using Google deps.dev and OSV.dev databases. - Discovering direct library alternatives with functional domain filtering that excludes ecosystem plugins and unrelated extensions. - Inspecting package quality metrics, GitHub repository health, and OpenSSF Scorecard ratings before adopting new project dependencies. - Analyzing bundle size, download velocity trends, and release version histories across public and custom NPM registries. - Auditing package README files and changelogs safely using demarcated data tags that protect models from indirect prompt injection.

Key facts

  • https://github.com/Nekzus/npm-sentinel-mcp
  • Developer Tools & Code Intelligence, Security & Compliance
  • dependencies, javascript, npm, supply-chain, vulnerability

Part of MCP Servers

Related MCP servers

  • MCP LaTeX Server — MCP LaTeX Server is an MCP server that provides tools for creating, editing, validating, and compiling LaTeX documents directly through…
  • MCP JSON — MCP JSON is an MCP server collection that bundles tools for file system operations, Google search, browser-based web automation, and…
  • MCP Jupyter Complete — MCP Jupyter Complete is an MCP server that provides tools for manipulating Jupyter notebook files through position-based cell operations and…
  • MCP LSP Go — MCP LSP Go is an MCP server that connects AI assistants to the official Go Language Server Protocol implementation, gopls,…
  • MCP Manager — MCP Manager is an MCP server management tool that connects directly to your Claude Desktop environment, enabling users to discover,…
  • MCP Lab — MCP Lab is an MCP server development environment designed for building, testing, and debugging custom Model Context Protocol servers integrated…

How do I install NPM Sentinel MCP?

You can install NPM Sentinel MCP by adding an npx configuration entry pointing to @nekzus/mcp-server@latest in your Claude Desktop or Cursor MCP settings file. It runs locally using standard input and output (STDIO) transport. Alternatively, it can be run via Docker or deployed as an HTTP service.

What can NPM Sentinel MCP do?

NPM Sentinel MCP provides 19 tools for NPM package intelligence. It performs vulnerability scanning via OSV.dev and deps.dev, tracks version histories and SRI integrity hashes, evaluates package quality metrics, monitors download statistics, maps transitive dependencies, and searches for package alternatives with automated plugin filtering.

Which MCP clients work with NPM Sentinel MCP?

The server supports both MCP v1 and v2 specifications. It operates seamlessly with Claude Desktop, Cursor, Smithery.ai, and web runtimes like Cloudflare Workers, Hono, Express, or any client compatible with standard STDIO or Streamable HTTP transports.

How does NPM Sentinel MCP protect against prompt injection?

The server enforces OWASP LLM01 indirect prompt injection controls. When fetching external README files or changelogs, it encapsulates untrusted markdown in dedicated XML tags, adds metadata flags, caps search query lengths, and instructs consuming LLM clients to handle the text purely as passive data.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories