NPM Sentinel MCP is an MCP server that provides deep inspection of NPM packages, dependencies, security vulnerabilities, and ecosystem metrics directly to AI agents. It connects LLM-driven developer environments like Claude and Cursor to the NPM registry, Google deps.dev, OSV.dev, OpenSSF Scorecard, and npms.io. Software engineers, security auditors, and system architects use this server to audit JavaScript and TypeScript software supply chains, evaluate new third-party libraries, inspect transitive dependency trees, and track bundle performance. The integration enables AI models to verify release integrity hashes, resolve semver shorthands, detect package deprecations, and check for known CVEs across package manifests without manual terminal queries. Designed with defensive security measures, it incorporates OWASP LLM01 indirect prompt injection protections by wrapping untrusted external documentation and README contents in dedicated demarcation tags. It also features automated lockfile-aware cache management, making it an effective tool for keeping AI coding workflows grounded in verifiable registry metadata.
Category: Developer Tools & Code Intelligence
Tags: dependencies, javascript, npm, supply-chain, vulnerability
To configure NPM Sentinel MCP in your MCP client, follow these steps: 1. In your Claude Desktop configuration (claude_desktop_config.json) or Cursor MCP configuration, add the server under the mcpServers block: json { "mcpServers": { "npm-sentinel": { "command": "npx", "args": ["-y", "@nekzus/mcp-server@latest"] } } } 2. If using HTTP mode on platforms like Smithery.ai, set the configuration type to http with the endpoint https://smithery.ai/server/@Nekzus/npm-sentinel-mcp. 3. Save the configuration and restart your client to initialize the server tools.
Part of MCP Servers
You can install NPM Sentinel MCP by adding an npx configuration entry pointing to @nekzus/mcp-server@latest in your Claude Desktop or Cursor MCP settings file. It runs locally using standard input and output (STDIO) transport. Alternatively, it can be run via Docker or deployed as an HTTP service.
NPM Sentinel MCP provides 19 tools for NPM package intelligence. It performs vulnerability scanning via OSV.dev and deps.dev, tracks version histories and SRI integrity hashes, evaluates package quality metrics, monitors download statistics, maps transitive dependencies, and searches for package alternatives with automated plugin filtering.
The server supports both MCP v1 and v2 specifications. It operates seamlessly with Claude Desktop, Cursor, Smithery.ai, and web runtimes like Cloudflare Workers, Hono, Express, or any client compatible with standard STDIO or Streamable HTTP transports.
The server enforces OWASP LLM01 indirect prompt injection controls. When fetching external README files or changelogs, it encapsulates untrusted markdown in dedicated XML tags, adds metadata flags, caps search query lengths, and instructs consuming LLM clients to handle the text purely as passive data.