npm Supply Chain Audit
io.github.tylerscomic-lab/npm-supply-chain-audit-mcp
Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.
Description as published in the official MCP registry.
Answers, but requires sign-in before the handshake. Checked 2026-10-05.
What we measured
| Endpoint | https://npm-supply-chain-audit-mcp.mcpize.run/mcp | registry |
|---|---|---|
| Handshake | Answers, but requires sign-in before the handshake (458 ms) | our check, 2026-10-05 |
| GitHub stars | 0 | github.com/tylerscomic-lab/npm-supply-chain-audit-mcp |
| Last push | 2026-10-01 | GitHub API |
| Licence | MIT | GitHub API |
| Registry version | 1.1.0 · active · updated 2026-10-01 | registry |
Signed reports
No signed reports yet. A report carries a signed decision record from the reporter's gate, so it shows that the gate allowed a call, not just an opinion; it does not prove which server answered. How to file one.
Connect
claude mcp add --transport http npm-supply-chain-audit-mcp https://npm-supply-chain-audit-mcp.mcpize.run/mcpCommands are built from the registry entry. Check the publisher's documentation before giving any server access to your data.
Related servers
- Commit — Supply Chain Risk Scoring Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
- supply-chain-intelligence Real-time supply chain risk intelligence — 24 tools, proprietary indices, predictive…
- Agent Skill & Config Security Audit Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.
- Claude Cost Audit Exact Claude API cost calc with real cache economics, plus a tiktoken-misuse scanner.
- Cron Schedule Audit Validates cron expressions and finds DST bugs that make jobs silently skip or double-fire.
- Dockerfile Security Audit Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base…
Badge for your README
Shows the result of our latest check and links back to this page.
[](https://openforallofus.com/tools/io.github.tylerscomic-lab/npm-supply-chain-audit-mcp)Agents can read this page as data: MCP endpoint https://openforallofus.com/api/mcp, tool get_tool with name io.github.tylerscomic-lab/npm-supply-chain-audit-mcp.