pkg-oracle — Dependency Trust Oracle
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
¿Debería usar esto?
Calidad y seguridad
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}Puntos de conexión remotos
https://mcp-snowy-dew-9447.fly.dev/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (1)
🟡verify_package(ecosystem, name, version)
Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.
Esquema de entrada
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"enum": [
"npm",
"pypi"
],
"description": "Package registry to check the name against."
},
"name": {
"type": "string",
"minLength": 1,
"maxLength": 214,
"description": "Exact package name as it would appear in the manifest (case-sensitive for npm scoped packages)."
},
"version": {
"type": "string",
"minLength": 1,
"maxLength": 100,
"description": "Optional exact version string to verify (e.g. \"4.17.21\"). Omit to check only the package name."
}
},
"required": [
"ecosystem",
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Comunidad
Evidencia