Presend dependency checks

Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
100%
이름 품질
80%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,261토큰 (도구 정의)
~887 B일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 0.99%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "presend-deps": {
      "url": "https://presend.pages.dev/mcp-deps"
    }
  }
}

원격 엔드포인트

https://presend.pages.dev/mcp-depsstreamable-http

할 수 있는 일

도구 목록

도구 (5)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟢maintainer_change_check(ecosystem, package)

Publisher-change analysis is npm only. Also reports whether the package exists (found) and its age (first_published, package_age_days, new_package if first published less than 30 days ago), for npm and for PyPI; on PyPI only existence and age are available. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.

입력 스키마

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "npm (full analysis) or pypi (existence and age only)."
    },
    "package": {
      "type": "string",
      "description": "Package name, e.g. lodash"
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢repo_health_check(repo)

Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.

입력 스키마

{
  "type": "object",
  "properties": {
    "repo": {
      "type": "string",
      "description": "GitHub repository in owner/name format, e.g. lodash/lodash."
    }
  },
  "required": [
    "repo"
  ]
}
🟢supply_chain_check(ecosystem, package, version)

Call this before installing or adding a package (npm install, pip install, a new entry in a manifest), especially one whose name you recalled or that a model suggested. One-call risk check: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. A package that does not exist on npm or PyPI gets overall_risk 'package_not_found': the name may be invented and should not be installed. A package first published less than 30 days ago gets the 'new_package' flag and overall_risk 'review_recommended': new packages are where invented and look-alike names get registered, so the name is worth confirming against the project's own documentation before installing (on PyPI the age is that of the oldest release still published; being new does not make a package malicious). Use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'.

입력 스키마

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm. maintainer-change-check only runs for npm."
    },
    "package": {
      "type": "string",
      "description": "Package name to check."
    },
    "version": {
      "type": "string",
      "description": "Exact version to check for known vulnerabilities. Optional: defaults to the latest published version (npm and PyPI)."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢typosquat_check(ecosystem, package)

Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.

입력 스키마

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm or PyPI."
    },
    "package": {
      "type": "string",
      "description": "Package name to check for likely typosquatting of a well-known package in the given ecosystem."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢vulnerability_check(ecosystem, package, version)

Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. For npm and PyPI, a name that does not exist returns found: false and vulnerable: null, never a clean result. Use supply_chain_check for a combined verdict.

입력 스키마

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet."
    },
    "package": {
      "type": "string",
      "description": "Package name to check against OSV.dev for known CVEs."
    },
    "version": {
      "type": "string",
      "description": "Omit to check all versions of the package."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 5개