pkg-oracle — Dependency Trust Oracle

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
100%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~362token 数(工具定义)
~1.7 KB典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.28%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "pkg-oracle": {
      "url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
    }
  }
}

远程端点

https://mcp-snowy-dew-9447.fly.dev/mcpstreamable-http

它能做什么

工具清单

工具(1)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟡verify_package(ecosystem, name, version)

Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi"
      ],
      "description": "Package registry to check the name against."
    },
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 214,
      "description": "Exact package name as it would appear in the manifest (case-sensitive for npm scoped packages)."
    },
    "version": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100,
      "description": "Optional exact version string to verify (e.g. \"4.17.21\"). Omit to check only the package name."
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社区

评价此服务器

证据

最近观测

已验证未记录版本1 个工具
已验证未记录版本1 个工具
已验证未记录版本1 个工具