pkg-oracle — Dependency Trust Oracle
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"pkg-oracle": {
"url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
}
}
}遠端端點
https://mcp-snowy-dew-9447.fly.dev/mcpstreamable-http它能做什麼
工具清單
工具(1)
🟡verify_package(ecosystem, name, version)
Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.
輸入結構描述
{
"type": "object",
"properties": {
"ecosystem": {
"type": "string",
"enum": [
"npm",
"pypi"
],
"description": "Package registry to check the name against."
},
"name": {
"type": "string",
"minLength": 1,
"maxLength": 214,
"description": "Exact package name as it would appear in the manifest (case-sensitive for npm scoped packages)."
},
"version": {
"type": "string",
"minLength": 1,
"maxLength": 100,
"description": "Optional exact version string to verify (e.g. \"4.17.21\"). Omit to check only the package name."
}
},
"required": [
"ecosystem",
"name"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}社群
證據