Skip to content
mcp/skillhub

NPMScan MCP Server

by salemalemio.github.salemalem/npmscanv1.0.0

Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

remoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained2mo ago

Install NPMScan MCP server

Install in Claude Code

claude mcp add --transport http npmscan https://npmscan.com/api/mcp

Remote endpoints

  • streamable-httphttps://npmscan.com/api/mcp

Freshness

Maintained — last maintenance signal 2mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    no data · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-08-01 · 2mo ago · official registry · v1.0.0

FAQ

›How do I install the NPMScan MCP server in Claude Code?

Run: claude mcp add --transport http npmscan https://npmscan.com/api/mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does NPMScan require an API key?

No required environment variables are declared in its published metadata.

›Can I use NPMScan as a remote (hosted) MCP server?

Yes. It is a hosted MCP server; connect to its URL with any client that supports remote MCP.

›Is NPMScan in the official MCP registry?

Yes, as io.github.salemalem/npmscan.

Alternatives to NPMScan

Other version control MCP servers.

View all