Skip to content
mcp/skillhub

Package Risk MCP Server

by makosddavidio.github.makosdDavid/package-riskv1.0.5

MCP tools for package-risk: dependency maintenance, licence and advisory checks, paid per call via x402.

0Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained56d ago

Install Package Risk MCP server

Install in Claude Code

claude mcp add package-risk -e EVM_PRIVATE_KEY='<evm-private-key>' -- npx -y @makosdav/package-risk-mcp

Configuration

VariableRequiredSecretDescription
EVM_PRIVATE_KEYyesyesPrivate key of an EVM wallet holding a small amount of USDC on Base mainnet. Each tool call spends $0.005-$0.01 from it. Use a lightly funded key dedicated to this agent, never a main wallet.

Freshness

Maintained — last maintenance signal 56d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-08-14 · 56d ago · GitHub

  2. Latest release

    no data · GitHub

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-08-14 · 56d ago · official registry · v1.0.5

FAQ

›How do I install the Package Risk MCP server in Claude Code?

Run: claude mcp add package-risk -e EVM_PRIVATE_KEY='<evm-private-key>' -- npx -y @makosdav/package-risk-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Package Risk require an API key?

Yes. It expects EVM_PRIVATE_KEY, of which 1 is a secret.

›Can I use Package Risk as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Package Risk in the official MCP registry?

Yes, as io.github.makosdDavid/package-risk.