Package Risk MCP Server
by makosddavidio.github.makosdDavid/package-riskv1.0.5
MCP tools for package-risk: dependency maintenance, licence and advisory checks, paid per call via x402.
context tax
queued
security
queued
cold start
queued
freshness
Maintained56d ago
Install Package Risk MCP server
Install in Claude Code
claude mcp add package-risk -e EVM_PRIVATE_KEY='<evm-private-key>' -- npx -y @makosdav/package-risk-mcpInstall in Cursor
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": [
"-y",
"@makosdav/package-risk-mcp"
],
"env": {
"EVM_PRIVATE_KEY": "<evm-private-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": [
"-y",
"@makosdav/package-risk-mcp"
],
"env": {
"EVM_PRIVATE_KEY": "<evm-private-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"package-risk": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@makosdav/package-risk-mcp"
],
"env": {
"EVM_PRIVATE_KEY": "<evm-private-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": [
"-y",
"@makosdav/package-risk-mcp"
],
"env": {
"EVM_PRIVATE_KEY": "<evm-private-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| EVM_PRIVATE_KEY | yes | yes | Private key of an EVM wallet holding a small amount of USDC on Base mainnet. Each tool call spends $0.005-$0.01 from it. Use a lightly funded key dedicated to this agent, never a main wallet. |
Freshness
Maintained — last maintenance signal 56d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-08-14 · 56d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-08-14 · 56d ago · official registry · v1.0.5
FAQ
›How do I install the Package Risk MCP server in Claude Code?
Run: claude mcp add package-risk -e EVM_PRIVATE_KEY='<evm-private-key>' -- npx -y @makosdav/package-risk-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Package Risk require an API key?
Yes. It expects EVM_PRIVATE_KEY, of which 1 is a secret.
›Can I use Package Risk as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Package Risk in the official MCP registry?
Yes, as io.github.makosdDavid/package-risk.