Skip to content
mcp/skillhub

Pkgtruth MCP Server

by hxckyaio.github.hxckya/pkgtruthv0.2.2

Ground truth about npm and PyPI packages for AI coding agents. Detects hallucinated and slopsquatted dependencies before they get installed.

4Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active4d ago

Install Pkgtruth MCP server

Install in Claude Code

claude mcp add pkgtruth -- npx -y pkgtruth

Configuration

VariableRequiredSecretDescription
PKGTRUTH_REGISTRY——Alternate npm registry to verify against. Defaults to https://registry.npmjs.org.
PKGTRUTH_DOWNLOADS_API——Alternate downloads API used for adoption figures. Defaults to https://api.npmjs.org.
PKGTRUTH_CACHE_DIR——Where adoption figures are cached between runs. Defaults to ~/.cache/pkgtruth.
PKGTRUTH_TIMEOUT_MS——Per-request timeout in milliseconds. Defaults to 8000.

Freshness

Active — last maintenance signal 4d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-05 · 4d ago · GitHub

  2. Latest release

    2026-09-28 · 11d ago · GitHub · report-2026-09-28

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-10 · 29d ago · official registry · v0.2.2

FAQ

›How do I install the Pkgtruth MCP server in Claude Code?

Run: claude mcp add pkgtruth -- npx -y pkgtruth. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Pkgtruth require an API key?

No required environment variables are declared in its published metadata.

›Can I use Pkgtruth as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Pkgtruth in the official MCP registry?

Yes, as io.github.hxckya/pkgtruth.