Pkgtruth MCP Server
by hxckyaio.github.hxckya/pkgtruthv0.2.2
Ground truth about npm and PyPI packages for AI coding agents. Detects hallucinated and slopsquatted dependencies before they get installed.
context tax
queued
security
queued
cold start
queued
freshness
Active4d ago
Install Pkgtruth MCP server
Install in Claude Code
claude mcp add pkgtruth -- npx -y pkgtruthInstall in Cursor
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"pkgtruth": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"pkgtruth"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| PKGTRUTH_REGISTRY | — | — | Alternate npm registry to verify against. Defaults to https://registry.npmjs.org. |
| PKGTRUTH_DOWNLOADS_API | — | — | Alternate downloads API used for adoption figures. Defaults to https://api.npmjs.org. |
| PKGTRUTH_CACHE_DIR | — | — | Where adoption figures are cached between runs. Defaults to ~/.cache/pkgtruth. |
| PKGTRUTH_TIMEOUT_MS | — | — | Per-request timeout in milliseconds. Defaults to 8000. |
Freshness
Active — last maintenance signal 4d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-05 · 4d ago · GitHub
Latest release
2026-09-28 · 11d ago · GitHub · report-2026-09-28
Package published
no data · npm/PyPI
Registry entry updated
2026-09-10 · 29d ago · official registry · v0.2.2
FAQ
›How do I install the Pkgtruth MCP server in Claude Code?
Run: claude mcp add pkgtruth -- npx -y pkgtruth. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Pkgtruth require an API key?
No required environment variables are declared in its published metadata.
›Can I use Pkgtruth as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Pkgtruth in the official MCP registry?
Yes, as io.github.hxckya/pkgtruth.