npmscan is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
Security analysis for npm packages, built for AI agents and developer tools. NPMScan helps agents inspect npm packages before installation by checking for: - Suspicious install scripts - Obfuscated or potentially malicious code - Credential and environment-variable access - Network and data-exfiltration indicators - Known vulnerabilities - Maintainer and ownership changes - Risky package updates and version differences Use this MCP server to investigate package risk, compare versions, and mak
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
npmscan
Source: Smithery
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check