← Files NPMScanARCHIVED FILE
.codex-plugin/plugin.json
3.26 KB · Sep 30, 2026 · 22:58 UTC
{
"apps": "./.app.json",
"author": {
"name": "SHYNGGYS SHYNBOLATOV"
},
"description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
"interface": {
"capabilities": [],
"category": "Developer Tools",
"defaultPrompt": [
"Find npm packages for parsing CSV files",
"Is minimist 1.2.5 safe to use, or do I need to upgrade?",
"Audit my package.json dependencies for vulnerabilities and risky install scripts"
],
"developerName": "SHYNGGYS SHYNBOLATOV",
"displayName": "NPMScan",
"longDescription": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
"privacyPolicyURL": "https://npmscan.com/privacy",
"shortDescription": "npm package & vuln lookups",
"supportURL": "https://npmscan.com/protect-my-project",
"termsOfServiceURL": "https://npmscan.com/terms",
"websiteURL": "https://npmscan.com/"
},
"name": "app-6a6a699e6f3481918d5e6034432894f2",
"skills": "./skills",
"version": "2.0.0"
}SHA-256: e1180ae4c300815d9aac03be971e91190c499653920b0047d7c7b9a88e4ea4c1