← NPMScanCONTENT HISTORY

Update to NPMScan

Snapshot Oct 1, 2026 · 18:00 UTC · version 3.0.0

WHAT CHANGED · RULE-BASED ANALYSIS

Declared capabilities changed

Product description changed from “seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...” to “read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...”.

Observed in instructions or declared skills. Runtime behavior has not been tested.

Product description

Before

seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...

After

read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...

Product description

Before

seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...

After

read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...

Declared skills

Before

[{"name":"dependency-audit","interface":{"brand_color":null,"iconography":"radar","display_name":"dependency-audit","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Audit a project's npm dependencies...

After

[{"name":"ci-pr-gate","interface":{"brand_color":null,"iconography":"code","display_name":"ci-pr-gate","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a dependency change — a before/after packa...

Id

Before

pluginrel_abc190d64f008191af6c32be52a9c4df

After

pluginrel_1e35db74309c81918693771d0841da81

Compare saved observations

Download comparison JSON
Full technical diff · 6 changed fields

changed /release/description

BEFORE
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
AFTER
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."

changed /release/id

BEFORE
"pluginrel_abc190d64f008191af6c32be52a9c4df"
AFTER
"pluginrel_1e35db74309c81918693771d0841da81"

changed /release/interface/developer_name

BEFORE
"SHYNGGYS SHYNBOLATOV"
AFTER
"SHYNGYS SHYNBOLATOV"

changed /release/interface/long_description

BEFORE
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
AFTER
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."

changed /release/skills

BEFORE
[
  {
    "name": "dependency-audit",
    "interface": {
      "brand_color": null,
      "iconography": "radar",
      "display_name": "dependency-audit",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
    },
    "description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
    "plugin_release_skill_id": "pluginrsk_6a976bffb2188191ad0b8770ba42e478"
  },
  {
    "name": "package-trust-check",
    "interface": {
      "brand_color": null,
      "iconography": "radar",
      "display_name": "package-trust-check",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
    },
    "description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
    "plugin_release_skill_id": "pluginrsk_6a976c0940308191a0bccf9befcd4cbc"
  }
]
AFTER
[
  {
    "name": "ci-pr-gate",
    "interface": {
      "brand_color": null,
      "iconography": "code",
      "display_name": "ci-pr-gate",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."
    },
    "description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).",
    "plugin_release_skill_id": "pluginrsk_6aa8829ab7cc8191937c29d6b3021817"
  },
  {
    "name": "dependency-audit",
    "interface": {
      "brand_color": null,
      "iconography": "radar",
      "display_name": "dependency-audit",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
    },
    "description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
    "plugin_release_skill_id": "pluginrsk_6aa8825150e481919b1acdd51722c07e"
  },
  {
    "name": "incident-response",
    "interface": {
      "brand_color": null,
      "iconography": "bolt",
      "display_name": "incident-response",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."
    },
    "description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).",
    "plugin_release_skill_id": "pluginrsk_6aa8825cc83881919643e10ecddf1b44"
  },
  {
    "name": "new-dependency-evaluation",
    "interface": {
      "brand_color": null,
      "iconography": "heart",
      "display_name": "new-dependency-evaluation",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."
    },
    "description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").",
    "plugin_release_skill_id": "pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"
  },
  {
    "name": "package-trust-check",
    "interface": {
      "brand_color": null,
      "iconography": "hierarchy",
      "display_name": "package-trust-check",
      "default_prompt": null,
      "icon_large_url": null,
      "icon_small_url": null,
      "short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
    },
    "description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
    "plugin_release_skill_id": "pluginrsk_6aa882a7264c8191a5daa9e688e5e052"
  }
]

changed /release/version

BEFORE
"2.0.0"
AFTER
"3.0.0"
Full snapshot data
{
  "id": "plugin_asdk_app_6a6a699e6f3481918d5e6034432894f2",
  "name": "app-6a6a699e6f3481918d5e6034432894f2",
  "scope": "GLOBAL",
  "status": "ENABLED",
  "release": {
    "id": "pluginrel_1e35db74309c81918693771d0841da81",
    "skills": [
      {
        "name": "ci-pr-gate",
        "interface": {
          "brand_color": null,
          "iconography": "code",
          "display_name": "ci-pr-gate",
          "default_prompt": null,
          "icon_large_url": null,
          "icon_small_url": null,
          "short_description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."
        },
        "description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).",
        "plugin_release_skill_id": "pluginrsk_6aa8829ab7cc8191937c29d6b3021817"
      },
      {
        "name": "dependency-audit",
        "interface": {
          "brand_color": null,
          "iconography": "radar",
          "display_name": "dependency-audit",
          "default_prompt": null,
          "icon_large_url": null,
          "icon_small_url": null,
          "short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
        },
        "description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
        "plugin_release_skill_id": "pluginrsk_6aa8825150e481919b1acdd51722c07e"
      },
      {
        "name": "incident-response",
        "interface": {
          "brand_color": null,
          "iconography": "bolt",
          "display_name": "incident-response",
          "default_prompt": null,
          "icon_large_url": null,
          "icon_small_url": null,
          "short_description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."
        },
        "description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).",
        "plugin_release_skill_id": "pluginrsk_6aa8825cc83881919643e10ecddf1b44"
      },
      {
        "name": "new-dependency-evaluation",
        "interface": {
          "brand_color": null,
          "iconography": "heart",
          "display_name": "new-dependency-evaluation",
          "default_prompt": null,
          "icon_large_url": null,
          "icon_small_url": null,
          "short_description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."
        },
        "description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").",
        "plugin_release_skill_id": "pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"
      },
      {
        "name": "package-trust-check",
        "interface": {
          "brand_color": null,
          "iconography": "hierarchy",
          "display_name": "package-trust-check",
          "default_prompt": null,
          "icon_large_url": null,
          "icon_small_url": null,
          "short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
        },
        "description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
        "plugin_release_skill_id": "pluginrsk_6aa882a7264c8191a5daa9e688e5e052"
      }
    ],
    "app_ids": [
      "asdk_app_6a6a699e6f3481918d5e6034432894f2"
    ],
    "version": "3.0.0",
    "keywords": [],
    "interface": {
      "category": "Developer Tools",
      "logo_url": "https://files.openai.com/content?id=file_0000000063f882468dd752086f6c99a7",
      "brand_color": null,
      "website_url": "https://npmscan.com/",
      "capabilities": [],
      "logo_url_dark": "https://files.openai.com/content?id=file_00000000630c8243aee15c270c53c093",
      "default_prompt": "Find npm packages for parsing CSV files",
      "developer_name": "SHYNGYS SHYNBOLATOV",
      "default_prompts": [
        "Find npm packages for parsing CSV files",
        "Is minimist 1.2.5 safe to use, or do I need to upgrade?",
        "Audit my package.json dependencies for vulnerabilities and risky install scripts"
      ],
      "screenshot_urls": [],
      "long_description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
      "composer_icon_url": "https://files.openai.com/content?id=file_000000004a3481f4940425585a62fda1",
      "short_description": "npm package & vuln lookups",
      "plugin_category_id": "developer tools",
      "privacy_policy_url": "https://npmscan.com/privacy",
      "terms_of_service_url": "https://npmscan.com/terms",
      "composer_icon_dark_url": "https://files.openai.com/content?id=file_00000000620481f4902f42d39eff7d12"
    },
    "description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
    "app_manifest": {
      "apps": {
        "app-6a6a699e6f3481918d5e6034432894f2": {
          "id": "asdk_app_6a6a699e6f3481918d5e6034432894f2",
          "required": true
        }
      }
    },
    "display_name": "NPMScan",
    "app_templates": [],
    "onboarding_skill_name": null,
    "requires_local_executor": false
  },
  "created_at": "2026-07-29T20:59:10.652584Z",
  "is_template": false,
  "connector_id": "asdk_app_6a6a699e6f3481918d5e6034432894f2",
  "discoverability": "LISTED",
  "canonical_app_id": "asdk_app_6a6a699e6f3481918d5e6034432894f2"
}

SHA-256: a268e2d1335468a42059a47e0f71096a749a28767e1712b42333cf81106a2df8