Update to NPMScan
Snapshot Oct 1, 2026 · 18:00 UTC · version 3.0.0
Declared capabilities changed
Product description changed from “seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...” to “read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...”.
Observed in instructions or declared skills. Runtime behavior has not been tested.
Product description
seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...
read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...
Product description
seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detecti...
read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typos...
Declared skills
[{"name":"dependency-audit","interface":{"brand_color":null,"iconography":"radar","display_name":"dependency-audit","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Audit a project's npm dependencies...
[{"name":"ci-pr-gate","interface":{"brand_color":null,"iconography":"code","display_name":"ci-pr-gate","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Turn a dependency change — a before/after packa...
Id
pluginrel_abc190d64f008191af6c32be52a9c4df
pluginrel_1e35db74309c81918693771d0841da81
Compare saved observations
Download comparison JSONFull technical diff · 6 changed fields
changed /release/description
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
changed /release/id
"pluginrel_abc190d64f008191af6c32be52a9c4df"
"pluginrel_1e35db74309c81918693771d0841da81"
changed /release/interface/developer_name
"SHYNGGYS SHYNBOLATOV"
"SHYNGYS SHYNBOLATOV"
changed /release/interface/long_description
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
"Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com."
changed /release/skills
[
{
"name": "dependency-audit",
"interface": {
"brand_color": null,
"iconography": "radar",
"display_name": "dependency-audit",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
},
"description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
"plugin_release_skill_id": "pluginrsk_6a976bffb2188191ad0b8770ba42e478"
},
{
"name": "package-trust-check",
"interface": {
"brand_color": null,
"iconography": "radar",
"display_name": "package-trust-check",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
},
"description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
"plugin_release_skill_id": "pluginrsk_6a976c0940308191a0bccf9befcd4cbc"
}
][
{
"name": "ci-pr-gate",
"interface": {
"brand_color": null,
"iconography": "code",
"display_name": "ci-pr-gate",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."
},
"description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).",
"plugin_release_skill_id": "pluginrsk_6aa8829ab7cc8191937c29d6b3021817"
},
{
"name": "dependency-audit",
"interface": {
"brand_color": null,
"iconography": "radar",
"display_name": "dependency-audit",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
},
"description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
"plugin_release_skill_id": "pluginrsk_6aa8825150e481919b1acdd51722c07e"
},
{
"name": "incident-response",
"interface": {
"brand_color": null,
"iconography": "bolt",
"display_name": "incident-response",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."
},
"description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).",
"plugin_release_skill_id": "pluginrsk_6aa8825cc83881919643e10ecddf1b44"
},
{
"name": "new-dependency-evaluation",
"interface": {
"brand_color": null,
"iconography": "heart",
"display_name": "new-dependency-evaluation",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."
},
"description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").",
"plugin_release_skill_id": "pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"
},
{
"name": "package-trust-check",
"interface": {
"brand_color": null,
"iconography": "hierarchy",
"display_name": "package-trust-check",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
},
"description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
"plugin_release_skill_id": "pluginrsk_6aa882a7264c8191a5daa9e688e5e052"
}
]changed /release/version
"2.0.0"
"3.0.0"
Full snapshot data
{
"id": "plugin_asdk_app_6a6a699e6f3481918d5e6034432894f2",
"name": "app-6a6a699e6f3481918d5e6034432894f2",
"scope": "GLOBAL",
"status": "ENABLED",
"release": {
"id": "pluginrel_1e35db74309c81918693771d0841da81",
"skills": [
{
"name": "ci-pr-gate",
"interface": {
"brand_color": null,
"iconography": "code",
"display_name": "ci-pr-gate",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check)."
},
"description": "Turn a dependency change — a before/after package.json/lockfile snapshot, or one or more named \"bump X from A to B\" upgrades — into one deterministic PASS/WARN/FAIL verdict formatted for a CI check or PR-comment bot, not a conversational report. Use when the user explicitly wants a mergeable/blocking verdict, a \"CI gate,\" a PR status comment, or asks \"should this PR be blocked,\" \"is this safe to merge,\" \"gate this dependency bump.\" Not for a plain explanation of what changed in a diff (dependency-audit's own snapshot-diff flow already covers that conversationally) and not for a single already-installed package's trust investigation (package-trust-check).",
"plugin_release_skill_id": "pluginrsk_6aa8829ab7cc8191937c29d6b3021817"
},
{
"name": "dependency-audit",
"interface": {
"brand_color": null,
"iconography": "radar",
"display_name": "dependency-audit",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance."
},
"description": "Audit a project's npm dependencies for known vulnerabilities and risky install scripts before installing, upgrading, or shipping. Use when the user pastes or attaches a package.json/lockfile, lists dependencies, or asks to check/audit/scan their packages for security issues — including comparing two snapshots (a PR diff) or checking license compliance.",
"plugin_release_skill_id": "pluginrsk_6aa8825150e481919b1acdd51722c07e"
},
{
"name": "incident-response",
"interface": {
"brand_color": null,
"iconography": "bolt",
"display_name": "incident-response",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that)."
},
"description": "Turn a flagged npm supply-chain finding — or just a vague, non-technical description of one (\"this package looks sketchy,\" \"someone said we got hacked,\" \"npm install did something weird\") — into concrete remediation steps. Use whenever the user wants to know what to actually do about a suspicious/compromised/flagged package, however precisely or vaguely they describe it — not for the initial trust/vulnerability investigation itself (see package-trust-check/dependency-audit for that).",
"plugin_release_skill_id": "pluginrsk_6aa8825cc83881919643e10ecddf1b44"
},
{
"name": "new-dependency-evaluation",
"interface": {
"brand_color": null,
"iconography": "heart",
"display_name": "new-dependency-evaluation",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\")."
},
"description": "Help decide what to add as a NEW npm dependency — comparing 2-5 named candidates for the same job, evaluating one named candidate against its real peers, or shortlisting candidates from a described need, before anything is installed. Use for \"which should we use for X,\" \"axios vs got vs node-fetch,\" \"is X a good pick for Y,\" \"what should we use to do Z,\" \"should we add X or is there something better.\" Not for auditing packages already in the project (see dependency-audit), not for a deep single-package compromise/trust investigation (see package-trust-check), and not for a plain factual question with no choice being made (\"what does X do\").",
"plugin_release_skill_id": "pluginrsk_6aa882a41b3481918b3b93986c8d4a7a"
},
{
"name": "package-trust-check",
"interface": {
"brand_color": null,
"iconography": "hierarchy",
"display_name": "package-trust-check",
"default_prompt": null,
"icon_large_url": null,
"icon_small_url": null,
"short_description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\""
},
"description": "Investigate whether one specific npm package is trustworthy — maintainer/ownership takeover signals, publish-provenance mismatches, and risky install scripts. Use when the user asks if a single named package is safe, compromised, hijacked, suspicious, or \"can I trust this\" — not for auditing a full package.json/lockfile (see dependency-audit) and not for a plain factual question like \"what does X do.\"",
"plugin_release_skill_id": "pluginrsk_6aa882a7264c8191a5daa9e688e5e052"
}
],
"app_ids": [
"asdk_app_6a6a699e6f3481918d5e6034432894f2"
],
"version": "3.0.0",
"keywords": [],
"interface": {
"category": "Developer Tools",
"logo_url": "https://files.openai.com/content?id=file_0000000063f882468dd752086f6c99a7",
"brand_color": null,
"website_url": "https://npmscan.com/",
"capabilities": [],
"logo_url_dark": "https://files.openai.com/content?id=file_00000000630c8243aee15c270c53c093",
"default_prompt": "Find npm packages for parsing CSV files",
"developer_name": "SHYNGYS SHYNBOLATOV",
"default_prompts": [
"Find npm packages for parsing CSV files",
"Is minimist 1.2.5 safe to use, or do I need to upgrade?",
"Audit my package.json dependencies for vulnerabilities and risky install scripts"
],
"screenshot_urls": [],
"long_description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
"composer_icon_url": "https://files.openai.com/content?id=file_000000004a3481f4940425585a62fda1",
"short_description": "npm package & vuln lookups",
"plugin_category_id": "developer tools",
"privacy_policy_url": "https://npmscan.com/privacy",
"terms_of_service_url": "https://npmscan.com/terms",
"composer_icon_dark_url": "https://files.openai.com/content?id=file_00000000620481f4902f42d39eff7d12"
},
"description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.",
"app_manifest": {
"apps": {
"app-6a6a699e6f3481918d5e6034432894f2": {
"id": "asdk_app_6a6a699e6f3481918d5e6034432894f2",
"required": true
}
}
},
"display_name": "NPMScan",
"app_templates": [],
"onboarding_skill_name": null,
"requires_local_executor": false
},
"created_at": "2026-07-29T20:59:10.652584Z",
"is_template": false,
"connector_id": "asdk_app_6a6a699e6f3481918d5e6034432894f2",
"discoverability": "LISTED",
"canonical_app_id": "asdk_app_6a6a699e6f3481918d5e6034432894f2"
}SHA-256: a268e2d1335468a42059a47e0f71096a749a28767e1712b42333cf81106a2df8