Update to NPMScan
Snapshot Oct 2, 2026 · 00:16 UTC · version 3.0.0
Package or technical metadata updated
Package contents changed in 14 files: .codex-plugin/plugin.json, skills/ci-pr-gate/SKILL.md, skills/ci-pr-gate/agents/openai.yaml, …. Open the file diff to inspect the edits.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Package file
e1180ae4c300815d9aac03be971e91190c499653920b0047d7c7b9a88e4ea4c1
6482042fa1f2d1ca1793a41b3fa72b145e6d4e18e83985baf33f7b82646e7238
Package file
3336
4948
Package file
Not present
{"sha256":"311a5ea8af307f51df42801d1031c8ec4d906134a1e83623d3802cfadce1bec5","size":10799}
Package file
Not present
{"sha256":"f620ec7378056cbae153fb6e13d095f6d74d8045e53ecd5b17a803e9c8f83c68","size":270}
Compare saved observations
Download comparison JSONChanged files
skills/ci-pr-gate/agents/openai.yaml →
skills/ci-pr-gate/references/test-prompts.md →
skills/dependency-audit/SKILL.md →
skills/dependency-audit/references/test-prompts.md →
skills/incident-response/SKILL.md →
skills/incident-response/agents/openai.yaml →
skills/incident-response/references/test-prompts.md →
skills/new-dependency-evaluation/SKILL.md →
skills/new-dependency-evaluation/agents/openai.yaml →
skills/new-dependency-evaluation/references/test-prompts.md →
.codex-plugin/plugin.json
--- before +++ after @@ -1,9 +1,9 @@ { "apps": "./.app.json", "author": { - "name": "SHYNGGYS SHYNBOLATOV" + "name": "SHYNGYS SHYNBOLATOV" }, - "description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.", + "description": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.", "interface": { "capabilities": [], "category": "Developer Tools", @@ -12,9 +12,9 @@ "Is minimist 1.2.5 safe to use, or do I need to upgrade?", "Audit my package.json dependencies for vulnerabilities and risky install scripts" ], - "developerName": "SHYNGGYS SHYNBOLATOV", + "developerName": "SHYNGYS SHYNBOLATOV", "displayName": "NPMScan", - "longDescription": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.", + "longDescription": "Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.", "privacyPolicyURL": "https://npmscan.com/privacy", "shortDescription": "npm package & vuln lookups", "supportURL": "https://npmscan.com/protect-my-project", @@ -23,5 +23,5 @@ }, "name": "app-6a6a699e6f3481918d5e6034432894f2", "skills": "./skills", - "version": "2.0.0" + "version": "3.0.0" } \ No newline at end of file
Full technical diff · 19 changed fields
changed /files/.codex-plugin~1plugin.json/sha256
"e1180ae4c300815d9aac03be971e91190c499653920b0047d7c7b9a88e4ea4c1"
"6482042fa1f2d1ca1793a41b3fa72b145e6d4e18e83985baf33f7b82646e7238"
changed /files/.codex-plugin~1plugin.json/size
3336
4948
added /files/skills~1ci-pr-gate~1SKILL.md
Field was absent
{
"sha256": "311a5ea8af307f51df42801d1031c8ec4d906134a1e83623d3802cfadce1bec5",
"size": 10799
}added /files/skills~1ci-pr-gate~1agents~1openai.yaml
Field was absent
{
"sha256": "f620ec7378056cbae153fb6e13d095f6d74d8045e53ecd5b17a803e9c8f83c68",
"size": 270
}added /files/skills~1ci-pr-gate~1references~1test-prompts.md
Field was absent
{
"sha256": "241917a0489dc0a5ee72acccd616997415bfb0a18fe119449efb97bfd4668b08",
"size": 10870
}changed /files/skills~1dependency-audit~1SKILL.md/sha256
"acd365ac39e69396553693cae7e900dc948b4dda792405d6a0703605571a75e6"
"c22beba035f436d32e9bf22a3ff1a0e3ae255ba4718d3f5b49f2ab787732d9b7"
changed /files/skills~1dependency-audit~1SKILL.md/size
12330
15751
changed /files/skills~1dependency-audit~1references~1test-prompts.md/sha256
"ee2f665fd1bf690d85e29fb2b378b453895cfe6bc4b79fcfa99494da0117ef5e"
"a3c7b9c9e0c161b3eb07ff3f9a802d6e0fc4cff125d18503b3b92012b90afaf9"
changed /files/skills~1dependency-audit~1references~1test-prompts.md/size
8800
17075
added /files/skills~1incident-response~1SKILL.md
Field was absent
{
"sha256": "ff83783720f5a63ffdba1b0d2a800044eecaa5a9570d795712ec139b7dda3d90",
"size": 9114
}added /files/skills~1incident-response~1agents~1openai.yaml
Field was absent
{
"sha256": "13ed660fe369be361892c028217fc7d27f0a0bcab98ad965271db54331adadc7",
"size": 293
}added /files/skills~1incident-response~1references~1test-prompts.md
Field was absent
{
"sha256": "ba2ab3fcd29e7435de1723c48ecae0de9dcbdb2218a8da73040f94b229f72536",
"size": 10772
}added /files/skills~1new-dependency-evaluation~1SKILL.md
Field was absent
{
"sha256": "3dad9cfb6d77beb73cd75261a3f111768fdd4973e291accc38983d63e4a536d8",
"size": 13357
}added /files/skills~1new-dependency-evaluation~1agents~1openai.yaml
Field was absent
{
"sha256": "93c7385ba42c9de08fff152f50f9bc1f5cca79a3fa428eede6c047ea4a161a71",
"size": 294
}added /files/skills~1new-dependency-evaluation~1references~1test-prompts.md
Field was absent
{
"sha256": "91699e23bffb7d10d1a250df7e4715a70194b279f253e9befb940a411fbd2e8b",
"size": 9542
}changed /files/skills~1package-trust-check~1SKILL.md/sha256
"809377cfcc20063734cece31f6db7228498d2c7cf5c41ff4ed6e797d01d90ea7"
"9fb514f8f06cf2e81c308d0cd556fdc88cec1fd9edb2a946bcf78f47e300a7f6"
changed /files/skills~1package-trust-check~1SKILL.md/size
6858
7089
changed /files/skills~1package-trust-check~1references~1test-prompts.md/sha256
"2978684b378b11d919676231677e7b8d20591e1168f9e7df4cd77d008b6a5093"
"af531aa470124b0281d265e4d2ae9109303a7ddd0fe960006e02f9395746db97"
changed /files/skills~1package-trust-check~1references~1test-prompts.md/size
6156
8725
Full snapshot data
{
"files": {
".app.json": {
"sha256": "894d21afb02217de7f3e5417c1efef318bf3d7032b4b87b70b4ba97825afac90",
"size": 127
},
".codex-plugin/plugin.json": {
"sha256": "6482042fa1f2d1ca1793a41b3fa72b145e6d4e18e83985baf33f7b82646e7238",
"size": 4948
},
"skills/ci-pr-gate/SKILL.md": {
"sha256": "311a5ea8af307f51df42801d1031c8ec4d906134a1e83623d3802cfadce1bec5",
"size": 10799
},
"skills/ci-pr-gate/agents/openai.yaml": {
"sha256": "f620ec7378056cbae153fb6e13d095f6d74d8045e53ecd5b17a803e9c8f83c68",
"size": 270
},
"skills/ci-pr-gate/references/test-prompts.md": {
"sha256": "241917a0489dc0a5ee72acccd616997415bfb0a18fe119449efb97bfd4668b08",
"size": 10870
},
"skills/dependency-audit/SKILL.md": {
"sha256": "c22beba035f436d32e9bf22a3ff1a0e3ae255ba4718d3f5b49f2ab787732d9b7",
"size": 15751
},
"skills/dependency-audit/agents/openai.yaml": {
"sha256": "f620ec7378056cbae153fb6e13d095f6d74d8045e53ecd5b17a803e9c8f83c68",
"size": 270
},
"skills/dependency-audit/references/test-prompts.md": {
"sha256": "a3c7b9c9e0c161b3eb07ff3f9a802d6e0fc4cff125d18503b3b92012b90afaf9",
"size": 17075
},
"skills/incident-response/SKILL.md": {
"sha256": "ff83783720f5a63ffdba1b0d2a800044eecaa5a9570d795712ec139b7dda3d90",
"size": 9114
},
"skills/incident-response/agents/openai.yaml": {
"sha256": "13ed660fe369be361892c028217fc7d27f0a0bcab98ad965271db54331adadc7",
"size": 293
},
"skills/incident-response/references/test-prompts.md": {
"sha256": "ba2ab3fcd29e7435de1723c48ecae0de9dcbdb2218a8da73040f94b229f72536",
"size": 10772
},
"skills/new-dependency-evaluation/SKILL.md": {
"sha256": "3dad9cfb6d77beb73cd75261a3f111768fdd4973e291accc38983d63e4a536d8",
"size": 13357
},
"skills/new-dependency-evaluation/agents/openai.yaml": {
"sha256": "93c7385ba42c9de08fff152f50f9bc1f5cca79a3fa428eede6c047ea4a161a71",
"size": 294
},
"skills/new-dependency-evaluation/references/test-prompts.md": {
"sha256": "91699e23bffb7d10d1a250df7e4715a70194b279f253e9befb940a411fbd2e8b",
"size": 9542
},
"skills/package-trust-check/SKILL.md": {
"sha256": "9fb514f8f06cf2e81c308d0cd556fdc88cec1fd9edb2a946bcf78f47e300a7f6",
"size": 7089
},
"skills/package-trust-check/agents/openai.yaml": {
"sha256": "f620ec7378056cbae153fb6e13d095f6d74d8045e53ecd5b17a803e9c8f83c68",
"size": 270
},
"skills/package-trust-check/references/test-prompts.md": {
"sha256": "af531aa470124b0281d265e4d2ae9109303a7ddd0fe960006e02f9395746db97",
"size": 8725
}
}
}SHA-256 of public snapshot: 67f0c05669a37573e91dd731d17b0202937c74c2e59218aabc989db00fbd31d0