Pkgtruth MCP server
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
4 stars77 downloads/wk
Reviews
Write oneNobody has reviewed Pkgtruth yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Pkgtruth tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_dependenciesVerify many npm or PyPI packages at once — use this before writing a package.json or requirements.txt,
check_install_commandVerify the packages a shell command would install or execute, before running it:
check_packageVerify a single npm or PyPI package before installing, importing, or recommending it.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- Code scan13 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 6 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Install directly
Runs npx -y pkgtruth on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add pkgtruth -- npx -y pkgtruth
Pkgtruth: common questions
- Is Pkgtruth MCP server safe?
- Yes, by our scan: it is graded A (89/100). Read the Pkgtruth safety report
- How do I install Pkgtruth?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Pkgtruth need an API key?
- No secret keys are declared. It reads 4 settings from the environment.
- Is Pkgtruth maintained?
- The last commit was 6 days ago (2026-09-14). The latest release is v0.2.2.
- What can I use instead of Pkgtruth?
- Servers from other publishers that do the same job: SkillTotal MCP server, mcpm MCP server and MCP server. Compare all Pkgtruth alternatives.
Alternatives to Pkgtruth
Same job from other publishers: the closest match first, then the best rated.
- SkillTotalDeterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.not reviewedGrowingB
- mcpmMCP security guard + package manager: trust-scored installs, blocks prompt injection and rug-pulls.not reviewedGrowingB
- MCPAuthorize consequential AI agent actions before executionnot reviewedEstablishedA
- ProjectmemCoding agent memory — one local MCP server for every project. Warns before repeating failed fixes.not reviewedGrowingA
- LockstepDecision memory for AI coding agents: captures decisions once, briefs every agent before it acts.not reviewedGrowingA