Npm Sentinel MCP server
Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
18 stars559 downloads/wk
Reviews
Write oneNobody has reviewed Npm Sentinel yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Npm Sentinel tools (19)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
npmAlternativesFind alternative packages with similar functionality
npmChangelogAnalysisAnalyze changelog and release history of packages
npmCompareCompare multiple NPM packages based on various metrics
npmDeprecatedCheck if packages are deprecated
npmDepsAnalyze dependencies and devDependencies of an NPM package
npmLatestGet the latest version and changelog of an NPM package
npmLicenseCompatibilityCheck license compatibility between multiple packages
npmMaintainersGet maintainers information for NPM packages
npmMaintenanceAnalyze package maintenance metrics
npmPackageReadmeGet the README content for NPM packages
npmQualityAnalyze package quality metrics
npmRepoStatsGet repository statistics for NPM packages
npmScoreGet consolidated package score based on quality, maintenance, and popularity metrics
npmSearchSearch for NPM packages with optional limit
npmSizeGet package size information including dependencies and bundle size
npmTrendsGet download trends and popularity metrics for packages
npmTypesCheck TypeScript types availability and version for a package
npmVersionsGet all available versions of an NPM package
npmVulnerabilitiesCheck for known vulnerabilities in packages
Public scan report
scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it
- Code scan32 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 28 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
What the publisher says
From the Npm Sentinel repository's README, as published. We do not edit it. Read it on GitHub
NPM Sentinel MCP
A powerful Model Context Protocol (MCP v2) server built on @modelcontextprotocol/server and @modelcontextprotocol/core (v2) that revolutionizes NPM package analysis through AI. Built to integrate seamlessly with Claude, Anthropic AI, and any MCP v2 compatible client, it provides real-time intelligence on package security, dependencies, and performance.
This server features Modular ESM Architecture (src/), Dual Output Protocol Returns (content + structuredContent), Zod Output Schemas (outputSchema), Embedded SVG Data URI Icons, and Real-Time Context Logging.
Key Features
- MCP v2 Native Protocol: Fully upgraded to MCP v2 with outputSchema Zod validation, dual structuredContent returning, and diagnostic context logging (ctx.mcpReq.log).
- Self-Contained Vector Icons: Pre-configured SVG Data URIs (data:image/svg+xml) embedded across all 19 tools, resources, and prompts for enhanced client UI presentation.
- Advanced Security Scanning: Recursive dependency checks powered by Google's deps.dev and OSV.dev, ecosystem awareness, and accurate version resolution.
- Smart Alternatives Filtering (npmAlternatives): Intelligent search based on functional domain keywords with strict ecosystem plugin/extension filtering (e.g., excludes express-rate-limit when searching for alternatives to express).
- Strict Input Validation & Batch Rate Control: Input sanitization via Zod against Path Traversal, SSRF, and Command Injection. Search queries (npmSearch) are capped at 100 characters and filtered for control characters. Batch analysis tools enforce a strict cap of 25 packages per request to prevent registry enumeration DoS.
- Dependency & Transitive Mapping: Complete dependency tree analysis mapping through deps.dev.
- Package Quality & Maintenance Metrics: Real-time scoring using OpenSSF Scorecard, GitHub repository metrics, and npms.io.
- Download Trends & Performance: Real-time download statistics and bundle size analysis.
- Smart SemVer Shorthand & Range Resolution: Transparently resolves major version shorthands, prefixes, and ranges (e.g., express@2, express@v4, zod@3.x, react@^18, lodash@~4.17) to the highest matching release without failing on missing exact version keys.
- Indirect Prompt Injection Defense (OWASP LLM01): All tools returning raw 3rd-party Markdown/text (npmPackageReadme, npmChangelogAnalysis) wrap untrusted content in tags, attach _meta.untrustedExternalContent = true flags, and enforce strict tool schema warnings.
- Efficient Caching System: Automated cache invalidation on workspace lockfile changes (pnpm-lock.yaml, package-lock.json, yarn.lock) with manual bypass (ignoreCache: true).
Security & OWASP LLM01 Compliance
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
Runs npx -y @nekzus/mcp-server on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add npm-sentinel-mcp -- npx -y @nekzus/mcp-server
Npm Sentinel: common questions
- Is Npm Sentinel MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the Npm Sentinel safety report
- How do I install Npm Sentinel?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Npm Sentinel need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Npm Sentinel maintained?
- The last commit was 28 days ago (2026-08-24). The latest release is v1.26.1.
- What can I use instead of Npm Sentinel?
- Servers from other publishers that do the same job: npm Registry MCP Server, CrowdStrike Falcon MCP Server and Reversecore MCP server. Compare all Npm Sentinel alternatives.
Alternatives to Npm Sentinel
Same job from other publishers: the closest match first, then the best rated.
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- CrowdStrike Falcon MCP ServerConnects AI agents with CrowdStrike Falcon for security analysis and automation.not reviewedEstablishedA
- Reversecore MCPSecurity-first MCP server for reverse engineering, malware analysis, forensics, and SAST.not reviewedEstablishedB
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA