Mmcp.market

Npm Sentinel MCP server

by Nekzus·io.github.Nekzus/npm-sentinel-mcp·v1.26.1

Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.

A92/100grade A
What users say
No reviews yet
Be the first
Safety scan
A92/100

full report

Adoption
Growing

18 stars559 downloads/wk

Reviews

Write one

Nobody has reviewed Npm Sentinel yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Npm Sentinel tools (19)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • npmAlternatives

    Find alternative packages with similar functionality

  • npmChangelogAnalysis

    Analyze changelog and release history of packages

  • npmCompare

    Compare multiple NPM packages based on various metrics

  • npmDeprecated

    Check if packages are deprecated

  • npmDeps

    Analyze dependencies and devDependencies of an NPM package

  • npmLatest

    Get the latest version and changelog of an NPM package

  • npmLicenseCompatibility

    Check license compatibility between multiple packages

  • npmMaintainers

    Get maintainers information for NPM packages

  • npmMaintenance

    Analyze package maintenance metrics

  • npmPackageReadme

    Get the README content for NPM packages

  • npmQuality

    Analyze package quality metrics

  • npmRepoStats

    Get repository statistics for NPM packages

  • npmScore

    Get consolidated package score based on quality, maintenance, and popularity metrics

  • npmSearch

    Search for NPM packages with optional limit

  • npmSize

    Get package size information including dependencies and bundle size

  • npmTrends

    Get download trends and popularity metrics for packages

  • npmTypes

    Check TypeScript types availability and version for a package

  • npmVersions

    Get all available versions of an NPM package

  • npmVulnerabilities

    Check for known vulnerabilities in packages

Public scan report

scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it

no findings
  • Code scan32 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 28 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 92/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

What the publisher says

From the Npm Sentinel repository's README, as published. We do not edit it. Read it on GitHub

NPM Sentinel MCP

A powerful Model Context Protocol (MCP v2) server built on @modelcontextprotocol/server and @modelcontextprotocol/core (v2) that revolutionizes NPM package analysis through AI. Built to integrate seamlessly with Claude, Anthropic AI, and any MCP v2 compatible client, it provides real-time intelligence on package security, dependencies, and performance.

This server features Modular ESM Architecture (src/), Dual Output Protocol Returns (content + structuredContent), Zod Output Schemas (outputSchema), Embedded SVG Data URI Icons, and Real-Time Context Logging.

Key Features

  • MCP v2 Native Protocol: Fully upgraded to MCP v2 with outputSchema Zod validation, dual structuredContent returning, and diagnostic context logging (ctx.mcpReq.log).
  • Self-Contained Vector Icons: Pre-configured SVG Data URIs (data:image/svg+xml) embedded across all 19 tools, resources, and prompts for enhanced client UI presentation.
  • Advanced Security Scanning: Recursive dependency checks powered by Google's deps.dev and OSV.dev, ecosystem awareness, and accurate version resolution.
  • Smart Alternatives Filtering (npmAlternatives): Intelligent search based on functional domain keywords with strict ecosystem plugin/extension filtering (e.g., excludes express-rate-limit when searching for alternatives to express).
  • Strict Input Validation & Batch Rate Control: Input sanitization via Zod against Path Traversal, SSRF, and Command Injection. Search queries (npmSearch) are capped at 100 characters and filtered for control characters. Batch analysis tools enforce a strict cap of 25 packages per request to prevent registry enumeration DoS.
  • Dependency & Transitive Mapping: Complete dependency tree analysis mapping through deps.dev.
  • Package Quality & Maintenance Metrics: Real-time scoring using OpenSSF Scorecard, GitHub repository metrics, and npms.io.
  • Download Trends & Performance: Real-time download statistics and bundle size analysis.
  • Smart SemVer Shorthand & Range Resolution: Transparently resolves major version shorthands, prefixes, and ranges (e.g., express@2, express@v4, zod@3.x, react@^18, lodash@~4.17) to the highest matching release without failing on missing exact version keys.
  • Indirect Prompt Injection Defense (OWASP LLM01): All tools returning raw 3rd-party Markdown/text (npmPackageReadme, npmChangelogAnalysis) wrap untrusted content in tags, attach _meta.untrustedExternalContent = true flags, and enforce strict tool schema warnings.
  • Efficient Caching System: Automated cache invalidation on workspace lockfile changes (pnpm-lock.yaml, package-lock.json, yarn.lock) with manual bypass (ignoreCache: true).

Security & OWASP LLM01 Compliance

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

Install directly

Runs npx -y @nekzus/mcp-server on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add npm-sentinel-mcp -- npx -y @nekzus/mcp-server
Add to Cursor

Npm Sentinel: common questions

Is Npm Sentinel MCP server safe?
Yes, by our scan: it is graded A (92/100). Read the Npm Sentinel safety report
How do I install Npm Sentinel?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Npm Sentinel need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Npm Sentinel maintained?
The last commit was 28 days ago (2026-08-24). The latest release is v1.26.1.
What can I use instead of Npm Sentinel?
Servers from other publishers that do the same job: npm Registry MCP Server, CrowdStrike Falcon MCP Server and Reversecore MCP server. Compare all Npm Sentinel alternatives.

Alternatives to Npm Sentinel

Same job from other publishers: the closest match first, then the best rated.

All Npm Sentinel alternatives →
  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B
  • CrowdStrike Falcon MCP Server
    Connects AI agents with CrowdStrike Falcon for security analysis and automation.
    A
  • Reversecore MCP
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
    B
  • MCPProxy
    Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
    B
  • Draugr
    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
    A

More from Nekzus