npx-vibe MCP server
Read-only npm package and project dependency preflight tools for AI applications.
0 stars95 downloads/wk
Reviews
Write oneNobody has reviewed npx-vibe yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
npx-vibe tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
list_modelsReturn the provider model recommendations bundled with this npx-vibe release. This does not access a model provider or require credentials.
scan_packageResolve, verify, and inspect one public npm registry package without executing package code. Use before installing, recommending, or running an unfamiliar package. Obey decision.action: continue, review, stop, or retry.
scan_projectInspect public-registry dependencies from package.json and package-lock.json without installing or executing them. Direct dependencies by default; set transitive to walk the whole installed tree. Use after dependency or lockfile changes and before installation.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan19 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 18 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Install directly
Runs npx -y npx-vibe on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add npx-vibe -- npx -y npx-vibe
npx-vibe: common questions
- Is npx-vibe MCP server safe?
- Yes, by our scan: it is graded A (92/100). Read the npx-vibe safety report
- How do I install npx-vibe?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does npx-vibe need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is npx-vibe maintained?
- The last commit was 19 days ago (2026-09-02). The latest release is v1.6.0.