Mmcp.market

pkg-oracle — Dependency Trust Oracle MCP server

by julian-martin89·io.github.julian-martin89/pkg-oracle·v1.0.1

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

C67/100grade C
What users say
No reviews yet
Be the first
Safety scan
C67/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed pkg-oracle — Dependency Trust Oracle yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

pkg-oracle — Dependency Trust Oracle tools (1)

write = sends, deletes, buys or posts
  • verify_packageFree

    Dependency Trust Oracle. Call this BEFORE writing any package into a manifest (package.json, requirements.txt, pyproject.toml, ...). It checks whether the package actually exists on its registry, cross-references OSV.dev for known CVEs, pulls the package's OpenSSF Scorecard via deps.dev, and runs a Levenshtein-distance typosquat/slopsquat check against a curated list of popular packages combined with the package's publish age. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings before installing), or BLOCK (do not install — likely a hallucinated package name, an active typosquat, or a known critical/high-severity vulnerability). Always call this before running an install command for a package you have not already verified in this session. First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

1 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 584ms20/20
  • Tool poisoning1 tool descriptions checked15/15
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenanceno repository listed3/15
  • Maintainer identityno repository or website to verify2/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 67/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http pkg-oracle https://mcp-snowy-dew-9447.fly.dev/mcp
Add to Cursor

pkg-oracle — Dependency Trust Oracle: common questions

Is pkg-oracle — Dependency Trust Oracle MCP server safe?
With care: it is graded C, so read the findings first (67/100). Read the pkg-oracle — Dependency Trust Oracle safety report
How do I install pkg-oracle — Dependency Trust Oracle?
It runs remotely at mcp-snowy-dew-9447.fly.dev. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does pkg-oracle — Dependency Trust Oracle need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is pkg-oracle — Dependency Trust Oracle maintained?
The latest release is v1.0.1.
Is pkg-oracle — Dependency Trust Oracle up?
100% of our last 5 checks got an answer. We check remote servers about four times a day.
What can I use instead of pkg-oracle — Dependency Trust Oracle?
Servers from other publishers that do the same job: SkillTotal MCP server, mcpm MCP server and Agent Wormhole MCP server. Compare all pkg-oracle — Dependency Trust Oracle alternatives.

Alternatives to pkg-oracle — Dependency Trust Oracle

Same job from other publishers: the closest match first, then the best rated.

All pkg-oracle — Dependency Trust Oracle alternatives →
  • SkillTotal
    Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
    B
  • mcpm
    MCP security guard + package manager: trust-scored installs, blocks prompt injection and rug-pulls.
    B
  • Agent Wormhole
    Check tokens, pages and x402 payments before your agent trusts them. Offline verdicts.
    B
  • MCP
    Authorize consequential AI agent actions before execution
    A
  • mcptoon
    MCP tools + agent skills in one zero-dependency CLI: 71,929 -> 581 tokens (-99.2%, measured).
    A

More from julian-martin89