MCP低风险未认领
pkgtruth
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
hxckyahxckya/pkgtruth
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.hxckya/pkgtruth",
"description": "Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.",
"repository": {
"url": "https://github.com/hxckya/pkgtruth",
"source": "github"
},
"version": "0.2.2",
"packages": [
{
"registryType": "npm",
"identifier": "pkgtruth",
"version": "0.2.2",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Alternate npm registry to verify against. Defaults to https://registry.npmjs.org.",
"format": "string",
"name": "PKGTRUTH_REGISTRY"
},
{
"description": "Alternate downloads API used for adoption figures. Defaults to https://api.npmjs.org.",
"format": "string",
"name": "PKGTRUTH_DOWNLOADS_API"
},
{
"description": "Where adoption figures are cached between runs. Defaults to ~/.cache/pkgtruth.",
"format": "string",
"name": "PKGTRUTH_CACHE_DIR"
},
{
"description": "Per-request timeout in milliseconds. Defaults to 8000.",
"format": "number",
"name": "PKGTRUTH_TIMEOUT_MS"
}
]
}
]
}权限
声明检测
运行代码—
node安装—
npm:pkgtruth@0.2.2安装时运行脚本—无
网络无无
需要的凭据无无
工作区外的路径—无
智能体工具—无
检查
低风险 · 没有发现需要提醒的地方。
未经人工审核 · 已做规则检查;模型审核尚未开启。
版本
- #10.2.2最新2026年10月7日
pkgtruth在 Codeg 中打开