MCP低风险未认领

pkgproof

Verify an npm package before install: advisories, install scripts, typosquats, declared repository.

pkgproof.netpkgproof.net/pkgproof更新于 2026年10月8日

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "net.pkgproof/pkgproof",
  "description": "Verify an npm package before install: advisories, install scripts, typosquats, declared repository.",
  "title": "pkgproof",
  "repository": {
    "url": "https://github.com/jahija-okan/pkgproof-mcp",
    "source": "github"
  },
  "version": "0.1.11",
  "websiteUrl": "https://pkgproof.net",
  "packages": [
    {
      "registryType": "npm",
      "registryBaseUrl": "https://registry.npmjs.org",
      "identifier": "@pkgproof/mcp",
      "version": "0.1.11",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Base64 account key of a throwaway Algorand wallet holding USDC (ASA 31566704) on Algorand Mainnet. Not a 25-word mnemonic. Optional: the first verification each day is free without any key. This is the rail payments prefer.",
          "isSecret": true,
          "name": "PKGPROOF_ALGORAND_PRIVATE_KEY"
        },
        {
          "description": "0x-prefixed private key of a throwaway EVM wallet holding USDC on Base. Optional, and only used when no Algorand key is configured. Needs no ETH: payment is an off-chain signature and the facilitator pays the gas.",
          "isSecret": true,
          "name": "PKGPROOF_BASE_PRIVATE_KEY"
        }
      ]
    }
  ]
}

权限

声明检测
运行代码—node
安装—npm:@pkgproof/mcp@0.1.11
安装时运行脚本—无
网络无无
需要的凭据PKGPROOF_ALGORAND_PRIVATE_KEYPKGPROOF_BASE_PRIVATE_KEYPKGPROOF_ALGORAND_PRIVATE_KEYPKGPROOF_BASE_PRIVATE_KEY
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

版本

  1. #20.1.11最新2026年10月8日
  2. #10.1.82026年10月7日