Faceabot

Catalog › io.github.tylerscomic-lab/npm-supply-chain-audit-mcp

Is npm Supply Chain Audit reliable?

Not measured yet Not measured yet. Faceabot will test it automatically; you can speed this up with the MCP tool check_reliability.

En français : Pas encore mesuré. Faceabot teste cet outil lui-même, en continu, sans dépendre de ce que son auteur affirme.

What it does

Check npm packages for typosquats, hallucinated names, install scripts and risky new releases.

Source: official MCP registry (registry.modelcontextprotocol.io) · version 1.1.0 · publisher website
Connect your agent
{
  "mcpServers": {
    "npm-supply-chain-audit-mcp": {
      "url": "https://npm-supply-chain-audit-mcp.mcpize.run/mcp"
    }
  }
}
Or ask Faceabot first: MCP tool check_reliability {"id":"io.github.tylerscomic-lab/npm-supply-chain-audit-mcp"} on https://faceabot.com/api/mcp.
Does it actually do the job?

Not tested with a real task yet. Faceabot only runs real tasks on tools that declare themselves read-only (readOnlyHint), with a neutral sample input.

Faceabot measurements

No measurement yet.

Method: MCP initialize then tools/list from Faceabot (FaceabotProbe/1.0), plus one read-only tool call with a neutral input when the server declares one, repeated over time. This checks that the server is up and speaks MCP correctly; it does not certify the quality or safety of each tool. How measurement works.

Similar tools

pkgproof Not measured yet

Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.

Package npm : @pkgproof/mcp · website · measurements and details
npm Name Shape Not measured yet

Check an npm package name shape. Name discarded.

MCP endpoint : https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/npm-name-shape/mcp · website · measurements and details
pkg-oracle — Dependency Trust Oracle Not measured yet

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

MCP endpoint : https://mcp-snowy-dew-9447.fly.dev/mcp · measurements and details
Presend MCP Server Not measured yet

Before an AI agent installs an npm/PyPI package: typosquat, vulnerability and existence checks.

MCP endpoint : https://presend.pages.dev/mcp · website · measurements and details
package-guard-mcp Not measured yet

Supply-chain guard for AI coding agents: verify packages, check vulns/malware, detect typosquats.

Package npm : package-guard-mcp · website · measurements and details
Publisher of npm Supply Chain Audit?

Show your measured reliability on your README or website:

Faceabot reliability badge for npm Supply Chain Audit

[![Measured by Faceabot](https://faceabot.com/badge/io.github.tylerscomic-lab/npm-supply-chain-audit-mcp.svg)](https://faceabot.com/tools/io.github.tylerscomic-lab/npm-supply-chain-audit-mcp)
Data in JSON: /api/catalog?id=io.github.tylerscomic-lab/npm-supply-chain-audit-mcp · Stop probes: POST /api/reliability/opt-out

AI agents: all of this is available without keys over MCP https://faceabot.com/api/mcp · HTTP https://faceabot.com/api/catalog?q=… · Guide : llms.txt

Pulse: what is changing in agent commerce · Is your store ready for AI shopping agents? · State of MCP (weekly) · MCP server doctor · Open reliability data