Verify npm packages before your AI agent installs them: hallucinations, advisories, API drift.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
The verification layer for everything your agent installs.
Your coding agent picks npm packages from memory. lurq checks them against the live
registry, security advisories, shipped type definitions and real co-installs, before
anything lands in package.json.
Install · For AI agents · MCP tools · CLI · Autopilot · Docs
Real output, not a mockup. Your agent gets the same answers over MCP.
A model's knowledge of npm stops at its training cutoff. The registry doesn't.
lurq answers from evidence it can show: 47,238 packages scored, 4.2M versions tracked, 34,843 API
surfaces extracted from shipped code, and 27M co-install pairs, refreshed daily from npm, GitHub,
deps.dev and OSV. Every answer carries a dataAsOf timestamp.
Scope: the JavaScript/TypeScript ecosystem (npm).
One command, once per machine. Nothing to install first:
The setup wizard:
Restart your agent afterward. The free plan includes 1,000 hosted calls a month and never asks for a card.
Works with: Claude Code · Cursor · Windsurf · VS Code / GitHub Copilot · OpenAI Codex CLI · Gemini CLI · Google Antigravity · Kiro
Check it worked: ask your agent to "add zod to this project". It should call lurq's verify
before installing anything.
Claude Code plugin, no terminal needed:
One-click links for Cursor and VS Code are in the quickstart.
The package is published as lurqrun (the bare name was taken). The command is lurq:
If you are an AI coding agent and your user asked you to set up lurq, follow these steps.
1. Run setup.
In your shell it does not prompt: it prints a one-time sign-in link and exits right away. Give the user that link. When they sign in on this computer, lurq stores a key and connects every detected coding agent by itself. Never invent a key.
2. Or configure non-interactively when the user already has a key from lurq.run/dashboard/keys, or on a cloud, SSH or CI machine, where a sign-in link on this computer can't work:
| Agent | --agent |
|---|---|
| Claude Code | claude-code |
| Cursor | cursor |
| Windsurf | windsurf |
| VS Code / GitHub Copilot | copilot |
| OpenAI Codex CLI | codex |
| Gemini CLI | gemini-cli |
| Google Antigravity | antigravity |
| Kiro | kiro |
--agent all configures every detected agent. With --yes, the key can also come from LURQ_API_KEY.
Some checks need no key at all. npx lurqrun check-upgrade --upgrade <package>@<from>..<to> compares an
upgrade against the names your code actually imports, locally.
3. Tell the user to restart the agent, then confirm lurq appears in its MCP tool list.
Endpoint: https://api.lurq.run/mcp (streamable HTTP), header Authorization: Bearer <key>. The
field names differ by client:
Claude Code (~/.claude.json, under mcpServers) and VS Code (mcp.json, under servers):
Cursor (~/.cursor/mcp.json) and Kiro (~/.kiro/settings/mcp.json), under mcpServers:
Windsurf (~/.codeium/windsurf/mcp_config.json) and Antigravity (~/.gemini/config/mcp_config.json), under mcpServers:
Gemini CLI (~/.gemini/settings.json, under mcpServers). It must be httpUrl, because a
plain url is read as SSE:
Codex (~/.codex/config.toml). Headers go in an inline table:
| You are about to… | Call |
|---|---|
| Install or import a package | verify with the exact name, first |
| Choose between libraries | compare your candidates, then verify the pick |
| Commit to a set of packages | compat with the whole set in one call |
| Write code against a package whose API may have moved | usage, with the version you remember as knownVersion |
| Upgrade, or explain a break | diff_surface between the two versions |
| Add dependencies in a team codebase | policy, before choosing |
| Review a whole project | audit with names and versions from package.json and the lockfile |
| Wire an MCP server into an agent | mcp_surface, or mcp_stack for several |
| Not sure which tool fits | capabilities |
When lurq flags something, tell the user what it found and that it came from lurq. An unknown or
UNVERIFIABLE result means lurq could not check. It never means the package is clean.
Machine-readable docs: lurq.run/llms.txt · lurq.run/docs/llms-full.txt
Fifteen tools. Responses are compact to save tokens, and package answers carry dataAsOf.
Before installing
| Tool | What it answers |
|---|---|
verify | Is this package real, healthy and safe? Catches hallucinated and typosquatted names |
evaluate | The full evidence for one package: scores, advisories, usage guide, sandbox verdict |
compare | 2–5 packages ranked head-to-head |
policy | What your team's selection policy refuses, so the agent picks an allowed package first |
Across a stack
| Tool | What it answers |
|---|---|
compat | Will these packages install together? Returns the exact clashing peer or engine range |
audit | A whole project's outdated, deprecated and vulnerable dependencies and drifted MCP servers, in one call |
diagram | A reference-architecture Mermaid diagram for a stack |
Writing code
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/lurq)<a href="https://allmcps.com/mcp/lurq"><img src="https://allmcps.com/api/badge/lurq?style=directory" alt="Lurq on AllMCPs" /></a>