Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. Pkgtruth
Pkgtruth logo
Health: ActiveRecent health check succeeded.Last checked 9/7/2026, 8:30:51 PM

Pkgtruth

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository1 GitHub StarsTotal stargazers on GitHub for the source repository (1 stars).Visit Website

Catches hallucinated and slopsquatted npm packages before an agent installs them.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "pkgtruth": {
      "command": "npx",
      "args": [
        "-y",
        "pkgtruth"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

pkgtruth

npm CI node license

Ground truth about npm packages, for AI coding agents and CI.

pkgtruth catching a hallucinated package and a slopsquat

Your agent just wrote npm install unused-imports. That package is not the linter plugin it meant. It is a name an attacker registered because models kept inventing it β€” and npm has since replaced it with a security placeholder.

pkgtruth catches that before it reaches your lockfile.

Why this exists

Large language models invent package names. Measured across models, 19.7% of generated package names were hallucinated, and when researchers re-ran the prompts, 43% of those names came back every single time.

That reproducibility is the whole attack. An attacker does not need to compromise a maintainer, poison a build server, or find a vulnerability. They watch what models invent, register the name, and wait. The technique is called slopsquatting, and it is already happening in the wild.

The standing security advice is that agents with package-management capabilities should not install anything without a review gate. pkgtruth is that gate, in a form an agent can call on its own.

Found in the wild

Two names a model plausibly produces, both live on npm today:

NameWhat it isWeekly installsThe real one
types-node0.0.1-security β€” npm's placeholder after purging malware10@types/node (429M)
socket-ioDeprecated since 2022, "use the socket.io package instead"1,486socket.io (18M)

types-node is what you get when a model drops the scope from @types/node. npm removed it for malicious code in December 2024 and it is still installed ten times a week.

socket-io is not malicious β€” it is an abandoned package with a confusable name. That it takes 1,486 installs a week anyway is the point: a dot and a hyphen are enough.

Terminal
npx pkgtruth check types-node socket-io

Install

As an MCP server (for coding agents)

config.json
{
  "mcpServers": {
    "pkgtruth": {
      "command": "npx",
      "args": ["-y", "pkgtruth"]
    }
  }
}

Two tools become available:

ToolUse it when
check_packageAbout to add, import, or recommend one dependency
check_dependenciesAbout to write a package.json or run an install command

As a CLI (for humans and CI)

Terminal
npx pkgtruth check express unused-imports
npx pkgtruth scan .

scan reads every dependency in a package.json and exits non-zero when something is blocking, so it drops straight into CI:

yaml
- name: Block hallucinated and slopsquatted dependencies
  run: npx pkgtruth scan . --fail-on danger

What it checks

SignalMeaning
Not in registryThe name is fabricated. Nothing to install.
npm security placeholdernpm removed malicious code published under this name.
Impersonates a popular packageA near-identical name with a fraction of the adoption.
Install-time scriptspreinstall/install/postinstall run code on npm install.
DeprecatedUpstream says stop using it.
Very new / almost no adoptionDays old with single-digit installs.
No repositoryNo source to audit.
UnmaintainedNo release in years.

Verdicts are SAFE, CAUTION, DANGER, HALLUCINATED, or UNKNOWN. Every one arrives with the evidence behind it β€” an agent should never have to take "DANGER" on faith, and neither should you.

Design notes

Network failures never open the gate. If the registry is unreachable, the verdict is UNKNOWN, never SAFE. A degraded network must not silently turn a security check into a no-op.

Popular packages are not flagged. Checked against a real 18-dependency project, zero false positives. A gate that cries wolf gets switched off.

No build step. Two direct dependencies β€” the MCP SDK and zod, both only needed for the server. npx pkgtruth starts immediately.

Limitations

Read these before trusting it:

  • npm only. PyPI, crates.io, and Go modules are not covered yet.
  • Registry metadata only. It does not analyze package source code, so a legitimate-looking package with a malicious payload can still pass.
  • Not a replacement for npm audit or Snyk. Those find known CVEs in code you already trust. pkgtruth asks the earlier question: should this package be here at all?
  • New legitimate packages will get CAUTION. That is deliberate. Newness genuinely is a risk signal; use --fail-on danger so it does not block.

Options

Code
--json              Machine-readable output
--fail-on <level>   danger (default) | caution

--fail-on caution also blocks packages that could not be verified at all, since "we could not check" is not a pass.

Exit codes: 0 clean, 1 blocking packages found, 2 usage or runtime error.

Configuration

VariableDefaultPurpose
PKGTRUTH_TIMEOUT_MS8000Per-request timeout
PKGTRUTH_RETRIES3Retries for 429/5xx/network errors
PKGTRUTH_MAX_CONCURRENCYper-hostOverride request pacing
PKGTRUTH_REGISTRYnpmAlternate registry
PKGTRUTH_DOWNLOADS_APInpmAlternate downloads API
PKGTRUTH_CACHE_DIR~/.cache/pkgtruthWhere adoption figures are cached
PKGTRUTH_DISK_TTL_MS6 hoursHow long a cached figure stays usable
PKGTRUTH_NO_DISK_CACHEunsetSet to 1 to disable the cache

On speed and rate limits

Adoption figures come from npm's downloads API, which throttles bursts and cannot batch scoped names β€” a project with several @scope/pkg dependencies would spend its whole budget on every scan.

Three things keep that in check: the bulk endpoint resolves all unscoped names in one request, requests to that host are paced serially, and figures are cached on disk for six hours. Weekly download counts move slowly, so a six-hour-old number is no less true.

A warm scan of ~18 dependencies takes about 1.4 seconds. A cold one after heavy use may return UNKNOWN for some packages β€” that is the intended failure mode. A throttled lookup never becomes SAFE; re-run, and the cache will answer.

Cached figures are keyed by the API they came from, so pointing PKGTRUTH_DOWNLOADS_API at a private registry never reuses npm's numbers.

Contributing

Issues and pull requests are welcome at github.com/hxckya/pkgtruth.

Two things make a report especially useful: a legitimate package that gets flagged, and a malicious one that slips through. Both are regression tests waiting to be written.

Terminal
npm test                 # offline
npm run test:online      # includes live registry checks

License

MIT Β© hxckya

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • Trazum logoTrazum

    Trazum as an MCP server: let an agent price and budget its own prompts before it sends them.

    πŸ’» Developer Tools0 views
    Compare vs Trazum β†’
  • V
    Vdb

    Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.

    πŸ’» Developer Tools0 views
    Compare vs Vdb β†’
  • PraisonAI logoPraisonAI

    AI Agents Framework with Self Reflection and MCP support

    πŸ’» Developer Tools1 views
    Compare vs PraisonAI β†’
  • Labelhead Artist Momentum logoLabelhead Artist Momentum

    Trending hip-hop artist momentum scores across four cultural dimensions.

    πŸ’» Developer Tools0 views
    Compare vs Labelhead Artist Momentum β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
1
Stargazers on the source repository.
npm downloads
493
Package downloads in the last 30 days.
Last commit
5d ago
Most recent push to the default branch.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Pkgtruth

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "pkgtruth": { "command": "npx", "args": ["-y", "pkgtruth"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewPkgtruth AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/pkgtruth?style=directory)](https://allmcps.com/mcp/pkgtruth)
HTML Embed
<a href="https://allmcps.com/mcp/pkgtruth"><img src="https://allmcps.com/api/badge/pkgtruth?style=directory" alt="Pkgtruth on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 2, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars1
GitHub Star CountTotal stargazers on GitHub representing community popularity (1 stars).
Last commit5d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 2, 2026
npm downloads493/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
44Quality signal: Fair Β· 44/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to Pkgtruth β†’Install in Claude DesktopInstall in CursorInstall in VS Code