MCPサーバー

Presend dependency checks

io.github.presendapp/presend-deps
開発者向けツール セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Checks software packages for known vulnerabilities, typosquatting, maintainer takeover signals, repository health, and supply-chain risk.

maintainer_change_check
Package maintainer change check
Publisher-change analysis is npm only. Also reports whether the package exists (found) and its age (first_published, package_age_days, new_package if first published less than 30 days ago), for npm and for PyPI; on PyPI only existence and age are available. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name, e.g. lodash'}, 'ecosystem': {'type': 'string', 'description': 'npm (full analysis) or pypi (existence and age only).'}}}
repo_health_check
Repository health check
Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['repo'], 'properties': {'repo': {'type': 'string', 'description': 'GitHub repository in owner/name format, e.g. lodash/lodash.'}}}
supply_chain_check
Package supply-chain check
Call this before installing or adding a package (npm install, pip install, a new entry in a manifest), especially one whose name you recalled or that a model suggested. One-call risk check: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. A package that does not exist on npm or PyPI gets overall_risk 'package_not_found': the name may be invented, do not install it. A package first published less than 30 days ago gets the 'new_package' flag and overall_risk 'review_recommended': new packages are where invented and look-alike names get registered, so confirm the name against the project's own documentation before installing (on PyPI the age is that of the oldest release still published; being new does not make a package malicious). Use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check.'}, 'version': {'type': 'string', 'description': 'Exact version to check for known vulnerabilities. Optional: defaults to the latest published version (npm and PyPI).'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm. maintainer-change-check only runs for npm.'}}}
typosquat_check
Package typosquat check
Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check for likely typosquatting of a well-known package in the given ecosystem.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm or PyPI.'}}}
vulnerability_check
Package vulnerability check
Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. For npm and PyPI, a name that does not exist returns found: false and vulnerable: null, never a clean result. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check against OSV.dev for known CVEs.'}, 'version': {'type': 'string', 'description': 'Omit to check all versions of the package.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet.'}}}
追加
vulnerability_check
2026年10月5日2:40
追加
typosquat_check
2026年10月5日2:40
追加
supply_chain_check
2026年10月5日2:40
追加
repo_health_check
2026年10月5日2:40
追加
maintainer_change_check
2026年10月5日2:40

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…