check_package
Checks an npm dependency version for known vulnerabilities, malware advisories, typosquatting, and risky install scripts before installation.
When an agent should call it
Reads public npm metadata and OSV vulnerability advisories. Package scripts and source code are analyzed as text only and are never executed; direct dependency trees and maintainer history are not recursively assessed in this MVP.
Input: npm package name and optional exact semantic version
Price: $0.005 USDC per call, paid in USDC via x402 on Base.
MCP connection: one-time setup, then call check_package on each needed workflow.
Direct HTTP resource: https://mcp.dropenginehq.com/api/check-package
Example input
{
"ecosystem": "npm",
"package": "axios"
}Representative output
This is an example of the response shape, not a live result. Current registry data and provider configuration can change the values.
{
"success": true,
"ecosystem": "npm",
"package": "axios",
"requested_version": null,
"resolved_version": "1.7.0",
"risk_score": 10,
"risk_level": "low",
"risk_confidence": "medium",
"recommendation": "allow",
"known_malicious": false,
"malicious_confidence": null,
"known_vulnerabilities": [],
"typosquat_risk": "low",
"similar_to": null,
"similarity_score": null,
"install_script_risk": "low",
"suspicious_scripts": [],
"dependency_risk": "low",
"dependency_count": 0,
"dependencies_analyzed": 0,
"dependency_findings": [],
"maintainer_risk": "unknown",
"maintainer_count": null,
"reputation": "neutral",
"package_age_days": null,
"new_package": null,
"deprecated": false,
"warnings": [],
"sources": [
"npm_registry",
"osv"
],
"degraded": false,
"cached": false,
"checked_at": "2026-09-28T00:00:00.000Z",
"data_freshness_seconds": 0
}Each call requests payment for this tool only. The agent receives a structured result and decides what to do next. Check the limits above before acting on risk, market, freshness, or availability results.
MCP endpoint: https://mcp.dropenginehq.com/api/paid-mcp