Developer · Local MCP server

Safe Upgrade

Evidence-backed npm upgrade preflight and dependency audits for coding agents, paid via x402.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.white-hat-lab/safe-upgrade
Version
0.2.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-08-10
Updated
2026-08-10
Publisher
white-hat-lab (GitHub) · 2 servers with pages here
Repository
github.com/white-hat-lab/x402-safe-upgrade-api
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npmsafe-upgrade-mcp0.2.0stdioPAYER_PRIVATE_KEY (secret)

How to connect Safe Upgrade

Safe Upgrade runs locally from a Node.js package published to the npm registry: safe-upgrade-mcp version 0.2.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y safe-upgrade-mcp@0.2.0. It reads the environment variable PAYER_PRIVATE_KEY (secret); set it in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "safe-upgrade": {
      "command": "npx",
      "args": [
        "-y",
        "safe-upgrade-mcp@0.2.0"
      ],
      "env": {
        "PAYER_PRIVATE_KEY": "<secret>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from white-hat-lab (GitHub)

All 2 →
ServerRunsEndpoint or package
Agent ToolkitPay-per-call developer utilities and npm supply-chain security tools for coding agents, over x402.Local · stdionpm: agent-toolkit-mcp

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Safari MCPNative Safari browser automation for AI agents — 98 tools, zero Chrome overhead.Local · stdionpm: safari-mcp
Safe FetchMCP server for fetching URLs, safe against SSRF, DNS rebinding, and redirect-to-internal attacks.Local · stdionpm: safe-fetch-mcp-server
Safe Fix MCPFinds real dead code and proposes a safe, test-gated branch+PR to remove it.Local · stdioPyPI: safe-fix-mcp
Safe Ssh MCPA secured scoped SSH MCP server for executing safe read-only diagnostic DevOps / SysOps commands.Local · stdioPyPI: safe-ssh-mcp
Safedb MCPA secure MCP server that lets AI agents query databases safely.Local · stdionpm: @safedb/safedb-mcp
SafeinstallLocal-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks.Local · stdionpm: safeinstall-cli
SafeNode MCP GatewayPolicy proxy for MCP tool calls. A denied call never reaches the downstream server.Local · stdionpm: safenode-mcp-gateway
safeprompt.devDetect prompt injection, jailbreaks, and code injection in untrusted text before it reaches an LLM.Local · stdionpm: @safeprompt.dev/mcp