Developer · Local MCP server
Safe Upgrade
Evidence-backed npm upgrade preflight and dependency audits for coding agents, paid via x402.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.white-hat-lab/safe-upgrade- Version
- 0.2.0
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-08-10
- Updated
- 2026-08-10
- Publisher
- white-hat-lab (GitHub) · 2 servers with pages here
- Repository
- github.com/white-hat-lab/x402-safe-upgrade-api
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | safe-upgrade-mcp | 0.2.0 | stdio |
How to connect Safe Upgrade
Safe Upgrade runs locally from a Node.js package published to the npm registry: safe-upgrade-mcp version 0.2.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y safe-upgrade-mcp@0.2.0. It reads the environment variable PAYER_PRIVATE_KEY (secret); set it in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"safe-upgrade": {
"command": "npx",
"args": [
"-y",
"safe-upgrade-mcp@0.2.0"
],
"env": {
"PAYER_PRIVATE_KEY": "<secret>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from white-hat-lab (GitHub)
| Server | Runs |
|---|---|
| Agent ToolkitPay-per-call developer utilities and npm supply-chain security tools for coding agents, over x402. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| Safari MCPNative Safari browser automation for AI agents — 98 tools, zero Chrome overhead. | Local · stdio |
| Safe FetchMCP server for fetching URLs, safe against SSRF, DNS rebinding, and redirect-to-internal attacks. | Local · stdio |
| Safe Fix MCPFinds real dead code and proposes a safe, test-gated branch+PR to remove it. | Local · stdio |
| Safe Ssh MCPA secured scoped SSH MCP server for executing safe read-only diagnostic DevOps / SysOps commands. | Local · stdio |
| Safedb MCPA secure MCP server that lets AI agents query databases safely. | Local · stdio |
| SafeinstallLocal-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks. | Local · stdio |
| SafeNode MCP GatewayPolicy proxy for MCP tool calls. A denied call never reaches the downstream server. | Local · stdio |
| safeprompt.devDetect prompt injection, jailbreaks, and code injection in untrusted text before it reaches an LLM. | Local · stdio |