Developer · Local MCP server
pkgproof
Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
net.pkgproof/pkgproof- Version
- 0.1.7
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-14
- Updated
- 2026-09-14
- Publisher
- net.pkgproof
- Website
- pkgproof.net
- Repository
- github.com/jahija-okan/pkgproof-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @pkgproof/mcp | 0.1.7 | stdio |
How to connect pkgproof
pkgproof runs locally from a Node.js package published to the npm registry: @pkgproof/mcp version 0.1.7. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @pkgproof/mcp@0.1.7. It reads these environment variables: PKGPROOF_ALGORAND_PRIVATE_KEY (secret) and PKGPROOF_BASE_PRIVATE_KEY (secret); set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"pkgproof": {
"command": "npx",
"args": [
"-y",
"@pkgproof/mcp@0.1.7"
],
"env": {
"PKGPROOF_ALGORAND_PRIVATE_KEY": "<secret>",
"PKGPROOF_BASE_PRIVATE_KEY": "<secret>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More developer servers
| Server | Runs |
|---|---|
| Pixabay MCP ServerUnofficial MCP server for the Pixabay API: search and fetch royalty-free images and videos. | Local · stdio |
| Pixelletter MCPSend physical letters and faxes through the PixelLetter interface, test mode included. | Local · stdio |
| PixlintLint, curate & prepare computer-vision datasets from your AI assistant — MCP server, 67 tools. | Local · stdio |
| Pizza DeveloperWork management for AI agents: plan Ideas, Batches and Works, keep context, ship Deliveries. | Remote · HTTP |
| PkgSeek Linux IntelligenceLinux package, file, command, vulnerability, lifecycle, migration, and repository intelligence. | Remote · HTTP |
| PkgtruthCatches hallucinated and slopsquatted npm and PyPI packages before an agent installs them. | Local · stdio |
| pkgxrayPre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence. | Local · stdio |
| PlainQuery | MCP DB AgentQuery PostgreSQL databases in plain English — LLM-generated, safety-validated SQL. | Remote · HTTP |