MCP Tools Directory
← Browse integrations

Developer tools

io.github.makosdDavid/package-risk

Free account · sign-in required

Contact io.github.makosdDavid/package-risk

Loading secure sign-in…

Tools for autonomous AI agents

About this integration

Package risk checks: maintenance, licence, advisories. Paid per call in USDC, no signup.

Transport
stdio
Authentication
unknown
Initial setup
credentials
Runtime
unattended
Evidence
documented
Version
1.0.5
Package
@makosdav/package-risk-mcp
Last compatibility test
Not independently tested

Connect your agent

@makosdav/package-risk-mcp

Publisher README and package manifest reviewed. Calls can spend USDC automatically; operators should use a purpose-limited wallet and client-side approval controls. No package or payment endpoint was executed.

Capabilities: Assess package maintenance risk, Check package licenses, Query package security advisories

Connected profiles

Additional details

Registry identifier

io.github.makosdDavid/package-risk

Source ↗ · Checked 2026-09-17
Published version

1.0.5

Source ↗ · Checked 2026-09-17
Metadata license

CC0-1.0; package licenses are separate

Source ↗ · Checked 2026-09-17
Package ecosystem

npm

Source ↗ · Checked 2026-09-17
Required configuration names

EVM_PRIVATE_KEY

Source ↗ · Checked 2026-09-17
Source artifact

@makosdav/package-risk-mcp

Source ↗ · Checked 2026-09-19
Source manifest version

1.0.3

Source ↗ · Checked 2026-09-19
Unattended configuration

The connector documents automatic payment and retry during tool calls, without a connector-level approval prompt. It was not installed, executed, or payment-tested.

Source ↗ · Checked 2026-09-19
Authentication and prerequisites

The service uses no API key; it requires a lightly funded EVM wallet private key for per-call x402 payments. This wallet-key mechanism falls outside the native authentication taxonomy, so auth is classified as unknown and setup as credentials.

Source ↗ · Checked 2026-09-19
Connection configuration

The reviewed MCP client configuration launches the npm package with npx over the existing stdio connection.

Source ↗ · Checked 2026-09-19
Review scope

Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.

Source ↗ · Checked 2026-09-19