Presend package checks
Before Claude installs or suggests an npm or PyPI package, Presend package checks looks the name up and reports what deserves a second look: names that do not exist on the registry (often invented by a model), packages first published less than 30 days ago, near-misses of popular package names (typosquats), known vulnerabilities of the version (OSV.dev), the health of the GitHub repository, and, on npm, a new publisher taking over a dormant package. All five tools are read-only. No account and no API key. The tools receive only package names, versions and repository names, which Presend passes to npm, PyPI, OSV.dev and GitHub. Limits: Presend is not a malware scanner; the typosquat check compares names against a list of popular packages; a clean result does not prove a package is safe; per-minute rate limits apply. False-positive rates on the 15,000 most downloaded PyPI packages and about 17,000 high-impact npm packages are measured and published at presend.pages.dev/measurements.
Details
https://presend.pages.dev/mcp-deps · streamable-http
