package-risk MCP connector

package-risk MCP connector

Provides MCP tools to check a package's maintenance status, licence, and security advisories before you depend on it, with per-call payment in USDC on Base mainnet via x402.

Category
Visit Server

README

package-risk MCP connector

MCP tools for checking a package's maintenance status, licence, and security advisories before you depend on it - package_risk, package_licence, package_advisories. Paid per call in USDC on Base mainnet via x402.

No subscription, no API key. You pay from your own wallet, per call, only for what you use.

What this is (and isn't)

This is a thin client. The actual service is a stateless HTTP API at x402-package-risk.x402-package-risk.workers.dev. This connector never sees, holds, or forwards anyone else's funds - it only ever spends the wallet key you configure below, and only when you call one of its tools.

Setup

You need an EVM wallet with a small amount of USDC on Base mainnet (calls cost $0.005-$0.01 each). Never use a wallet holding significant funds for an automated agent key - keep this one funded lightly.

Add to your MCP client config (Claude Desktop, Claude Code, Cursor, etc.):

{
  "mcpServers": {
    "package-risk": {
      "command": "npx",
      "args": ["-y", "@makosdav/package-risk-mcp"],
      "env": {
        "EVM_PRIVATE_KEY": "0xyour-private-key-here"
      }
    }
  }
}

Tools

Tool Price What it returns
package_risk $0.01 Full verdict: maintenance, licence, advisories, deprecation
package_licence $0.005 Licence expression and closed-source safety
package_advisories $0.005 Open OSV advisories for the resolved version

All three take system (npm/pypi/go/maven/cargo/nuget), name, and an optional version.

How payment works

  1. Your agent calls a tool.
  2. This connector requests the resource; the server replies 402 Payment Required.
  3. @x402/fetch builds and signs a payment authorisation with your key.
  4. The request retries with payment attached; the server verifies via Coinbase CDP, returns the result, and settles on-chain.

No approval prompt happens here beyond what your MCP client itself asks for - if you want per-call confirmation, configure that in your agent framework, not here.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured