Agent♥︎Age
Catalog

io.github.mlawsonking/package-guard-mcp

Official

by mlawsonking · JavaScript

Supply-chain guard for AI coding agents: verify packages, check vulns/malware, detect typosquats.

package-guard-mcp (MCP Server)

The io.github.mlawsonking/package-guard-mcp MCP server acts as a supply-chain guard for AI coding agents. Before an agent installs a package, it verifies the package name, checks vulnerabilities and malware signals, and detects typosquats. It is deterministic, does not use an LLM, and is described as free.

🛠️ Key Features

  • Vets a package before installation
  • Verifies the package name is registered
  • Checks OSV for advisories (vulns/malware)
  • Detects typosquats (including “slopsquatting”)
  • Flags “not in this registry” during verify_package

🚀 Use Cases

  • Preventing agents from installing unknown or deceptive packages
  • Reducing risk from package-name suggestions that don’t exist
  • Guarding agent-run installs against typosquats

⚡ Developer Benefits

  • Deterministic checks (no LLM)
  • Registry lookup-based hallucination detection
  • Tools for supply-chain security workflows

⚠️ Limitations

  • “Likely hallucination” means “not in this registry” and does not add further detail

Topics

agent-securityagent-security-toolsai-agentsapimcpmcp-serverprompt-injectionsupply-chain-security