설정

플러그인

NPMScan

npm package & vuln lookups

플러그인 설치

Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, GitHub's own API, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing, or compare 2-5 candidates side-by-side with a deterministic pick; check an exact version pinned in a lockfile, or simulate upgrading one before running npm install to see if it's a safe patch or a likely-breaking major bump; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; audit an entire GitHub repository's dependencies (including monorepo workspaces) in one call, or generate a spec-valid CycloneDX/SPDX SBOM with vulnerability and license data embedded; rank the findings from a raw `npm audit --json` report by CISA KEV/FIRST EPSS exploitation data to know what to fix first, then pull the concrete, ordered remediation playbook for a flagged finding; check an npm maintainer account's publish history for a compromised-account-style cluster, or pull their basic profile; browse the latest npm advisories from either GitHub's curated, mostly CVE-backed reviewed set or its known-malicious-package malware feed, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more, reviewed only), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.

앱

NPMScan

스킬

정보

개발자
SHYNGYS SHYNBOLATOV
카테고리
Developer Tools
웹사이트
버전
3.0.0
개인정보 보호정책
이용약관

NPMScan에 연결하면 ChatGPT가 요청에 필요한 맥락을 제공하기 위해 관련 채팅과 메모리를 이 앱과 공유할 수 있습니다. 이 데이터는 NPMScan의 이용약관 및 개인정보 보호정책에 따라 사용됩니다. 메모리 기능을 사용 설정한 경우 앱의 데이터가 유용한 정보나 제안을 미리 제공하는 데 사용될 수 있습니다. ChatGPT는 연결된 앱의 데이터를 포함해 학습 데이터 기본 설정을 항상 준수합니다. 앱 사용 시 높은 위험이 있을 수 있습니다. 설정에서 언제든지 기본 설정을 관리하거나 앱 연결을 해제할 수 있습니다. 자세히 알아보기