npm package & vuln lookups
Look up npm package metadata, known vulnerabilities, and CVE details directly from a conversation. NPMScan's MCP server gives AI agents seven read-only tools backed by the npm registry, OSV.dev, GitHub Security Advisories, and the NIST National Vulnerability Database: search packages by name or keyword with download counts, dependent-package counts, and typosquat detection on every result; inspect a package's install scripts, maintainers, license, GitHub stars, and download trend before installing; check an exact version pinned in a lockfile; query vulnerabilities for one package or up to 100 at once, each finding enriched with severity, a summary, CVE aliases, and the fixed version rather than a bare advisory ID; browse the latest reviewed npm advisories, filterable by severity, vulnerability category (XSS, SQL/NoSQL Injection, SSRF, Access Control, Code Injection, and 15 more), affected package, or an exact GHSA/CVE ID; and look up authoritative CVSS/CWE data for any CVE across any ecosystem, enriched with CISA's Known Exploited Vulnerabilities status and FIRST.org's EPSS exploitation-probability score. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.
NPMScan-உடன் இணைக்கப்படும்போது, உங்கள் கோரிக்கைகளுக்கான சூழலை வழங்க உதவ, பொருத்தமான அரட்டைகள் மற்றும் நினைவுகளை இந்தச் செயலியுடன் ChatGPT பகிரலாம். NPMScan-இன் இந்தத் தரவுப் பயன்பாடு அவர்களின் விதிமுறைகள் மற்றும் தனியுரிமைக் கொள்கைக்கு உட்பட்டது. நீங்கள் நினைவைச் செயல்படுத்தியிருந்தால், பயனுள்ள தகவல் அல்லது பரிந்துரைகளை முன்கூட்டியே வழங்க, செயலியின் தரவு பயன்படுத்தப்படலாம். இணைக்கப்பட்ட செயலிகளின் தரவு உட்பட உங்கள் பயிற்சித் தரவு விருப்பத்தேர்வுகளை ChatGPT எப்போதும் மதிக்கும். செயலிகளின் பயன்பாடு அதிக ஆபத்தைக் கொண்டிருக்கலாம். உங்கள் அமைப்புகளில் எந்த நேரத்திலும் நீங்கள் உங்கள் விருப்பத்தேர்வுகளை நிர்வகிக்கலாம் அல்லது செயலிகளிலிருந்து துண்டிக்கலாம். மேலும் அறிக