Npmjs Mcp
npm registry MCP server — package intelligence, security audits, dependency analysis
- Transport
- Not stated
- Package
- —
- Registry id
- io.github.YawLabs/npmjs-mcp
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
Read operations require no credentials. Write operations require the NPM_TOKEN environment variable. The server ships as a single bundled file with zero runtime dependencies.
The software is MIT licensed and published on npm. It includes known-vulnerability checks and a deep audit with CVSS scores, CWEs, and fix recommendations. It provides dependency tree analysis at a user-specified depth.
Summary drafted from the project's own website. Every sentence is backed by text on that page and was reviewed before publishing.