Use in your browser

Check an npm package

Point either tool at a public npm package and get the same verdict your agent gets: the exact published tarball is downloaded, hash-verified, and analyzed without installing or executing it.

Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage

npm Package Check

Connect agent

Guest access is available after setup. Full account linking verified by PowMCP: Claude only.

Package Check

Full preflight of one npm package: grade, tarball contents, install scripts, suspicious files, integrity, provenance presence, licensing, and release health.

Usually finishes within 30 seconds.

Public npm package; bare names resolve to the latest version

14 of 230

Add npm Package Check to your agent

Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.

Open the apps workspace A glowing app tile clicking into a slot on a dark agent device, with the PowMCP app box behind it

Connect directly

Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.

Use another agent

Copy one ready-to-send prompt for any agent that supports remote MCP connections.

Manual endpoint, JSON, and terminal commands

For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.

ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide

https://powmcp.com/npm-package-preflight/mcp
{
  "mcpServers": {
    "powmcp-npm-package-preflight": {
      "type": "http",
      "url": "https://powmcp.com/npm-package-preflight/mcp"
    }
  }
}

Terminal agents add this app with one command:

Claude Code
claude mcp add --transport http powmcp-npm-package-preflight https://powmcp.com/npm-package-preflight/mcp
Codex CLI
codex mcp add powmcp-npm-package-preflight --url https://powmcp.com/npm-package-preflight/mcp
Gemini CLI
gemini mcp add --transport http powmcp-npm-package-preflight https://powmcp.com/npm-package-preflight/mcp

Manage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.

Proof

What it does

Inspect the exact published npm tarball before you install or ship it: registry facts, shipped files, install scripts, integrity, and provenance, never an install

Check exact npm tarballs for dependency-health and supply-chain signals (shipped files, lifecycle install scripts, suspicious publish surface, integrity, provenance presence, licensing, and release health) without installing them, before you adopt a dependency or announce your own published release.

Category
Developer Tools

Request cost1 completed result

Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.

Tools in this app

01

Package Check

npm_package_check

Inspect one public npm package before installing or adopting it, or verify a maintainer's own published package or version. Resolves the exact version on the npm registry, downloads and hash-verifies the exact published tarball, inventories what the release actually ships, flags lifecycle install scripts, binaries, and suspicious files, and reads license, dependency, release-age, deprecation, signature, and provenance-attestation presence, all without ever installing or executing the package. Returns deterministic facts, findings, an evidence-based grade, and a prioritized review list. Covers dependency health and supply-chain signals only: it does not validate exports or TypeScript type resolution, and it does not analyze bundle or install weight. Usually finishes in 5-30 seconds; very large packages can take up to 100 seconds.

02

Package Compare

npm_package_compare

Compare two to five public npm packages or exact versions side by side when choosing which dependency to adopt. Runs the same deterministic pre-install checks as npm_package_check on every spec (registry facts, exact tarball contents, lifecycle scripts, integrity, provenance presence, and release health), then ranks the options by adoption friction with explicit tradeoffs. It never declares any package safe, never validates exports or TypeScript type resolution, and never compares bundle or install weight. Use npm_package_check instead for a single package. Usually finishes in 10-60 seconds; up to 100 seconds for large packages.

npm Package Check questions

Scope and boundaries for npm Package Check.

01What can I check with npm Package Check?

Inspect left-pad@1.3.0 as an exact public registry release, or compare ms@2.1.2 with ms@2.1.3 to review how the shipped tarballs, lifecycle scripts, integrity, provenance presence, licensing, dependencies, and release health differ.

02How should I read the result?

Read the exact resolved version and prioritized review list before the grade. The grade and score measure observed packaging and adoption friction, not package safety; resolve critical and high findings such as an integrity mismatch, rejected archive, deprecation, lifecycle scripts, or suspicious files before adoption. Treat every unmeasured or truncation entry as missing evidence, and read comparison rankings as the same limited adoption-friction ordering.

03What are its limits?

Only public npm registry packages are inspected, and package code is neither installed nor executed. The deterministic packaging signals are not a malware, vulnerability, or safety guarantee; exports, TypeScript resolution, bundle size, install weight, private registries, and unpublished local artifacts are outside this check.