npm Package Check
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Use in your browser
Point either tool at a public npm package and get the same verdict your agent gets: the exact published tarball is downloaded, hash-verified, and analyzed without installing or executing it.
Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage
Guest access is available after setup. Full account linking verified by PowMCP: Claude only.
Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.
Open the apps workspace
Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.
Copy one ready-to-send prompt for any agent that supports remote MCP connections.
For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.
ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide
https://powmcp.com/npm-package-preflight/mcp {
"mcpServers": {
"powmcp-npm-package-preflight": {
"type": "http",
"url": "https://powmcp.com/npm-package-preflight/mcp"
}
}
}Terminal agents add this app with one command:
claude mcp add --transport http powmcp-npm-package-preflight https://powmcp.com/npm-package-preflight/mcpcodex mcp add powmcp-npm-package-preflight --url https://powmcp.com/npm-package-preflight/mcpgemini mcp add --transport http powmcp-npm-package-preflight https://powmcp.com/npm-package-preflight/mcpManage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.
Proof
Inspect the exact published npm tarball before you install or ship it: registry facts, shipped files, install scripts, integrity, and provenance, never an install
Check exact npm tarballs for dependency-health and supply-chain signals (shipped files, lifecycle install scripts, suspicious publish surface, integrity, provenance presence, licensing, and release health) without installing them, before you adopt a dependency or announce your own published release.
Request cost1 completed result
Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.
npm_package_check
Inspect one public npm package before installing or adopting it, or verify a maintainer's own published package or version. Resolves the exact version on the npm registry, downloads and hash-verifies the exact published tarball, inventories what the release actually ships, flags lifecycle install scripts, binaries, and suspicious files, and reads license, dependency, release-age, deprecation, signature, and provenance-attestation presence, all without ever installing or executing the package. Returns deterministic facts, findings, an evidence-based grade, and a prioritized review list. Covers dependency health and supply-chain signals only: it does not validate exports or TypeScript type resolution, and it does not analyze bundle or install weight. Usually finishes in 5-30 seconds; very large packages can take up to 100 seconds.
npm_package_compare
Compare two to five public npm packages or exact versions side by side when choosing which dependency to adopt. Runs the same deterministic pre-install checks as npm_package_check on every spec (registry facts, exact tarball contents, lifecycle scripts, integrity, provenance presence, and release health), then ranks the options by adoption friction with explicit tradeoffs. It never declares any package safe, never validates exports or TypeScript type resolution, and never compares bundle or install weight. Use npm_package_check instead for a single package. Usually finishes in 10-60 seconds; up to 100 seconds for large packages.
Other apps for the jobs next to npm Package Check.
Scope and boundaries for npm Package Check.
Inspect left-pad@1.3.0 as an exact public registry release, or compare ms@2.1.2 with ms@2.1.3 to review how the shipped tarballs, lifecycle scripts, integrity, provenance presence, licensing, dependencies, and release health differ.
Read the exact resolved version and prioritized review list before the grade. The grade and score measure observed packaging and adoption friction, not package safety; resolve critical and high findings such as an integrity mismatch, rejected archive, deprecation, lifecycle scripts, or suspicious files before adoption. Treat every unmeasured or truncation entry as missing evidence, and read comparison rankings as the same limited adoption-friction ordering.
Only public npm registry packages are inspected, and package code is neither installed nor executed. The deterministic packaging signals are not a malware, vulnerability, or safety guarantee; exports, TypeScript resolution, bundle size, install weight, private registries, and unpublished local artifacts are outside this check.