pkgtruth MCP
v0.2.2io.github.hxckya/pkgtruth
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
transport:stdio
runtime:npm
Target client
run in your project directory
claude mcp add pkgtruth -e PKGTRUTH_REGISTRY=<PKGTRUTH_REGISTRY> -e PKGTRUTH_DOWNLOADS_API=<PKGTRUTH_DOWNLOADS_API> -e PKGTRUTH_CACHE_DIR=<PKGTRUTH_CACHE_DIR> -e PKGTRUTH_TIMEOUT_MS=<PKGTRUTH_TIMEOUT_MS> -- npx -y pkgtruth
Adds it for this project only. Append --scope user to make it available everywhere. Claude Code docs
This listing does not declare its tools. Connect the server and your client will discover them on the handshake.