NPMScan MCP Tools
NPMScan exposes 23 tools. Each one has its own page with the configuration for every client that can run this server.
-
search_packagesRead-onlysearch packages
-
get_packageRead-onlyget package
-
get_package_versionRead-onlyget package version
-
get_maintainer_profileRead-onlyget maintainer profile
-
query_vulnerabilitiesRead-onlyquery vulnerabilities
-
batch_query_vulnerabilitiesbatch query vulnerabilities
-
get_latest_advisoriesRead-onlyget latest advisories
-
get_cveRead-onlyget cve
-
analyze_install_scriptanalyze install script
-
analyze_transitive_dependenciesanalyze transitive dependencies
-
check_package_provenanceRead-onlycheck package provenance
-
check_maintainer_changesRead-onlycheck maintainer changes
-
check_maintainer_blast_radiusRead-onlycheck maintainer blast radius
-
check_license_complianceRead-onlycheck license compliance
-
diff_dependenciesdiff dependencies
-
prioritize_remediationprioritize remediation
-
simulate_dependency_upgradesimulate dependency upgrade
-
suggest_alternativesuggest alternative
-
compare_packagescompare packages
-
audit_github_repositoryaudit github repository
-
get_remediation_playbookRead-onlyget remediation playbook
-
generate_sbomgenerate sbom
-
enrich_npm_auditenrich npm audit
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.