Skip to content

Claude Desktop NPMScan batch_query_vulnerabilities

How to: Claude Desktop NPMScan batch_query_vulnerabilities

client:Claude Desktop transport:streamable-http tool:batch_query_vulnerabilities

Add NPMScan to Claude Desktop

  1. 01

    Open ~/Library/Application Support/Claude/claude_desktop_config.json and merge this in. Keep any servers already there.

{
  "mcpServers": {
    "npmscan": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://npmscan.com/api/mcp"
      ]
    }
  }
}
  1. 02

    Save the file and restart Claude Desktop.

  2. 03

    Ask for something batch_query_vulnerabilities does. Claude Desktop lists the server's tools on connect and calls batch_query_vulnerabilities itself — you do not invoke it by name.

  3. 04

    If nothing happens, check the server is running and that NPMScan's identifier in your config matches the one above exactly.

Claude Desktop has no remote transport in its config file, so this bridges through mcp-remote. Restart the app after saving. Claude Desktop docs

Same tool, other clients

This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what the server actually exposes, not what its listing claims.

Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.