enrich_npm_audit — NPMScan MCP Tool
enrich_npm_audit
(enrich npm audit) is one of 23 tools on the
NPMScan
MCP server. Connect the server and your client discovers it on the handshake.
by client
How to call enrich_npm_audit from your client
- Claude Code NPMScan enrich_npm_audit run in your project directory
- Claude Desktop NPMScan enrich_npm_audit ~/Library/Application Support/Claude/claude_desktop_config.json
- Cursor NPMScan enrich_npm_audit ~/.cursor/mcp.json
- VS Code NPMScan enrich_npm_audit .vscode/mcp.json
- Zed NPMScan enrich_npm_audit ~/.config/zed/settings.json
- Windsurf NPMScan enrich_npm_audit ~/.codeium/windsurf/mcp_config.json
- Cline NPMScan enrich_npm_audit ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
- Gemini CLI NPMScan enrich_npm_audit ~/.gemini/settings.json
- Grok NPMScan enrich_npm_audit .mcp.json (in your project root)
- ChatGPT NPMScan enrich_npm_audit Settings → Connectors → Advanced → Developer mode
- Claude.ai NPMScan enrich_npm_audit Settings → Connectors → Add custom connector
- LangChain NPMScan enrich_npm_audit pip install langchain-mcp-adapters
Fastest route
claude mcp add --transport http npmscan https://npmscan.com/api/mcp
Other tools on this server
- search_packages
- get_package
- get_package_version
- get_maintainer_profile
- query_vulnerabilities
- batch_query_vulnerabilities
- get_latest_advisories
- get_cve
- analyze_install_script
- analyze_transitive_dependencies
- check_package_provenance
- check_maintainer_changes
- check_maintainer_blast_radius
- check_license_compliance
- diff_dependencies
- prioritize_remediation
- simulate_dependency_upgrade
- suggest_alternative
- compare_packages
- audit_github_repository
- get_remediation_playbook
- generate_sbom
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.