query_vulnerabilities — NPMScan MCP Tool Read-only
query_vulnerabilities
(query vulnerabilities) is one of 23 tools on the
NPMScan
MCP server. Connect the server and your client discovers it on the handshake.
by client
How to call query_vulnerabilities from your client
- Claude Code NPMScan query_vulnerabilities run in your project directory
- Claude Desktop NPMScan query_vulnerabilities ~/Library/Application Support/Claude/claude_desktop_config.json
- Cursor NPMScan query_vulnerabilities ~/.cursor/mcp.json
- VS Code NPMScan query_vulnerabilities .vscode/mcp.json
- Zed NPMScan query_vulnerabilities ~/.config/zed/settings.json
- Windsurf NPMScan query_vulnerabilities ~/.codeium/windsurf/mcp_config.json
- Cline NPMScan query_vulnerabilities ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
- Gemini CLI NPMScan query_vulnerabilities ~/.gemini/settings.json
- Grok NPMScan query_vulnerabilities .mcp.json (in your project root)
- ChatGPT NPMScan query_vulnerabilities Settings → Connectors → Advanced → Developer mode
- Claude.ai NPMScan query_vulnerabilities Settings → Connectors → Add custom connector
- LangChain NPMScan query_vulnerabilities pip install langchain-mcp-adapters
Fastest route
claude mcp add --transport http npmscan https://npmscan.com/api/mcp
Other tools on this server
- search_packages
- get_package
- get_package_version
- get_maintainer_profile
- batch_query_vulnerabilities
- get_latest_advisories
- get_cve
- analyze_install_script
- analyze_transitive_dependencies
- check_package_provenance
- check_maintainer_changes
- check_maintainer_blast_radius
- check_license_compliance
- diff_dependencies
- prioritize_remediation
- simulate_dependency_upgrade
- suggest_alternative
- compare_packages
- audit_github_repository
- get_remediation_playbook
- generate_sbom
- enrich_npm_audit
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.