package-intel-mcp
Provides software supply-chain intelligence for npm packages, including metadata, version history, download counts, dependencies, health scores, and search.
Provides software supply-chain intelligence for PyPI packages, including metadata, version history, download counts, dependencies, health scores, and search.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@package-intel-mcpCheck the health and dependencies of the npm package jest"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Package Intel MCP — by Datakoot
Software supply-chain intelligence for AI agents — as MCP tools your agent can call mid-task, so it can vet a dependency before it installs it. Covers npm, PyPI and crates.io. No API keys.
Tools
Tool | What it does | Source |
| Metadata for a package: description, latest version, license, homepage & repo links | npm / PyPI / crates.io |
| Full version history with release dates | npm / PyPI / crates.io |
| Download counts and popularity signal | npm / PyPI / crates.io |
| Direct dependencies for a given version | deps.dev |
| Health signals: OpenSSF Scorecard, stars, dependents | deps.dev |
| Search for packages by keyword | npm / PyPI / crates.io |
Every tool accepts an ecosystem of npm, pypi, or crates. No API keys required.
Related MCP server: oss-intel-mcp
Quick start
claude mcp add --transport http package-intel https://package.datakoot.com/mcpOr point any MCP client at https://package.datakoot.com/mcp.
Data & attribution
Data comes from the public registry APIs for npm, PyPI and crates.io, plus deps.dev (Google Open Source Insights, CC-BY 4.0) for dependency graphs and OpenSSF Scorecard health signals. Package data is served from official public APIs and is informational.
Part of Datakoot — keyless intelligence APIs for AI agents.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Related MCP Connectors
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Real-time Python package and vulnerability data for AI coding agents.
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
31
Related MCP Servers
- AlicenseAqualityAmaintenanceDependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.95172Apache 2.0
- AlicenseNot gradedqualityFmaintenanceOpen source intelligence for AI agents — GitHub project-health scoring, package dependency-risk analysis, trending repositories, license checks, and side-by-side package comparison.MIT
- AlicenseAqualityDmaintenanceDependency security & health auditing for AI agents with no account or API key required.22MIT
- FlicenseNot gradedqualityCmaintenancePackage intelligence for AI coding agents that checks npm and PyPI package health, deprecation, vulnerabilities, bundle size, and compares alternatives.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/datakoot/package-intel-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server