io.github.makosdDavid/package-risk
Package risk checks: maintenance, licence, advisories. Paid per call in USDC, no signup.
Open source Open in the app JSON README (API)
About
Package risk checks: maintenance, licence, advisories. Paid per call in USDC, no signup.
Details
- Kind
- MCP servers
- Topic
- Finance & crypto
- Publisher
- makosddavid
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 1.0.5
- Last push
- 2026-08-14T08:17:11Z
- Repository state
- ativo
- Language
- JavaScript
- License
- MIT
- Added
- 2026-08-29 04:00:27
- Updated
- 2026-08-29 04:00:27
- Origin id
io.github.makosdDavid/package-risk
README
# package-risk MCP connector
MCP tools for checking a package's maintenance status, licence, and security
advisories before you depend on it - `package_risk`, `package_licence`,
`package_advisories`. Paid per call in USDC on Base mainnet via [x402](https://x402.org).
**No subscription, no API key.** You pay from your own wallet, per call, only
for what you use.
## What this is (and isn't)
This is a thin client. The actual service is a stateless HTTP API at
`x402-package-risk.x402-package-risk.workers.dev`. This connector never sees,
holds, or forwards anyone else's funds - it only ever spends the wallet key
**you** configure below, and only when **you** call one of its tools.
## Setup
You need an EVM wallet with a small amount of USDC on **Base mainnet**
(calls cost $0.005-$0.01 each). Never use a wallet holding significant funds
for an automated agent key - keep this one funded lightly.
Add to your MCP client config (Claude Desktop, Claude Code, Cursor, etc.):
```json
{
"mcpServers": {
"package-risk": {
"command": "npx",
"args": ["-y", "@makosdav/package-risk-mcp"],
"env": {
"EVM_PRIVATE_KEY": "0xyour-private-key-here"
}
}
}
}
```
## Tools
| Tool | Price | What it returns |
|---|---|---|
| `package_risk` | $0.01 | Full verdict: maintenance, licence, advisories, deprecation |
| `package_licence` | $0.005 | Licence expression and closed-source safety |
| `package_advisories` | $0.005 | Open OSV advisories for the resolved version |
All three take `system` (npm/pypi/go/maven/cargo/nuget), `name`, and an
optional `version`.
## How payment works
1. Your agent calls a tool.
2. This connector requests the resource; the server replies `402 Payment Required`.
3. `@x402/fetch` builds and signs a payment authorisation with your key.
4. The request retries with payment attached; the server verifies via Coinbase
CDP, returns the result, and settles on-chain.
No approval prompt happens here beyond what your MCP client itself asks for -
if you want per-call confirmation, configure that in your agent framework, not
here.