pkg-oracle — Dependency Trust Oracle

io.github.julian-martin89v1.0.1Updated Sep 25, 2026

Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.

VerifiedStreamable HTTPWeb executableAI & ML

Installation

In SourceWeft

  1. Open pkg-oracle — Dependency Trust Oracle in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "pkg-oracle": {
      "type": "http",
      "url": "https://mcp-snowy-dew-9447.fly.dev/mcp"
    }
  }
}

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.1LatestSep 16, 2026