
Presend dependency checks
io.github.presendappv1.0.0Updated Oct 3, 2026
Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.
Overview
Lets an assistant check npm and PyPI packages for supply-chain risks before installing them.
- What it does
- Presend exposes supply-chain checks as MCP tools over Streamable HTTP. The main tool, supply_chain_check, reports whether a package name does not exist on npm or PyPI, whether it was first published in the last 30 days, typosquat signals, known vulnerabilities of the version in use, and publisher changes on npm. Related checks cover maintainer change, repository health, DNS and WHOIS lookups, email checks, and JWT decoding.
- When to use it
- Useful when an agent proposes installing a dependency and you want a quick signal before running the install, for example to catch invented or very new package names. It reports signals worth a look rather than a verdict.
- Requirements
- A remote MCP endpoint over Streamable HTTP; no account, signup, or API key is required, and per-minute rate limits apply. Network access to the endpoint is needed.
Installation
In SourceWeft
- Open Presend dependency checks in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"presend-deps": {
"type": "http",
"url": "https://presend.pages.dev/mcp-deps"
}
}
}README
Presend — Free Privacy Tools, a Security API, and an MCP Server for AI Agents
[Open in GitHub Codespaces] [Live Site]
[Tools] [API] [MCP Server] [npm] [GitHub Marketplace] [Run in Postman] [License] [PWA] [Privacy]
Presend checks npm and PyPI packages before they are installed: typosquats, known vulnerabilities of the version you use, publisher changes (npm), and names that do not exist or were first published in the last 30 days. It is available as a free API, an MCP server for AI agents and a GitHub Action. The site also has free browser tools; the file tools process files locally.
Open Presend · API docs · OpenAPI spec · MCP server · Measurements · For teams
Why Presend?
- Before an agent installs a package -- the MCP tool
supply_chain_checkreportspackage_not_foundfor a name that does not exist on npm or PyPI (it may be invented by a model) andnew_packagefor one first published less than 30 days ago. - Measured false alarms -- the typosquat check is measured on the most downloaded PyPI packages and the npm-high-impact list, with the scripts to reproduce it: see the measurements page.
- Real supply-chain signal (API) --
maintainer-change-checkflags a package recently taken over by a previously unseen publisher after a long dormancy (the event-stream pattern; it does not detect hijacked existing accounts). - What it is not -- not a malware scanner: it reports signals worth a look before installing, it does not analyse package code.
- No account -- the API and the MCP server are free, with no signup and no key; per-minute rate limits apply. A paid offer for teams is being tested: Presend for teams.
- Browser file tools -- the file tools (EXIF, PDF, images, office files) run locally with Web Crypto, Canvas and FileReader. A few other tools rely on a network service (speech recognition, password breach lookup, link preview...); the privacy page lists each one.
- PWA -- install on mobile or desktop.
API & MCP Server
- REST API -- free endpoints: supply-chain checks (typosquat, vulnerabilities of a given version, maintainer change, repository health, and a combined supply-chain check), DNS and WHOIS lookups, email checks, JWT decode and verify, file and image processing, and everyday utilities. Full OpenAPI 3.0 spec.
- MCP server -- the same checks as tools over Streamable HTTP, no signup, no key; listed in the official MCP registry as
io.github.presendapp/presend-mcp. - npm client --
npm install presend-api, zero-dependency. - GitHub Action -- checks the dependencies of
package.jsonorrequirements.txtin CI (npm and PyPI). - Code examples -- working Python for LangChain, CrewAI, LlamaIndex, OpenAI Agents SDK, Google ADK, and plain REST.
- MCP config guides -- copy-paste setup for Claude Desktop, Claude Code, Cursor, and Windsurf, no code required.
- Browser extension -- "Presend — Clean Photos", strips EXIF/GPS on right-click.
Python: Cloudflare rejects the default
urllibUser-Agent (Python-urllib/3.x) with403 error code: 1010. Set an explicit one, e.g.urllib.request.Request(url, headers={"User-Agent": "my-app/1.0"}).requests, curl and Node are not affected.
Browser Tools (48 total, 22 shown below)
SEO and Performance
Presend is built for search engines and AI assistants:
- Schema.org: structured data on the pages (Organization, FAQPage, BreadcrumbList...)
- Sitemap: a static
sitemap.xmlcovering the tools, blog and guides in 8 languages - Dynamic OG Images: API generates social preview images per tool
- Core Web Vitals: Preconnect, DNS-prefetch, CSS preload, zero render-blocking JS
- PWA: Service worker + manifest for offline use and installability
- Privacy-First Analytics: Cloudflare Web Analytics (no cookies, no IP tracking)
Embed on Your Site
Add a Presend tool to your website or link back to us:
Tech Stack
- Frontend: Vanilla HTML5, CSS3, ES6 (zero build step)
- Hosting: Cloudflare Pages (200+ edge locations)
- APIs: Cloudflare Workers (share links, analytics, sitemap, OG images)
- Storage: Cloudflare KV (share links, 30-day TTL)
- PWA: Service Worker + Web App Manifest
License
MIT — free to use, modify, and embed.
Source: README.md at commit c1613db
Tools
0Version history
1- v1.0.0LatestOct 3, 2026
