ScriptProbe MCP

tech.thecompoundv0.1.0Updated Oct 5, 2026

ScriptProbe: Check npm install scripts and publisher changes before installing.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

Lets an assistant inspect an npm package's install-time scripts and publisher changes before you run npm install.

What it does
ScriptProbe exposes one tool, check_package_scripts(name, version?), which reports the install-time scripts an npm package runs, whether each script reaches the network or spawns a process, and whether the account that published the latest version differs from the previous ten. It is meant to be run before installing a package you have not used. A high verdict means the script is worth reading, not that the package is malware; for example, esbuild reads high because its postinstall downloads a platform binary.
When to use it
Use it when you are about to install an unfamiliar npm package and want a quick look at what its install scripts do and whether the publisher recently changed. It is a pre-install check, not a general vulnerability scanner.
Requirements
Runs locally as a stdio process, typically via npx scriptprobe-mcp; Node.js and network access are needed. No API key, signup, environment variables, or headers are required. It can also serve streamable HTTP on a local port.
Before you install
It only reports on packages; it does not block or remove anything, and a high verdict is not proof of malware. Installing the server runs an npm package on your machine, so the usual care about running third-party code applies.

Installation

In SourceWeft

  1. Open ScriptProbe MCP in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

scriptprobe-mcp

scriptprobe-mcp is the MCP server for ScriptProbe, from Compound Labs. It needs no API key and no signup.

mcp-name: tech.thecompound/scriptprobe

Tool

ToolAnswers
check_package_scripts(name, version?)The install-time scripts an npm package runs, whether each one reaches the network or spawns a process, and whether the account that published the latest version differs from the previous ten. Run it before npm install on a package you have not used.

A high verdict means you should read the script. It does not prove the package is malware. esbuild reads high because its postinstall downloads a platform binary.

Install

sh
claude mcp add scriptprobe -- npx -y scriptprobe-mcp

Claude Desktop, in claude_desktop_config.json:

json
{  "mcpServers": {    "scriptprobe": { "command": "npx", "args": ["-y", "scriptprobe-mcp"] }  }}

scriptprobe-mcp --http 8974 serves streamable HTTP on http://127.0.0.1:8974/mcp.

License

MIT

Source: packages/scriptprobe-mcp/README.md at commit 0caa9ed

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestOct 5, 2026