Presend dependency checks

io.github.presendappv1.0.0更新于 Oct 3, 2026

Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.

已验证Streamable HTTP可网页运行Developer ToolsSecurity & Monitoring

概览

AI 生成的概览

让助手在安装前检查 npm 和 PyPI 软件包的供应链风险。

功能
Presend 通过 Streamable HTTP 把供应链检查作为 MCP 工具提供。主要工具 supply_chain_check 会报告某个包名在 npm 或 PyPI 上是否存在、是否在最近 30 天内首次发布、仿冒包(typosquat)信号、所用版本的已知漏洞,以及 npm 上的发布者变更。相关检查还包括维护者变更、仓库健康度、DNS 与 WHOIS 查询、邮箱检查和 JWT 解码。
适用场景
当助手准备安装某个依赖、你希望在执行安装前获得一个快速信号时适用,例如识别模型编造或极新的包名。它给出的是值得留意的信号,而不是结论。
运行要求
通过 Streamable HTTP 连接的远程 MCP 端点;无需账号、注册或 API 密钥,但有每分钟速率限制。需要能访问该端点的网络。
安装前请注意
它不是恶意软件扫描器,也不分析软件包代码,因此检查通过并不等于安全保证。检查内容会发送到第三方服务。使用默认 urllib User-Agent 的 Python 客户端可能被以 403 拒绝,需要显式设置 User-Agent 头。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Presend dependency checks,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "presend-deps": {
      "type": "http",
      "url": "https://presend.pages.dev/mcp-deps"
    }
  }
}

README

Presend — Free Privacy Tools, a Security API, and an MCP Server for AI Agents

[Open in GitHub Codespaces] [Live Site]

[Tools] [API] [MCP Server] [npm] [GitHub Marketplace] [Run in Postman] [License] [PWA] [Privacy]

Presend checks npm and PyPI packages before they are installed: typosquats, known vulnerabilities of the version you use, publisher changes (npm), and names that do not exist or were first published in the last 30 days. It is available as a free API, an MCP server for AI agents and a GitHub Action. The site also has free browser tools; the file tools process files locally.

Open Presend · API docs · OpenAPI spec · MCP server · Measurements · For teams

Why Presend?

  • Before an agent installs a package -- the MCP tool supply_chain_check reports package_not_found for a name that does not exist on npm or PyPI (it may be invented by a model) and new_package for one first published less than 30 days ago.
  • Measured false alarms -- the typosquat check is measured on the most downloaded PyPI packages and the npm-high-impact list, with the scripts to reproduce it: see the measurements page.
  • Real supply-chain signal (API) -- maintainer-change-check flags a package recently taken over by a previously unseen publisher after a long dormancy (the event-stream pattern; it does not detect hijacked existing accounts).
  • What it is not -- not a malware scanner: it reports signals worth a look before installing, it does not analyse package code.
  • No account -- the API and the MCP server are free, with no signup and no key; per-minute rate limits apply. A paid offer for teams is being tested: Presend for teams.
  • Browser file tools -- the file tools (EXIF, PDF, images, office files) run locally with Web Crypto, Canvas and FileReader. A few other tools rely on a network service (speech recognition, password breach lookup, link preview...); the privacy page lists each one.
  • PWA -- install on mobile or desktop.

API & MCP Server

  • REST API -- free endpoints: supply-chain checks (typosquat, vulnerabilities of a given version, maintainer change, repository health, and a combined supply-chain check), DNS and WHOIS lookups, email checks, JWT decode and verify, file and image processing, and everyday utilities. Full OpenAPI 3.0 spec.
  • MCP server -- the same checks as tools over Streamable HTTP, no signup, no key; listed in the official MCP registry as io.github.presendapp/presend-mcp.
  • npm client -- npm install presend-api, zero-dependency.
  • GitHub Action -- checks the dependencies of package.json or requirements.txt in CI (npm and PyPI).
  • Code examples -- working Python for LangChain, CrewAI, LlamaIndex, OpenAI Agents SDK, Google ADK, and plain REST.
  • MCP config guides -- copy-paste setup for Claude Desktop, Claude Code, Cursor, and Windsurf, no code required.
  • Browser extension -- "Presend — Clean Photos", strips EXIF/GPS on right-click.

Python: Cloudflare rejects the default urllib User-Agent (Python-urllib/3.x) with 403 error code: 1010. Set an explicit one, e.g. urllib.request.Request(url, headers={"User-Agent": "my-app/1.0"}). requests, curl and Node are not affected.

Browser Tools (48 total, 22 shown below)

ToolWhat it doesLink
EXIF RemoverStrip GPS, camera model, timestamps from photosOpen
PDF Metadata RemoverRemove author, software, dates from PDFsOpen
Image CompressorShrink JPG/PNG/WebP with quality previewOpen
PDF CompressReduce PDF file size without quality lossOpen
PDF MergerCombine multiple PDFs into one documentOpen
Image ResizerResize to exact dimensions (Instagram, LinkedIn, Twitter)Open
HEIC to JPG ConverterConvert iPhone photos to universal JPGOpen
Video Metadata RemoverStrip GPS and device data from MP4/MOVOpen
Office Metadata RemoverClean Word, Excel, PowerPoint hidden dataOpen
File Hash CheckerVerify SHA-256, SHA-1, SHA-512 checksumsOpen
Password GeneratorCreate cryptographically secure passwordsOpen
Password StrengthAnalyze password entropy and crack timeOpen
QR Code GeneratorGenerate QR codes for URLs, WiFi, textOpen
URL CleanerRemove tracking parameters (UTM, fbclid, gclid)Open
Email List CleanerDeduplicate, validate, clean email listsOpen
JSON to CSV ConverterConvert between JSON and CSV instantlyOpen
Image to Base64Encode images for embedding in HTML/CSSOpen
Text DiffCompare two texts side by sideOpen
Text FormatterBold, italic, stylized text for social mediaOpen
Thread SplitterSplit long text into Twitter/X threadsOpen
Word CounterCount words, characters, reading timeOpen
Color ContrastCheck WCAG accessibility contrast ratiosOpen

SEO and Performance

Presend is built for search engines and AI assistants:

  • Schema.org: structured data on the pages (Organization, FAQPage, BreadcrumbList...)
  • Sitemap: a static sitemap.xml covering the tools, blog and guides in 8 languages
  • Dynamic OG Images: API generates social preview images per tool
  • Core Web Vitals: Preconnect, DNS-prefetch, CSS preload, zero render-blocking JS
  • PWA: Service worker + manifest for offline use and installability
  • Privacy-First Analytics: Cloudflare Web Analytics (no cookies, no IP tracking)

Embed on Your Site

Add a Presend tool to your website or link back to us:

See all embed options

Tech Stack

  • Frontend: Vanilla HTML5, CSS3, ES6 (zero build step)
  • Hosting: Cloudflare Pages (200+ edge locations)
  • APIs: Cloudflare Workers (share links, analytics, sitemap, OG images)
  • Storage: Cloudflare KV (share links, 30-day TTL)
  • PWA: Service Worker + Web App Manifest

License

MIT — free to use, modify, and embed.

Open Presend

来源:README.md,提交 c1613db

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 3, 2026