
ScriptProbe MCP
tech.thecompoundv0.1.0更新于 Oct 5, 2026
ScriptProbe: Check npm install scripts and publisher changes before installing.
概览
AI 生成的概览
让助手在你执行 npm install 之前检查 npm 包的安装脚本和发布者变更。
- 功能
- ScriptProbe 提供一个工具 check_package_scripts(name, version?),用于报告某个 npm 包在安装时运行的脚本、每个脚本是否访问网络或启动进程,以及最新版本的发布账号是否与前十个版本不同。它适合在安装未使用过的包之前运行。高判定结果意味着该脚本值得阅读,并不证明该包是恶意软件;例如 esbuild 会得到高判定,因为它的 postinstall 会下载平台二进制文件。
- 适用场景
- 当你准备安装不熟悉的 npm 包,想快速了解其安装脚本做什么、发布者是否近期变更时使用。它是安装前检查,不是通用的漏洞扫描器。
- 运行要求
- 作为本地 stdio 进程运行,通常通过 npx scriptprobe-mcp 启动;需要 Node.js 和网络访问。不需要 API 密钥、注册、环境变量或请求头。也可在本地端口提供 streamable HTTP 服务。
安装前请注意
它只提供包的检查结果,不会阻止或删除任何内容,高判定也不等于恶意软件。安装该服务器会在你的机器上运行一个 npm 包,因此仍需按运行第三方代码的常规谨慎对待。
安装
在 SourceWeft 中
- 打开 控制台中的 ScriptProbe MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
scriptprobe-mcp
scriptprobe-mcp is the MCP server for ScriptProbe, from Compound Labs. It needs no API key and no signup.
mcp-name: tech.thecompound/scriptprobe
Tool
A high verdict means you should read the script. It does not prove the package is malware. esbuild reads high because its postinstall downloads a platform binary.
Install
Claude Desktop, in claude_desktop_config.json:
scriptprobe-mcp --http 8974 serves streamable HTTP on http://127.0.0.1:8974/mcp.
License
MIT
来源:packages/scriptprobe-mcp/README.md,提交 0caa9ed
工具
0工具元数据尚未被收录。
版本历史
1- v0.1.0最新Oct 5, 2026
