ScriptProbe MCP

tech.thecompoundv0.1.0更新于 Oct 5, 2026

ScriptProbe: Check npm install scripts and publisher changes before installing.

概览

AI 生成的概览

让助手在你执行 npm install 之前检查 npm 包的安装脚本和发布者变更。

功能
ScriptProbe 提供一个工具 check_package_scripts(name, version?),用于报告某个 npm 包在安装时运行的脚本、每个脚本是否访问网络或启动进程,以及最新版本的发布账号是否与前十个版本不同。它适合在安装未使用过的包之前运行。高判定结果意味着该脚本值得阅读,并不证明该包是恶意软件;例如 esbuild 会得到高判定,因为它的 postinstall 会下载平台二进制文件。
适用场景
当你准备安装不熟悉的 npm 包,想快速了解其安装脚本做什么、发布者是否近期变更时使用。它是安装前检查,不是通用的漏洞扫描器。
运行要求
作为本地 stdio 进程运行,通常通过 npx scriptprobe-mcp 启动;需要 Node.js 和网络访问。不需要 API 密钥、注册、环境变量或请求头。也可在本地端口提供 streamable HTTP 服务。
安装前请注意
它只提供包的检查结果,不会阻止或删除任何内容,高判定也不等于恶意软件。安装该服务器会在你的机器上运行一个 npm 包,因此仍需按运行第三方代码的常规谨慎对待。

安装

在 SourceWeft 中

  1. 打开 控制台中的 ScriptProbe MCP,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

scriptprobe-mcp

scriptprobe-mcp is the MCP server for ScriptProbe, from Compound Labs. It needs no API key and no signup.

mcp-name: tech.thecompound/scriptprobe

Tool

ToolAnswers
check_package_scripts(name, version?)The install-time scripts an npm package runs, whether each one reaches the network or spawns a process, and whether the account that published the latest version differs from the previous ten. Run it before npm install on a package you have not used.

A high verdict means you should read the script. It does not prove the package is malware. esbuild reads high because its postinstall downloads a platform binary.

Install

sh
claude mcp add scriptprobe -- npx -y scriptprobe-mcp

Claude Desktop, in claude_desktop_config.json:

json
{  "mcpServers": {    "scriptprobe": { "command": "npx", "args": ["-y", "scriptprobe-mcp"] }  }}

scriptprobe-mcp --http 8974 serves streamable HTTP on http://127.0.0.1:8974/mcp.

License

MIT

来源:packages/scriptprobe-mcp/README.md,提交 0caa9ed

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Oct 5, 2026