Presend dependency checks

io.github.presendappv1.0.0更新於 Oct 3, 2026

Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & Monitoring

概覽

AI 產生的概覽

讓助理在安裝前檢查 npm 與 PyPI 套件的供應鏈風險。

功能
Presend 透過 Streamable HTTP 將供應鏈檢查以 MCP 工具形式提供。主要工具 supply_chain_check 會回報某個套件名稱在 npm 或 PyPI 上是否存在、是否在最近 30 天內首次發布、仿冒套件(typosquat)訊號、所用版本的已知漏洞,以及 npm 上的發布者變更。相關檢查還包括維護者變更、儲存庫健康度、DNS 與 WHOIS 查詢、電子郵件檢查與 JWT 解碼。
適用情境
適合在助理準備安裝某個相依套件、而你希望在實際安裝前取得快速訊號時使用,例如辨識模型虛構或極新的套件名稱。它提供的是值得留意的訊號,而非結論。
執行需求
透過 Streamable HTTP 連線的遠端 MCP 端點;不需要帳號、註冊或 API 金鑰,但有每分鐘速率限制。需要能連線至該端點的網路。
安裝前請注意
它不是惡意軟體掃描器,也不分析套件程式碼,因此檢查通過並不代表安全保證。檢查內容會傳送至第三方服務。使用預設 urllib User-Agent 的 Python 用戶端可能被以 403 拒絕,需要明確設定 User-Agent 標頭。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Presend dependency checks,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "presend-deps": {
      "type": "http",
      "url": "https://presend.pages.dev/mcp-deps"
    }
  }
}

README

Presend — Free Privacy Tools, a Security API, and an MCP Server for AI Agents

[Open in GitHub Codespaces] [Live Site]

[Tools] [API] [MCP Server] [npm] [GitHub Marketplace] [Run in Postman] [License] [PWA] [Privacy]

Presend checks npm and PyPI packages before they are installed: typosquats, known vulnerabilities of the version you use, publisher changes (npm), and names that do not exist or were first published in the last 30 days. It is available as a free API, an MCP server for AI agents and a GitHub Action. The site also has free browser tools; the file tools process files locally.

Open Presend · API docs · OpenAPI spec · MCP server · Measurements · For teams

Why Presend?

  • Before an agent installs a package -- the MCP tool supply_chain_check reports package_not_found for a name that does not exist on npm or PyPI (it may be invented by a model) and new_package for one first published less than 30 days ago.
  • Measured false alarms -- the typosquat check is measured on the most downloaded PyPI packages and the npm-high-impact list, with the scripts to reproduce it: see the measurements page.
  • Real supply-chain signal (API) -- maintainer-change-check flags a package recently taken over by a previously unseen publisher after a long dormancy (the event-stream pattern; it does not detect hijacked existing accounts).
  • What it is not -- not a malware scanner: it reports signals worth a look before installing, it does not analyse package code.
  • No account -- the API and the MCP server are free, with no signup and no key; per-minute rate limits apply. A paid offer for teams is being tested: Presend for teams.
  • Browser file tools -- the file tools (EXIF, PDF, images, office files) run locally with Web Crypto, Canvas and FileReader. A few other tools rely on a network service (speech recognition, password breach lookup, link preview...); the privacy page lists each one.
  • PWA -- install on mobile or desktop.

API & MCP Server

  • REST API -- free endpoints: supply-chain checks (typosquat, vulnerabilities of a given version, maintainer change, repository health, and a combined supply-chain check), DNS and WHOIS lookups, email checks, JWT decode and verify, file and image processing, and everyday utilities. Full OpenAPI 3.0 spec.
  • MCP server -- the same checks as tools over Streamable HTTP, no signup, no key; listed in the official MCP registry as io.github.presendapp/presend-mcp.
  • npm client -- npm install presend-api, zero-dependency.
  • GitHub Action -- checks the dependencies of package.json or requirements.txt in CI (npm and PyPI).
  • Code examples -- working Python for LangChain, CrewAI, LlamaIndex, OpenAI Agents SDK, Google ADK, and plain REST.
  • MCP config guides -- copy-paste setup for Claude Desktop, Claude Code, Cursor, and Windsurf, no code required.
  • Browser extension -- "Presend — Clean Photos", strips EXIF/GPS on right-click.

Python: Cloudflare rejects the default urllib User-Agent (Python-urllib/3.x) with 403 error code: 1010. Set an explicit one, e.g. urllib.request.Request(url, headers={"User-Agent": "my-app/1.0"}). requests, curl and Node are not affected.

Browser Tools (48 total, 22 shown below)

ToolWhat it doesLink
EXIF RemoverStrip GPS, camera model, timestamps from photosOpen
PDF Metadata RemoverRemove author, software, dates from PDFsOpen
Image CompressorShrink JPG/PNG/WebP with quality previewOpen
PDF CompressReduce PDF file size without quality lossOpen
PDF MergerCombine multiple PDFs into one documentOpen
Image ResizerResize to exact dimensions (Instagram, LinkedIn, Twitter)Open
HEIC to JPG ConverterConvert iPhone photos to universal JPGOpen
Video Metadata RemoverStrip GPS and device data from MP4/MOVOpen
Office Metadata RemoverClean Word, Excel, PowerPoint hidden dataOpen
File Hash CheckerVerify SHA-256, SHA-1, SHA-512 checksumsOpen
Password GeneratorCreate cryptographically secure passwordsOpen
Password StrengthAnalyze password entropy and crack timeOpen
QR Code GeneratorGenerate QR codes for URLs, WiFi, textOpen
URL CleanerRemove tracking parameters (UTM, fbclid, gclid)Open
Email List CleanerDeduplicate, validate, clean email listsOpen
JSON to CSV ConverterConvert between JSON and CSV instantlyOpen
Image to Base64Encode images for embedding in HTML/CSSOpen
Text DiffCompare two texts side by sideOpen
Text FormatterBold, italic, stylized text for social mediaOpen
Thread SplitterSplit long text into Twitter/X threadsOpen
Word CounterCount words, characters, reading timeOpen
Color ContrastCheck WCAG accessibility contrast ratiosOpen

SEO and Performance

Presend is built for search engines and AI assistants:

  • Schema.org: structured data on the pages (Organization, FAQPage, BreadcrumbList...)
  • Sitemap: a static sitemap.xml covering the tools, blog and guides in 8 languages
  • Dynamic OG Images: API generates social preview images per tool
  • Core Web Vitals: Preconnect, DNS-prefetch, CSS preload, zero render-blocking JS
  • PWA: Service worker + manifest for offline use and installability
  • Privacy-First Analytics: Cloudflare Web Analytics (no cookies, no IP tracking)

Embed on Your Site

Add a Presend tool to your website or link back to us:

See all embed options

Tech Stack

  • Frontend: Vanilla HTML5, CSS3, ES6 (zero build step)
  • Hosting: Cloudflare Pages (200+ edge locations)
  • APIs: Cloudflare Workers (share links, analytics, sitemap, OG images)
  • Storage: Cloudflare KV (share links, 30-day TTL)
  • PWA: Service Worker + Web App Manifest

License

MIT — free to use, modify, and embed.

Open Presend

來源:README.md,提交 c1613db

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 3, 2026