
Presend dependency checks
io.github.presendappv1.0.0更新於 Oct 3, 2026
Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.
概覽
讓助理在安裝前檢查 npm 與 PyPI 套件的供應鏈風險。
- 功能
- Presend 透過 Streamable HTTP 將供應鏈檢查以 MCP 工具形式提供。主要工具 supply_chain_check 會回報某個套件名稱在 npm 或 PyPI 上是否存在、是否在最近 30 天內首次發布、仿冒套件(typosquat)訊號、所用版本的已知漏洞,以及 npm 上的發布者變更。相關檢查還包括維護者變更、儲存庫健康度、DNS 與 WHOIS 查詢、電子郵件檢查與 JWT 解碼。
- 適用情境
- 適合在助理準備安裝某個相依套件、而你希望在實際安裝前取得快速訊號時使用,例如辨識模型虛構或極新的套件名稱。它提供的是值得留意的訊號,而非結論。
- 執行需求
- 透過 Streamable HTTP 連線的遠端 MCP 端點;不需要帳號、註冊或 API 金鑰,但有每分鐘速率限制。需要能連線至該端點的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Presend dependency checks,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"presend-deps": {
"type": "http",
"url": "https://presend.pages.dev/mcp-deps"
}
}
}README
Presend — Free Privacy Tools, a Security API, and an MCP Server for AI Agents
[Open in GitHub Codespaces] [Live Site]
[Tools] [API] [MCP Server] [npm] [GitHub Marketplace] [Run in Postman] [License] [PWA] [Privacy]
Presend checks npm and PyPI packages before they are installed: typosquats, known vulnerabilities of the version you use, publisher changes (npm), and names that do not exist or were first published in the last 30 days. It is available as a free API, an MCP server for AI agents and a GitHub Action. The site also has free browser tools; the file tools process files locally.
Open Presend · API docs · OpenAPI spec · MCP server · Measurements · For teams
Why Presend?
- Before an agent installs a package -- the MCP tool
supply_chain_checkreportspackage_not_foundfor a name that does not exist on npm or PyPI (it may be invented by a model) andnew_packagefor one first published less than 30 days ago. - Measured false alarms -- the typosquat check is measured on the most downloaded PyPI packages and the npm-high-impact list, with the scripts to reproduce it: see the measurements page.
- Real supply-chain signal (API) --
maintainer-change-checkflags a package recently taken over by a previously unseen publisher after a long dormancy (the event-stream pattern; it does not detect hijacked existing accounts). - What it is not -- not a malware scanner: it reports signals worth a look before installing, it does not analyse package code.
- No account -- the API and the MCP server are free, with no signup and no key; per-minute rate limits apply. A paid offer for teams is being tested: Presend for teams.
- Browser file tools -- the file tools (EXIF, PDF, images, office files) run locally with Web Crypto, Canvas and FileReader. A few other tools rely on a network service (speech recognition, password breach lookup, link preview...); the privacy page lists each one.
- PWA -- install on mobile or desktop.
API & MCP Server
- REST API -- free endpoints: supply-chain checks (typosquat, vulnerabilities of a given version, maintainer change, repository health, and a combined supply-chain check), DNS and WHOIS lookups, email checks, JWT decode and verify, file and image processing, and everyday utilities. Full OpenAPI 3.0 spec.
- MCP server -- the same checks as tools over Streamable HTTP, no signup, no key; listed in the official MCP registry as
io.github.presendapp/presend-mcp. - npm client --
npm install presend-api, zero-dependency. - GitHub Action -- checks the dependencies of
package.jsonorrequirements.txtin CI (npm and PyPI). - Code examples -- working Python for LangChain, CrewAI, LlamaIndex, OpenAI Agents SDK, Google ADK, and plain REST.
- MCP config guides -- copy-paste setup for Claude Desktop, Claude Code, Cursor, and Windsurf, no code required.
- Browser extension -- "Presend — Clean Photos", strips EXIF/GPS on right-click.
Python: Cloudflare rejects the default
urllibUser-Agent (Python-urllib/3.x) with403 error code: 1010. Set an explicit one, e.g.urllib.request.Request(url, headers={"User-Agent": "my-app/1.0"}).requests, curl and Node are not affected.
Browser Tools (48 total, 22 shown below)
SEO and Performance
Presend is built for search engines and AI assistants:
- Schema.org: structured data on the pages (Organization, FAQPage, BreadcrumbList...)
- Sitemap: a static
sitemap.xmlcovering the tools, blog and guides in 8 languages - Dynamic OG Images: API generates social preview images per tool
- Core Web Vitals: Preconnect, DNS-prefetch, CSS preload, zero render-blocking JS
- PWA: Service worker + manifest for offline use and installability
- Privacy-First Analytics: Cloudflare Web Analytics (no cookies, no IP tracking)
Embed on Your Site
Add a Presend tool to your website or link back to us:
Tech Stack
- Frontend: Vanilla HTML5, CSS3, ES6 (zero build step)
- Hosting: Cloudflare Pages (200+ edge locations)
- APIs: Cloudflare Workers (share links, analytics, sitemap, OG images)
- Storage: Cloudflare KV (share links, 30-day TTL)
- PWA: Service Worker + Web App Manifest
License
MIT — free to use, modify, and embed.
來源:README.md,提交 c1613db
工具
0版本歷史
1- v1.0.0最新Oct 3, 2026
