ScriptProbe MCP

tech.thecompoundv0.1.0更新於 Oct 5, 2026

ScriptProbe: Check npm install scripts and publisher changes before installing.

概覽

AI 產生的概覽

讓助手在你執行 npm install 之前檢查 npm 套件的安裝指令碼與發佈者變更。

功能
ScriptProbe 提供一個工具 check_package_scripts(name, version?),用來回報某個 npm 套件在安裝時執行的指令碼、每個指令碼是否連上網路或啟動行程,以及最新版本的發佈帳號是否與前十个版本不同。它適合在安裝未曾使用過的套件之前執行。高判定結果代表該指令碼值得閱讀,並不證明該套件是惡意軟體;例如 esbuild 會得到高判定,因為它的 postinstall 會下載平台二進位檔。
適用情境
當你準備安裝不熟悉的 npm 套件,想快速了解其安裝指令碼做什麼、發佈者是否近期變更時使用。它是安裝前檢查,不是通用的弱點掃描器。
執行需求
以本機 stdio 行程執行,通常透過 npx scriptprobe-mcp 啟動;需要 Node.js 與網路存取。不需要 API 金鑰、註冊、環境變數或標頭。也可在本機連接埠提供 streamable HTTP 服務。
安裝前請注意
它只提供套件的檢查結果,不會阻擋或刪除任何內容,高判定也不等於惡意軟體。安裝此伺服器會在你的機器上執行一個 npm 套件,因此仍需依執行第三方程式碼的慣例謹慎處理。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 ScriptProbe MCP,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

scriptprobe-mcp

scriptprobe-mcp is the MCP server for ScriptProbe, from Compound Labs. It needs no API key and no signup.

mcp-name: tech.thecompound/scriptprobe

Tool

ToolAnswers
check_package_scripts(name, version?)The install-time scripts an npm package runs, whether each one reaches the network or spawns a process, and whether the account that published the latest version differs from the previous ten. Run it before npm install on a package you have not used.

A high verdict means you should read the script. It does not prove the package is malware. esbuild reads high because its postinstall downloads a platform binary.

Install

sh
claude mcp add scriptprobe -- npx -y scriptprobe-mcp

Claude Desktop, in claude_desktop_config.json:

json
{  "mcpServers": {    "scriptprobe": { "command": "npx", "args": ["-y", "scriptprobe-mcp"] }  }}

scriptprobe-mcp --http 8974 serves streamable HTTP on http://127.0.0.1:8974/mcp.

License

MIT

來源:packages/scriptprobe-mcp/README.md,提交 0caa9ed

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 5, 2026