Skip to content

Support scanning MCP server npm packages #3

Description

@amberb617

MCP servers distributed via npm are one of the fastest-growing AI artifact types. artguard should be able to scan an npm package (local tarball or directory) containing an MCP server config.

What to build:

  • Detect MCP server packages by looking for mcp.json, tool definitions in package.json, or server manifest files
  • Parse tool definitions, permission scopes, and network endpoints
  • Extract README/description claims for Layer 1 privacy posture comparison

Why it matters:
npm MCP packages are being installed with zero review. This is arguably the highest-risk artifact type in the wild right now.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions