.codex-plugin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited .codex-plugin (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center"> <h1>@cyanheads/npi-providers-mcp-server</h1> <p><b>Look up US healthcare providers in the NPPES NPI registry and resolve NUCC specialty codes via MCP. STDIO or Streamable HTTP.</b> <div>3 Tools • 2 Resources</div> </p> </div>
<div align="center">
</div>
<div align="center">
</div>
<div align="center">
Public Hosted Server: https://npi-providers.caseyjhand.com/mcp
</div>
Three tools covering the provider directory — search the registry, decode an NPI to its full record, and resolve plain-language specialties through the bundled taxonomy:
| Tool | Description |
|---|---|
npi_search_providers | Search the NPPES registry by name, organization, location, provider type, and specialty. Plain-language specialties resolve through the bundled NUCC taxonomy before searching. |
npi_get_provider | Fetch the complete NPPES record for up to 10 NPIs — taxonomies, addresses, credentials, identifiers, endpoints, and status. |
npi_lookup_taxonomy | Resolve, fetch, or browse the NUCC Healthcare Provider Taxonomy — fully offline. |
npi_search_providersSearch the registry for individual practitioners and organizations, with specialty resolution and honest pagination disclosure.
name_search shortcut, explicit first_name / last_name, organization_name, city / state / postal_code, and provider_type (individual / organization)specialty (e.g. "cardiologist") resolves through the bundled NUCC taxonomy to the registry's exact descriptions before searching; the resolved taxonomy is echoed back so you can see what was actually searchedtaxonomy_description escape hatch for callers who already hold an exact NUCC description (mutually exclusive with specialty)*) name matching, with the registry's ≥2-leading-character rule documented inlinenpi_get_providerDecode one or more NPIs into fully populated provider profiles — the tool to turn an NPI from a claim, prescription, or another health data source into a known provider.
notFound rather than failing the whole callnpi_lookup_taxonomyResolve and browse the NUCC Healthcare Provider Taxonomy — the specialty code set NPPES uses — fully offline from the bundled code set.
resolve — turn a plain-language specialty into matching taxonomy codes and canonical descriptions (the value the search tools filter on)get — return the full entry for an exact taxonomy codebrowse — walk the hierarchy (grouping → classification → specialization), filterable by grouping and by NPI section (Individual/NPI-1 vs Non-Individual/NPI-2)| Type | Name | Description |
|---|---|---|
| Resource | npi://provider/{npi} | A single provider's full decoded record by NPI — the resource twin of npi_get_provider. |
| Resource | npi://taxonomy/{code} | A single NUCC taxonomy entry by code — the resource twin of npi_lookup_taxonomy mode get. |
All resource data is also reachable via tools. The resources are convenience twins for resource-capable clients; tool-only clients lose nothing.
Built on @cyanheads/mcp-ts-core:
none, jwt, oauthin-memory, filesystem, Supabase, Cloudflare KV/R2/D1NPI/NPPES-specific:
Errors[] body on validation failure and maps it to typed, recoverable error reasonsAgent-friendly output:
taxonomy_description sent to the registry are echoed back, so agents can see what was actually searched and re-run with a different codenpi_get_provider returns per-NPI found / notFound rows instead of failing the whole batch when some NPIs are deactivated or never enumeratedA public instance is available at https://npi-providers.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP, with this client config:
{
"mcpServers": {
"npi-providers-mcp-server": {
"type": "streamable-http",
"url": "https://npi-providers.caseyjhand.com/mcp"
}
}
}Add the following to your MCP client configuration file. No API key is required — the upstream NPPES registry is keyless.
{
"mcpServers": {
"npi-providers-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/npi-providers-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"npi-providers-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/npi-providers-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"npi-providers-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/npi-providers-mcp-server:latest"]
}
}
}For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpgit clone https://github.com/cyanheads/npi-providers-mcp-server.gitcd npi-providers-mcp-serverbun installcp .env.example .env
# edit .env only if you need to override the NPPES base URL or timeoutNo required variables — the server runs out of the box against the keyless NPPES registry. All variables below are optional overrides.
| Variable | Description | Default |
|---|---|---|
NPPES_API_BASE_URL | NPPES NPI Registry API base URL. Override for a private mirror or testing. | https://npiregistry.cms.hhs.gov/api |
NPPES_TIMEOUT_MS | Per-request HTTP timeout for NPPES calls, in milliseconds. | 15000 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for the HTTP server. | 3010 |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
STORAGE_PROVIDER_TYPE | Storage backend. | in-memory |
OTEL_ENABLED | Enable OpenTelemetry instrumentation (spans, metrics, completion logs). | false |
See .env.example for the full list of optional overrides.
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against specdocker build -t npi-providers-mcp-server .
docker run --rm -e MCP_TRANSPORT_TYPE=http -p 3010:3010 npi-providers-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/npi-providers-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools and resources, inits services. |
src/config | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools | Tool definitions (*.tool.ts). |
src/mcp-server/resources | Resource definitions (*.resource.ts). |
src/services/nppes | NPPES NPI Registry API client — query building, Errors[]-on-200 detection, normalization. |
src/services/taxonomy | Bundled NUCC taxonomy service — in-memory index for resolve / get / browse. |
tests/ | Unit and integration tests mirroring src/. |
See CLAUDE.md/AGENTS.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagecreateApp() arraysIssues and pull requests are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testApache-2.0 — see LICENSE for details.
Provider data from the CMS NPPES NPI Registry (public domain). Specialty codes from the NUCC Health Care Provider Taxonomy (NUCC, bundled).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.