Npmlens Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Npmlens Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center"> <img src="images/npmlens-mcp-logo.svg" alt="NPMLens MCP Logo" width="80" height="80"> <h1>NPMLens MCP</h1> </div>
<p> <a href="https://npmjs.org/package/npmlens-mcp"> <img src="https://img.shields.io/npm/v/npmlens-mcp.svg" alt="npm version"> </a> <a href="https://github.com/rakeshmenon/npmlens-mcp/actions/workflows/ci.yml"> <img src="https://github.com/rakeshmenon/npmlens-mcp/actions/workflows/ci.yml/badge.svg" alt="CI"> </a> <img src="https://img.shields.io/npm/dm/npmlens-mcp?logo=npm" alt="npm downloads"> <img src="https://img.shields.io/badge/TypeScript-5.x-3178C6?logo=typescript&logoColor=white" alt="TypeScript"> <img src="https://img.shields.io/badge/Node-%3E%3D18.17-339933?logo=node.js&logoColor=white" alt="Node"> <img src="https://img.shields.io/badge/MCP-Server-6E56CF" alt="MCP"> <img src="https://img.shields.io/badge/tests-Vitest-729B1B?logo=vitest&logoColor=white" alt="Tests"> <img src="https://img.shields.io/badge/coverage-100%25-brightgreen" alt="Coverage"> <img src="https://img.shields.io/badge/lint-ESLint-4B32C3?logo=eslint&logoColor=white" alt="Lint"> <img src="https://img.shields.io/badge/license-MIT-blue" alt="License"> </p>
npmlens-mcp lets your coding agent (such as Claude, Cursor, Copilot, Gemini or Codex) search the npm registry and fetch package context (README, downloads, GitHub info, usage snippets). It acts as a Model‑Context‑Protocol (MCP) server, giving your AI assistant a structured way to discover libraries and integrate them quickly.
npmlens-mcp performs network requests to npm and GitHub when tools are used. Avoid sharing secrets in prompts; set GITHUB_TOKEN only if you want higher GitHub rate limits.
Add the following config to your MCP client:
{
"mcpServers": {
"npmlens": {
"command": "npx",
"args": ["-y", "npmlens-mcp@latest"]
}
}
}[!NOTE] Using npmlens-mcp@latest ensures your MCP client always runs the latest published version.<details> <summary>Amp</summary> Follow the Amp docs and use the config provided above. You can also install via CLI:
amp mcp add npmlens -- npx npmlens-mcp@latest</details>
<details> <summary>Claude Code</summary> Use the Claude Code CLI to add the NPMLens MCP server (see the Claude Code MCP guide):
claude mcp add npmlens npx npmlens-mcp@latest</details>
<details> <summary>Cline</summary> Follow <https://docs.cline.bot/mcp/configuring-mcp-servers> and use the config provided above. </details>
<details> <summary>Codex</summary> Use the Codex CLI to add the server:
codex mcp add npmlens -- npx npmlens-mcp@latest</details>
<details> <summary>Copilot CLI</summary>
Start Copilot CLI:
copilotStart the dialog to add a new MCP server by running:
/mcp addConfigure the following fields and press CTRL+S to save:
npmlensLocalnpx -y npmlens-mcp@latest</details>
<details> <summary>Copilot / VS Code</summary> Use the VS Code CLI:
code --add-mcp '{"name":"npmlens","command":"npx","args":["-y","npmlens-mcp@latest"]}'</details>
<details> <summary>Cursor</summary>
Go to Cursor Settings -> MCP -> New MCP Server. Use the config provided above.
</details>
<details> <summary>Gemini CLI</summary> Install the NPMLens MCP server using the Gemini CLI.
Project wide:
gemini mcp add npmlens npx npmlens-mcp@latestGlobally:
gemini mcp add -s user npmlens npx npmlens-mcp@latestAlternatively, follow the Gemini CLI MCP guide and use the standard config from above.
</details>
<details> <summary>Gemini Code Assist</summary> Follow the provider guide to configure MCP servers and use the standard config from above. </details>
<details> <summary>JetBrains AI Assistant & Junie</summary>
Go to Settings | Tools | AI Assistant | Model Context Protocol (MCP) -> Add. Use the config provided above. Same for Junie under Settings | Tools | Junie | MCP Settings -> Add.
</details>
<details> <summary>Warp</summary>
Go to Settings | AI | Manage MCP Servers -> + Add and use the config provided above.
</details>
Enter one of the following prompts in your MCP client to check if everything works:
Basic search and info:
Find 5 React debounce hook libraries, include weekly downloads, and
fetch the README for the top result.Compare packages:
Compare react-query, swr, and apollo-client. Show me their weekly
downloads, GitHub stars, and licenses.Version history:
Show me all TypeScript versions released in the last 6 months with
their publish dates.Dependencies:
What are the dependencies of express? Include dev dependencies.Looking for JSON‑RPC examples, tool schemas, the local dev CLI, troubleshooting, or contributor setup?
docs/advanced.md for all technical details.CONTRIBUTING.md for contributing guidelines.Below are the tools exposed by NPMLens MCP. For full JSON schemas, see the Tool reference.
search_npmquery (string, required), size (1..250), from (offset),weights (object with quality, popularity, maintenance).
{ total, results[] } where each result includes name,version, description, links, score, etc.
search_by_keywordskeywords (array of strings, required), operator (AND |OR, default AND), size (1..250).
search_npm.get_readmename (string, required), version (string), truncateAt(number).
name, version, repository, homepage)and the README as text content.
get_package_infoand GitHub details.
name (string, required), version (string), includeReadme(boolean).
name, version, repository, homepage, `github{fullName, url, stars, forks, license }, downloadsLastWeek, and optional readme`.
get_usage_snippetname (string, required), version (string).{ snippet: { language, code, heading } }.get_package_versionstags.
name (string, required), limit (number), since (string -ISO date or relative like "6 months").
{ name, versions[] } where each version includesversion, date, tags[].
get_package_dependenciesname (string, required), version (string), depth (1-3,default 1), includeDevDependencies (boolean).
{ name, version, dependencies[], devDependencies[] } withname and version range for each dependency.
get_downloadsday/week/month.name (string, required), period (day | week | month,default week).
{ downloads, start, end, package }.compare_packagespackages (array of 1-10 package names, required).name, version,description, downloads, stars, forks, license, repository, homepage, and optional error.
Below are example queries you can use with your AI assistant to test all 9 NPMLens tools:
Search npm for react testing librariesFind packages related to "typescript validation" and show me the top 5 resultsShow me the README for expressGet the README for react version 18.0.0Get detailed information about the lodash packageTell me about the vite package including GitHub stats and download numbersHow many downloads does react have in the last week?Show me download statistics for next for the last monthShow me a usage example for axiosHow do I use the commander package? Give me a code snippet.List all versions of React from the last yearShow me the version history of TypeScript since 6 months agoWhat dependencies does express have?Show me the dependency tree for next with depth 2Compare react, vue, and angularCompare the packages axios, fetch, and node-fetch and help me decide which to useFind packages with keywords "react" AND "hooks" AND "typescript"Search for packages with keywords "cli" OR "terminal"You can also ask your AI assistant to use multiple tools together:
Compare react-query, swr, and apollo-client, then show me usage examples for the most popular oneSearch for typescript validation libraries, then show me the README and dependencies for the top resultFind the package "zod", show me its download stats, version history, and a usage exampleNPMLens MCP is MIT licensed. Contributions are welcome! Please see CONTRIBUTING.md for guidelines.
Found a bug or have a feature request? Open an issue on GitHub.
Made with ❤️ for the vibe coding community. Happy coding!
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.