cd /news/ai-safety/show-hn-check-an-npm-package-or-mcp-… · home topics ai-safety article
[ARTICLE · art-131110] src=bouncer.run ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Show HN: Check an NPM package or MCP server for malicious code before install

A new security tool lets developers paste an npm package or MCP server install command and receive an automated risk assessment of the published files before running them, without executing any code. The scanner checks npm packages for install scripts that fetch or run code, code touching SSH keys, cloud credentials, tokens or wallets, data destinations, and release age, provenance, maintainer changes and known advisories, while its MCP scanner reviews every tool offered, hidden instructions and invisible characters in tool descriptions, tools that steer agents toward other tools or secrets, and fingerprints the tool list to flag changes. The tool's page states it performs "Automated risk assessment. Not a guarantee of safety.

by read1 min views1 publishedSep 16, 2026
Show HN: Check an NPM package or MCP server for malicious code before install
Image: source

security check

Your agent installs AI skills, MCP servers and npm packages on a single chat message. Paste what you're about to install and see exactly what it does before it ever runs on your machine.

Paste the install command you were about to run. We read the published files as text — we never run them.

try:

Automated risk assessment. Not a guarantee of safety.

What we look at #

One careless install can hand a stranger your SSH keys, cloud credentials and every file on disk — or plant hidden instructions your agent will follow without ever showing you. A check takes seconds.

npm package security check

  • Install scripts that fetch or run code on your machine
  • Code that touches SSH keys, cloud credentials, tokens or wallets
  • Where it sends data, and whether those places are known
  • Release age, provenance, maintainer changes and known advisories

MCP security scanner

  • Every tool it offers, and what each one claims to do
  • Hidden instructions and invisible characters in tool descriptions
  • Tools that steer your agent towards other tools or secrets
  • A fingerprint of the tool list, so you are told when it changes

Recent checks, with real findings #

Every report below came from a live package or server — read the findings before you install.

── more in #ai-safety 4 stories · sorted by recency
── more on @npm 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/show-hn-check-an-npm…] indexed:0 read:1min 2026-09-16 ·