Show HN: Check an NPM package or MCP server for malicious code before install A new security tool lets developers paste an npm package or MCP server install command and receive an automated risk assessment of the published files before running them, without executing any code. The scanner checks npm packages for install scripts that fetch or run code, code touching SSH keys, cloud credentials, tokens or wallets, data destinations, and release age, provenance, maintainer changes and known advisories, while its MCP scanner reviews every tool offered, hidden instructions and invisible characters in tool descriptions, tools that steer agents toward other tools or secrets, and fingerprints the tool list to flag changes. The tool's page states it performs "Automated risk assessment. Not a guarantee of safety. security check Nobody reads what their agent installs. We do. Your agent installs AI skills, MCP servers and npm packages on a single chat message. Paste what you're about to install and see exactly what it does before it ever runs on your machine. Paste the install command you were about to run. We read the published files as text — we never run them. try: Automated risk assessment. Not a guarantee of safety. What we look at One careless install can hand a stranger your SSH keys, cloud credentials and every file on disk — or plant hidden instructions your agent will follow without ever showing you. A check takes seconds. npm package security check - Install scripts that fetch or run code on your machine - Code that touches SSH keys, cloud credentials, tokens or wallets - Where it sends data, and whether those places are known - Release age, provenance, maintainer changes and known advisories MCP security scanner - Every tool it offers, and what each one claims to do - Hidden instructions and invisible characters in tool descriptions - Tools that steer your agent towards other tools or secrets - A fingerprint of the tool list, so you are told when it changes Recent checks, with real findings Every report below came from a live package or server — read the findings before you install. loading…