Package Health Check in ChatGPT
Vulnerabilities and upkeep. The MCP server is https://packages.openkrill.app/mcp. No key. The steps below are only for ChatGPT. A call to check_package was checked against that server on 2026-10-01.
What this server answers
Check an npm or Python package before you depend on it, or the dependencies of a package.json you already have, and get the facts from public sources.
Ask "is lodash 4.17.15 vulnerable?", "is this npm package maintained?", "what license is this package?", "safer alternative to request" or "check my package.json for known vulnerabilities".
Package Health Check reads OSV.dev for known vulnerabilities, the npm registry and the PyPI JSON API for deprecation notices, licenses and versions, deps.dev for release history and dependents, and npm for weekly downloads.
For one package it reports the advisories that affect the version you name (or the latest), how severe each is and the version that fixes it, the license, any deprecation notice, the last release date, how many releases came out in the last year, and how many packages depend on it.
For a package.json it looks up every dependency at the version the file names and lists the ones with known vulnerabilities, most severe first. Version ranges are checked at their lowest version, so a lockfile gives the exact answer for what is installed.
It only needs public package names and versions. Never paste source code, tokens or private package names: a package.json is read for its dependency names and versions only, is not stored, and the rest of the file is ignored.
A recent release date is not a security guarantee, and a package with no known advisories can still be vulnerable. It does not scan source code or recommend replacements on its own: when a package is deprecated or abandoned, ChatGPT suggests candidates and checks each one.
What it can do
- Lists known vulnerabilities of an npm or PyPI package version with severity and the fixed version
- Shows the license, deprecation notice, last release date and release pace of a package
- Shows how many packages depend on a package and its weekly npm downloads
- Checks every dependency of a pasted package.json for known vulnerabilities
- Checks candidate replacements for a deprecated or abandoned package
Tools
check_package, Check a package's health. Use this when the user asks whether an npm or PyPI package is vulnerable, maintained, deprecated or safe to use, or what license it has: "is lodash 4.17.15 vulnerable?", "is this npm package maintained?", "what license is this package?", "safer alternative to request". Pass the public package name, ecosystem (npm or pypi) and a version if the user gave one; otherwise the latest is checked. Returns the known vulnerabilities of that version with severity and fixed version, the license, any deprecation notice, last release date, releases in the last year, weekly downloads (npm) and dependents. It does not pick alternatives: for a deprecated or stale package, suggest candidates and check each one with this tool.check_package_json, Check package.json for vulnerabilities. Use this when the user asks to check their package.json, or the dependencies of a project, for known vulnerabilities: "check my package.json for known vulnerabilities". Pass the text of the package.json; only the names and versions in dependencies, devDependencies and optionalDependencies are read, nothing else in the file is used or kept, and nothing is stored. Do not ask for source code or tokens. Checks up to 150 npm dependencies at the version each names (ranges at their lowest version) and returns the vulnerable ones, most severe first, with the fixed version. Dependencies without an exact version (tags, urls, workspaces) are listed as skipped.
Add Package Health Check in ChatGPT
ChatGPT does not read a local config file. A custom MCP server is added in the product, and only after developer mode is on. These steps were checked against OpenAI's plugin connect guide and the ChatGPT MCP guide on 2026-10-01. Developer mode can be hidden by a workspace policy, so a Team or Enterprise admin may have to allow it first.
- Open ChatGPT settings, then Security and login, and turn on Developer mode.
- Open ChatGPT plugins and select the plus button.
- Enter a name such as "Package Health Check" and a one-line description of what you want it to answer.
- Under Connection, choose the public endpoint and paste
https://packages.openkrill.app/mcp. Include the/mcppath. Do not add a tunnel id: this server is already public. - Create the connection and review the tools ChatGPT lists. You should see
check_package,check_package_json. The feedback tools on the same server are optional and not required for the lookup. - Start a new conversation, add the connection from the tools menu, and ask: Is lodash 4.17.15 vulnerable?
No API key and no OAuth client id are required. The server answers without a login. Calls are limited per network and per day, and a limit comes back as a tool error rather than a partial answer. If the tool list is stale after a server change, open the connection and select Refresh, then start a new conversation.
The ChatGPT desktop app, Codex CLI and IDE extension share a different config. In the desktop app, open Settings, then MCP servers, choose Add server, select Streamable HTTP, and paste the same URL. In ~/.codex/config.toml the equivalent is a table named mcp_servers.packages with url = "https://packages.openkrill.app/mcp". ChatGPT on the web does not read that file. A published directory listing is also a different path: this page is the developer-mode connection, not a claim that Package Health Check is already in the ChatGPT directory.
Treat the server as untrusted until you have read a few answers. A remote MCP server sees the arguments the model sends. Package Health Check is read-only and documents what it sends onward on the privacy page.
A call checked on 2026-10-01
lodash 4.17.15 is a public npm release with a known advisory, so the vulnerability fields can be checked. The request below was posted to https://packages.openkrill.app/mcp as tools/call. HTTP 200. Source: the Package Health Check server, read 2026-10-01.
{
"method": "tools/call",
"params": {
"name": "check_package",
"arguments": {
"name": "lodash",
"ecosystem": "npm",
"version": "4.17.15"
}
}
}
- status. ok
- name. lodash
- vulnerabilities. 6 returned
Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.