Agent Tools / MCP install guides / Package Health Check in Claude

Package Health Check in Claude

Vulnerabilities and upkeep. The MCP server is https://packages.openkrill.app/mcp. No key. The steps below are only for Claude. A call to check_package was checked against that server on 2026-10-01.

What this server answers

Check an npm or Python package before you depend on it, or the dependencies of a package.json you already have, and get the facts from public sources.

Ask "is lodash 4.17.15 vulnerable?", "is this npm package maintained?", "what license is this package?", "safer alternative to request" or "check my package.json for known vulnerabilities".

Package Health Check reads OSV.dev for known vulnerabilities, the npm registry and the PyPI JSON API for deprecation notices, licenses and versions, deps.dev for release history and dependents, and npm for weekly downloads.

For one package it reports the advisories that affect the version you name (or the latest), how severe each is and the version that fixes it, the license, any deprecation notice, the last release date, how many releases came out in the last year, and how many packages depend on it.

For a package.json it looks up every dependency at the version the file names and lists the ones with known vulnerabilities, most severe first. Version ranges are checked at their lowest version, so a lockfile gives the exact answer for what is installed.

It only needs public package names and versions. Never paste source code, tokens or private package names: a package.json is read for its dependency names and versions only, is not stored, and the rest of the file is ignored.

A recent release date is not a security guarantee, and a package with no known advisories can still be vulnerable. It does not scan source code or recommend replacements on its own: when a package is deprecated or abandoned, ChatGPT suggests candidates and checks each one.

What it can do

Tools

Add Package Health Check in Claude

Claude connects to a remote MCP server as a custom connector. The connection is made from Anthropic's cloud, not from your laptop, so the server must be on the public internet. Package Health Check is. These steps were checked against Claude's custom-connector article (updated 2026-08-11) and the Claude Code MCP docs on 2026-10-01.

On a Pro or Max plan:

  1. Open Customize, then Connectors.
  2. Select the plus button, then Add custom connector.
  3. Paste https://packages.openkrill.app/mcp. Leave Advanced settings empty: this server does not need an OAuth client id or secret.
  4. Select Add. The connector is yours. Anthropic has not reviewed it, and it is not a Directory listing.
  5. In a conversation, open the plus button, then Connectors, and enable Package Health Check. Ask: Is lodash 4.17.15 vulnerable?

On Team and Enterprise, an Owner adds the connector first at Organization settings, then Connectors, then Add, then Custom, then Web, and pastes the same URL. Members then connect it from Customize. A Free plan can add one custom connector.

In Claude Code, add it from the project directory:

claude mcp add --transport http packages https://packages.openkrill.app/mcp

That writes a local or user config. A JSON entry needs "type": "http" (or streamable-http) plus the url. An entry with a url and no type is skipped. Confirm with claude mcp get packages. The tools you should see are check_package, check_package_json.

Enable the connector only in conversations that need it. Claude can call the tools while you work, including during research, so turn off any tool you do not want invoked. Package Health Check does not write to your accounts. It still receives the arguments of each call. Read the privacy page before you paste anything that is not public.

A call checked on 2026-10-01

lodash 4.17.15 is a public npm release with a known advisory, so the vulnerability fields can be checked. The request below was posted to https://packages.openkrill.app/mcp as tools/call. HTTP 200. Source: the Package Health Check server, read 2026-10-01.

{
  "method": "tools/call",
  "params": {
    "name": "check_package",
    "arguments": {
      "name": "lodash",
      "ecosystem": "npm",
      "version": "4.17.15"
    }
  }
}

Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.

Same server, other clients

Roles that use Package Health Check

Terms used on this page

Source: plugin listing for packages in this repository, and a live tools/call on 2026-10-01. As of 2026-10-01.