LO

Lockfile Guardian MCP

Audit a package-lock.json for supply-chain attacks BEFORE npm install. Cross-checks every resolved dependency against the live npm

Grade A Local · stdio No auth needed tools not listed v0.2.2
No reviews yet by baneado98npm Runs on your machine, nothing hosted
p95 latency
call success
local
runs on your machine
calls last 7d

What it does

Audit a package-lock.json for supply-chain attacks BEFORE npm install. Cross-checks every resolved dependency against the live npm registry: blocks integrity (sha512) mismatches (lockfile poisoning) and not-on-registry entries, and flags new/fresh depende

Quickstart

# 1 — run it from where its publisher ships it npx -y lockfile-guardian-mcp # 2 — ask your agent something > Audit a package-lock.json for supply-chain attacks BEFORE npm install. Cross-checks every resolved dependency against the live npm

Lockfile Guardian is free: there is no plan to choose, no cap to set and nothing that can bill you.

Publishernot claimed
BA
baneado9818 servers
7 categories

Collected from a public index. Nobody has claimed this account, so nothing here was written by its author — claim it if it is yours.

All 18 servers
Often installed together

Pairs well with

See all