Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.