{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"net.pkgproof/pkgproof","description":"Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.","title":"pkgproof","repository":{"url":"https://github.com/jahija-okan/pkgproof-mcp","source":"github"},"version":"0.1.7","websiteUrl":"https://pkgproof.net","packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@pkgproof/mcp","version":"0.1.7","transport":{"type":"stdio"},"environmentVariables":[{"description":"Base64 account key of a throwaway Algorand wallet holding USDC (ASA 31566704) on Algorand Mainnet. Not a 25-word mnemonic. Optional: the first verification each day is free without any key. This is the rail payments prefer.","isSecret":true,"name":"PKGPROOF_ALGORAND_PRIVATE_KEY"},{"description":"0x-prefixed private key of a throwaway EVM wallet holding USDC on Base. Optional, and only used when no Algorand key is configured. Needs no ETH: payment is an off-chain signature and the facilitator pays the gas.","isSecret":true,"name":"PKGPROOF_BASE_PRIVATE_KEY"}]}]},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-14T13:17:41.741959Z","publishedAt":"2026-09-14T13:17:41.741959Z","updatedAt":"2026-09-14T13:17:41.741959Z","isLatest":true}}}
