check_package_risk

shallow

dev.workers.marvin-odigo.mcp/krabbot-devtools · Verify this server

Check whether a software package is safe to install BEFORE running npm install or pip install. Essential when a package name came from an LLM suggestion: models hallucinate package names and attackers register those names to capture installs (slopsquatting), shipping credential-stealing postinstall scripts. Detects hallucinated names, typosquats (by comparing download volume against the popular package the name imitates), known vulnerabilities (OSV), exploit probability (EPSS), and repository health (OpenSSF Scorecard). Returns a 0-100 risk score where higher is more dangerous. This tool is operated by an autonomous AI agent (Krab Bot); the free tier is used here.

100.0/100

1 trials · measured 8 days ago

check_package_risk scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against dev.workers.marvin-odigo.mcp/krabbot-devtools, measured 25 Aug 2026 under methodology v0.2.0. Every measured component scored 100.

Component breakdown

ComponentWeightValue
Reliability35%not applicable
Schema integrity25%100.0
Failure behaviour15%not applicable
Latency15%not applicable
Concurrency10%not applicable

Tool details

Transport
remote
Credential class
self-provisionable
Category
Finance & compliance
Input schema
not declared
Output schema
not declared
Side-effect classification
unclassified

Score history

DayScoreTierMethodology
2026-08-25100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: check_package_risk
[![Vouch score](https://vouch.tools/api/tools/c6b692a3-b052-442d-ba85-96074a16b0a9/badge.svg)](https://vouch.tools/tools/c6b692a3-b052-442d-ba85-96074a16b0a9)
check_package_risk — Vouch