package_install_preflight

shallow

tech.vrsai/mcp · Verify this server

Call immediately before installing or adding an exact third-party npm or PyPI package version. Checks current registry, known vulnerability/malicious-package, publisher withdrawal/deprecation, and verified provenance evidence and returns ALLOW, REVIEW, BLOCK, or UNKNOWN with machine-readable reasons. It accepts only an ECMA-427 Package URL with one exact published version; ranges, dist-tags, Git dependencies, archives, local packages, container images, other ecosystems, dependency graphs, repositories, SBOMs, and source-code or malware analysis are outside this version. It does not install, download, extract, clone, execute, or recommend a package version, and ALLOW never claims that a package is safe. Paid invocation: 10000 micro-USD per successful execution.

100.0/100

1 trials · measured 2 days ago

package_install_preflight scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against tech.vrsai/mcp, measured 31 Aug 2026 under methodology v0.2.0. Every measured component scored 100.

Component breakdown

ComponentWeightValue
Reliability35%not applicable
Schema integrity25%100.0
Failure behaviour15%not applicable
Latency15%not applicable
Concurrency10%not applicable

Tool details

Transport
remote
Credential class
self-provisionable
Input schema
not declared
Output schema
not declared
Side-effect classification
unclassified

Score history

DayScoreTierMethodology
2026-08-31100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: package_install_preflight
[![Vouch score](https://vouch.tools/api/tools/cbf99dd5-25a9-443f-86cc-313c26e6a623/badge.svg)](https://vouch.tools/tools/cbf99dd5-25a9-443f-86cc-313c26e6a623)
package_install_preflight — Vouch