npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

correctover-scan

v1.7.3

Published

Correctover Security Scanner — CCS audit for MCP configurations AND published JS bundles/npm packages. Detects hardcoded secrets, RCE, SSRF, credential hijacking against OWASP AISVS 1.0.

Readme

correctover-scan

Rekor anchored

Security scanner for MCP servers and AI agents — detects credential exposure, SSRF, command injection risk and missing auth across your MCP configuration. 14 checks mapped to OWASP AISVS 1.0. Run anywhere with npx correctover-scan.

npm license IETF Internet-Draft


Verifiable artifacts behind this tool

correctover-scan audits the MCP (Model Context Protocol) configuration files used by Claude Code, Claude Desktop, Cursor, VS Code and other AI agent tools. It scans for credential leaks, SSRF exposure, missing transport encryption, over-broad tool permissions and more — 14 security checks covering the issues that turn MCP integrations into RCE, data exfiltration and prompt-injection paths. Zero install: npx correctover-scan runs locally, works in CI, and outputs SARIF for GitHub code scanning.

v1.4.0 adds a second mode: --bundle code-layer signal scanning for published npm packages and bundled/minified JavaScript — 17 checks over shipped code, with file+line findings, minified-code reformatting and context-based false-positive suppression.

⚡ Quick Start — running in 30 seconds

Zero config, no account, no sign-up — scan the current directory for MCP configuration issues:

npx correctover-scan@latest

It auto-detects MCP config files (.cursor/mcp.json, claude_desktop_config.json, .claude/mcp.json, mcp.json, .vscode/mcp.json and more) and runs 14 checks. Everything runs locally on your machine — config files are not uploaded.

# Scan a specific config file
npx correctover-scan mcp.json

# Recursively scan a project directory
npx correctover-scan -d ./my-project -r

# SARIF output for GitHub code scanning
npx correctover-scan mcp.json -f sarif > report.sarif

What It Checks

| # | Check | Severity | AISVS | |---|-------|----------|-------| | 1 | TLS Transport Encryption | 🔴 Critical | C10.1 | | 2 | Server Authentication | 🟠 High | C10.2 | | 3 | Timeout Configuration | 🟡 Medium | C9.1 | | 4 | Credential Exposure | 🔴 Critical | C5.1 | | 5 | Tool Allowlist | 🟠 High | C9.3 | | 6 | Token Budget Control | 🟠 High | C9.1 | | 7 | SSRF Protection | 🔴 Critical | C10.3 | | 8 | Audit Logging | 🟡 Medium | C12.1 | | 9 | Sandbox Isolation | 🟡 Medium | C4.1 | | 10 | Dependency Version Pinning | 🟡 Medium | C6.1 | | 11 | Error Handling Strategy | 🟡 Medium | C12.2 | | 12 | Input Validation | 🟠 High | C2.1 | | 13 | Output Validation | 🟡 Medium | C7.1 | | 14 | Kill Switch | 🟠 High | C9.5 |

Output Formats

# Terminal (default)
correctover-scan mcp.json

# JSON
correctover-scan mcp.json -f json

# SARIF (for CI integration)
correctover-scan mcp.json -f sarif > report.sarif

Supported Config Files

Auto-detects these files:

  • .cursor/mcp.json
  • claude_desktop_config.json
  • .claude/mcp.json
  • mcp.json / mcp.yaml / mcp.yml
  • .vscode/mcp.json
  • .mcp/mcp.json
  • config/mcp.json

📦 Bundle / published-package code scan (v1.4.0)

Usage

# Audit an unpacked npm package: reads package.json entry (main/module/bin)
# and every .js/.mjs/.cjs/.ts file in the tree (node_modules skipped)
npx correctover-scan@latest --bundle ./node_modules/some-pkg
npx correctover-scan@latest -b ./pkg                      # -b is shorthand for --bundle

# Audit a single minified/bundled JS file
npx correctover-scan@latest --bundle dist/app.min.js

# A positional .js/.mjs/.cjs/.ts target auto-selects bundle mode
npx correctover-scan@latest ./cli.js

# Outputs: text (default), JSON, or SARIF with file+line locations
npx correctover-scan@latest -b ./pkg -f json
npx correctover-scan@latest -b ./pkg -f sarif > bundle.sarif
npx correctover-scan@latest -b ./pkg -o report.txt        # write the report to a file
npx correctover-scan@latest -b ./pkg -f json -o bundle.json

Exit code is 1 when any check produces a fail-level finding — drop the command straight into CI.

What bundle mode is — and what it is not

Bundle mode is signal scanning over shipped/minified code. Minifiers rename local variables, but property names, string literals, URLs, environment-variable names and error messages survive bundling — so the attack-surface signals the checks rely on are still present in the published artifact.

  • 12 automatic checks return a verdict (pass / warn / fail) — hardcoded secrets, cloud-metadata/SSRF, shell:true/exec subprocess calls, dynamic eval/Function/vm, plaintext endpoints, MCP transport auth, permission gates, missing timeouts/kill-switch/input validation, env-credential flow, sandbox signals.
  • 5 semi-automatic checks (token budget, audit logging/telemetry, supply-chain/SBOM, error handling/retry, output truncation/filtering) enumerate the signals they find in shipped code — the signal's presence is verifiable, but whether the control is actually enforced needs human review. Those signals are listed in the JSON output and never counted as fails.
  • Every finding is grounded at file + line with a code snippet. Minified files are detected and lightly reformatted internally (statement/block expansion, no dependencies) so line numbers stay usable; already-formatted source is scanned untouched.
  • Known-benign patterns are suppressed with context heuristics and reported as info — for example cloud-SDK metadata credential providers (AWS IMDS / GCP metadata), shell:false fixed-argument spawn calls, sandbox VM implementations, localhost/spec-namespace URLs and placeholder/example strings.

Honest scope: bundle mode does not prove reachability or intent — a signal that is located correctly may still be unreachable in practice, and conclusions on the semi-automatic checks remain a manual-review job. It is an automated triage layer that points a reviewer at the exact lines to examine; it does not replace the 116-check manual audit methodology, where reviewers trace data flow and what each capability can actually be made to do. Scanning covers JavaScript/TypeScript code, configuration and protocol-layer signals; deep logic compiled into native binaries (e.g. Bun --compile single-file executables) is outside static analysis and is not covered by bundle mode. Everything runs locally — package code is not uploaded.

Bundle checks (17)

Check ids continue the config scanner's 14-check scheme so text/JSON/SARIF outputs stay aligned.

| # | Check | Type | Severity | AISVS | |---|-------|------|----------|-------| | 1 | Hardcoded credentials in code (sk-/ghp_/AKIA/AIza/xox patterns, placeholder-aware) | automatic | 🔴 Critical | C5.1 | | 2 | Plaintext HTTP outbound endpoints (localhost/spec/example hosts suppressed) | automatic | 🟠 High | C10.1 | | 3 | Cloud metadata & intranet addresses / SSRF (169.254.x, RFC1918, GCP metadata; cloud-SDK & guard context suppressed) | automatic | 🔴 Critical | C10.3 | | 4 | Subprocess execution — shell:true / exec (shell:false fixed-arg spawn not flagged) | automatic | 🟠 High | C4.1 | | 5 | Dynamic code execution — eval / new Function / vm (sandbox/shim contexts suppressed) | automatic | 🟠 High | C4.1 | | 6 | Environment-variable credential flow (hardcoded fallback secrets flagged) | automatic | 🟡 Medium | C5.1 | | 7 | Permission modes & tool gates (allowedTools, dangerouslySkipPermissions) | automatic | 🟠 High | C9.3 | | 8 | MCP transport authentication (remote sse/http/ws without Authorization signal) | automatic | 🟠 High | C10.2 | | 9 | Timeout & interruption signals (AbortSignal.timeout / timeout options) | automatic | 🟡 Medium | C9.1 | | 10 | Kill switch — AbortController / AbortSignal presence | automatic | 🟠 High | C9.5 | | 11 | Sandbox isolation signals (bwrap / sandbox manager) | automatic | 🟡 Medium | C4.1 | | 12 | Input validation / schema signals | automatic | 🟠 High | C2.1 | | 13 | Token budget constants (MAX_*_TOKENS / cost limits) | semi-automatic | 🟠 High | C9.1 | | 14 | Audit logging / telemetry endpoints | semi-automatic | 🟡 Medium | C12.1 | | 15 | Supply chain / vendor SBOM (native artifacts, vendor versions) | semi-automatic | 🟡 Medium | C6.1 | | 16 | Error handling / retry / fallback | semi-automatic | 🟡 Medium | C12.2 | | 17 | Output truncation / filtering | semi-automatic | 🟡 Medium | C7.1 |

The free-tier daily scan allowance applies to bundle scans too (counted the same way as config scans); a Pro license removes the limit. License verification runs sub-millisecond on the core verification hot path.

CI/CD Integration

GitHub Actions

- uses: DSHCorrectover/correctover-scan-action@v1
  with:
    path: ./mcp.json

Web Scanner

Try the no-install browser version (files never leave your machine): in-browser scanner

Standards Compliance

  • OWASP AISVS 1.0 — AI System Vulnerability Severity
  • GB/T《智能体应用安全基本要求》 — Chinese National Mandatory Standard

Manual audit

The free automated scan covers surface-level configuration checks. A manual Correctover audit goes deeper:

  • 116-check manual audit methodology — reviewers trace what each MCP tool can actually be made to do, not just whether a config field is present
  • Findings grounded in real MCP ecosystem CVEs
  • 5-day turnaround, delivered as a PDF report with recommended fixes
  • A free 1-page summary of your configuration first — you decide whether to continue after reading it

For first customers, if the manual audit finds no critical-severity issue, you pay nothing.

  • Get your free 1-page summary: email [email protected]
  • Learn more about the manual audit: https://correctover.com/agent-audit.html

Links

Specification

CCS (Correctover Conformance Shape) is published as an individual Internet-Draft: draft-correctover-ccs.

An Internet-Draft is an individual submission. It is not an RFC, an adopted working-group item, or IETF endorsement; the Datatracker page is authoritative for revision and status.

License & scope

MIT © Correctover.

This CLI is a free, open-source lead-generation tool (MIT-licensed): use it in your terminal, CI, and agent hooks (such as the Kimi Code security hook), fork it, and redistribute it under the MIT terms. External pull requests are welcome.

The commercial products — the hosted zero-upload scan platform, the CCS runtime verification engine, and the manual Agent Output Audit service — are proprietary and are not part of this open-source release. See correctover.com for those.