NPMScan
npm package & vuln lookups
- Category
- Pending
- Primary Subcategory
- Pending
Integration details
Description
Look up npm package metadata and known vulnerabilities directly from a conversation. NPMScan's MCP server gives AI agents six read-only tools backed by the npm registry, OSV.dev, and GitHub Security Advisories: search packages, inspect install scripts and maintainers before installing, check an exact version pinned in a lockfile, query vulnerabilities for one package or up to 100 at once (a full package.json/lockfile scan), and browse the latest reviewed advisories for the npm ecosystem. No API key or authentication is required, and every result links back to the full write-up on npmscan.com.
- Integration type
- Plugin
- Verification status
- Not applicable
- Platform
- ChatGPT
- Category
- Pending
- Primary Subcategory
- Pending
- Secondary Subcategories
- None listed
- Brand
- Unknown
- Access
- No account required
- First tracked
- 2026-09-01
- Tool count
- 6
- Geography
- US
The broad Category that contains the Primary Subcategory.
The Primary Subcategory used for this profile’s headline score.
Other Subcategories where the Integration is listed.
ChatGPT Plugin Discovery Score
ChatGPT Plugin discovery is coming soon
ChatGPT can surface a Plugin when it matches a user's request.Your Plugin Discovery Score measures how often yours appears.
No spam. Unsubscribe any time.
What discovery looks like

Competitive lineup
6 tools agents can invoke
How do I improve a ChatGPT Plugin's discoverability?
The levers are the listing surface agents actually read: names, descriptions, keywords, tool metadata, and registry health. Which lever matters depends on where discovery breaks, which is what continuous measurement shows.
Where is this profile measured?
This profile uses the geography attached to the latest public registry snapshot: US. Locale tags are intentionally omitted.