
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@aimodelwatch/mcp
Advanced tools
MCP server for AI Model Watch — query 250+ AI/LLM models with prices, lifecycle status, and deprecation data
MCP server for AI Model Watch — query 250+ AI/LLM models with prices, context windows, lifecycle status, and deprecation data, directly from any MCP-capable agent (Claude, Cursor, Windsurf, etc.).
Data is fetched from the public API at aimodelwatch.dev/api and cached in memory for
1 hour. No API key required.
npm install -g @aimodelwatch/mcp
Or run directly:
npx @aimodelwatch/mcp
Add to your MCP config (claude_desktop_config.json or .claude.json):
{
"mcpServers": {
"aimodelwatch": {
"command": "npx",
"args": ["-y", "@aimodelwatch/mcp"]
}
}
}
Add to .cursor/mcp.json:
{
"mcpServers": {
"aimodelwatch": {
"command": "npx",
"args": ["-y", "@aimodelwatch/mcp"]
}
}
}
| Tool | Description |
|---|---|
list_models | List all models with optional filters: provider, status, modality |
get_model | Full details for a model by id or api_string |
search_models | Free-text search across names, providers, and notes |
compare_models | Side-by-side comparison of 2-4 models |
cheapest_models | Find the N cheapest models by blended price |
list_deprecations | Upcoming/past deprecations, filterable by provider or date range |
check_model_status | Check if a model is deprecated/retiring and get its replacement |
Ask your AI agent:
All data comes from AI Model Watch, a daily-verified,
first-party-sourced catalog. Every model row carries the official source_url it was
read from. The data is MIT-licensed.
MIT
FAQs
MCP server for AI Model Watch — prices, context windows, lifecycle status and deprecation dates for 270+ AI/LLM models, from official provider pages, refreshed daily. Read-only, no key.
The npm package @aimodelwatch/mcp receives a total of 34 weekly downloads. As such, @aimodelwatch/mcp popularity was classified as not popular.
We found that @aimodelwatch/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.