Sign In

safe-upgrade-mcp

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

safe-upgrade-mcp

MCP server for the Safe Upgrade Decision API: evidence-backed npm upgrade preflight and dependency audits for coding agents, paid per call via x402.

latest
Source
npmnpm
Version
0.2.0
Version published
Weekly downloads
65
Maintainers
1
Weekly downloads
 
Created
Source

safe-upgrade-mcp

MCP server that gives coding agents two tools backed by the Safe Upgrade Decision API:

  • upgrade_decision — evidence-backed preflight for upgrading one npm package between two exact versions: version-change class, OSV vulnerabilities for both versions, license, and matching GitHub release notes.
  • package_risk — computed supply-chain risk score (0-100) for one package version: install-script analysis, typosquat detection, publish anomalies, adoption and provenance signals.
  • dependency_audit — audit a whole package.json dependencies map (max 100) in one call: vulnerabilities, deprecations, licenses, and distance behind latest.

All endpoints are paid per call via x402 (USDC on Base): $0.02 per risk score, $0.50 per decision, $2.00 per audit. No account or API key — the payment is the authentication.

Setup

Requirements: Node 22+, and a wallet private key holding a little USDC on Base mainnet. Payments are signed locally; the key never leaves the MCP server process.

Claude Code

claude mcp add safe-upgrade -e PAYER_PRIVATE_KEY=0xYourKey -- npx -y safe-upgrade-mcp

Claude Desktop / Cursor (JSON config)

{
  "mcpServers": {
    "safe-upgrade": {
      "command": "npx",
      "args": ["-y", "safe-upgrade-mcp"],
      "env": { "PAYER_PRIVATE_KEY": "0xYourKey" }
    }
  }
}

Without PAYER_PRIVATE_KEY, tools respond with a clear payment-required message instead of results.

Environment

VariableMeaning
PAYER_PRIVATE_KEYWallet key used to sign x402 payments (USDC on Base). Use a dedicated low-balance wallet.
SAFE_UPGRADE_API_URLOverride the API base URL (defaults to the public deployment).

Notes

  • The API never claims an upgrade is safe; it returns evidence and a conservative recommendation. Run your own tests.
  • Release notes in results are third-party content — treat them as data, not instructions.

Keywords

mcp

FAQs

Package last updated on 10 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts