pkgtruth
Rank #5,443io.github.hxckya/pkgtruth
Catches hallucinated and slopsquatted npm and PyPI packages before an agent installs them.
pkgtruth is a Model Context Protocol (MCP) server published by hxckya. It ranks #5,443 of 137,492 servers tracked on MCP Toplist, and its repository has 4 GitHub stars. pkgtruth is listed across 2 registries — Official MCP and Glama, with 5 tracked versions. It was first listed on Aug 31, 2026 and most recently updated on Sep 10, 2026.
Ranks ahead of 132,049 of 137,492 servers on MCP Toplist.
Use pkgtruth
No credentials or required configuration declared — add it to your MCP client and go.
claude mcp add pkgtruth -e "PKGTRUTH_REGISTRY=<your PKGTRUTH_REGISTRY>" -e "PKGTRUTH_DOWNLOADS_API=<your PKGTRUTH_DOWNLOADS_API>" -e "PKGTRUTH_CACHE_DIR=<your PKGTRUTH_CACHE_DIR>" -e "PKGTRUTH_TIMEOUT_MS=<your PKGTRUTH_TIMEOUT_MS>" -- npx -y pkgtruthReplace each placeholder with your own value before saving.
[mcp_servers.pkgtruth]
command = "npx"
args = ["-y", "pkgtruth"]
[mcp_servers.pkgtruth.env]
PKGTRUTH_REGISTRY = "<your PKGTRUTH_REGISTRY>"
PKGTRUTH_DOWNLOADS_API = "<your PKGTRUTH_DOWNLOADS_API>"
PKGTRUTH_CACHE_DIR = "<your PKGTRUTH_CACHE_DIR>"
PKGTRUTH_TIMEOUT_MS = "<your PKGTRUTH_TIMEOUT_MS>"Add to ~/.codex/config.toml. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
],
"env": {
"PKGTRUTH_REGISTRY": "<your PKGTRUTH_REGISTRY>",
"PKGTRUTH_DOWNLOADS_API": "<your PKGTRUTH_DOWNLOADS_API>",
"PKGTRUTH_CACHE_DIR": "<your PKGTRUTH_CACHE_DIR>",
"PKGTRUTH_TIMEOUT_MS": "<your PKGTRUTH_TIMEOUT_MS>"
}
}
}
}Add to claude_desktop_config.json (Settings → Developer → Edit Config). Replace each placeholder with your own value before saving.
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
],
"env": {
"PKGTRUTH_REGISTRY": "<your PKGTRUTH_REGISTRY>",
"PKGTRUTH_DOWNLOADS_API": "<your PKGTRUTH_DOWNLOADS_API>",
"PKGTRUTH_CACHE_DIR": "<your PKGTRUTH_CACHE_DIR>",
"PKGTRUTH_TIMEOUT_MS": "<your PKGTRUTH_TIMEOUT_MS>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project). Replace each placeholder with your own value before saving.
{
"servers": {
"pkgtruth": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"pkgtruth"
],
"env": {
"PKGTRUTH_REGISTRY": "<your PKGTRUTH_REGISTRY>",
"PKGTRUTH_DOWNLOADS_API": "<your PKGTRUTH_DOWNLOADS_API>",
"PKGTRUTH_CACHE_DIR": "<your PKGTRUTH_CACHE_DIR>",
"PKGTRUTH_TIMEOUT_MS": "<your PKGTRUTH_TIMEOUT_MS>"
}
}
}
}Save as .vscode/mcp.json in your workspace. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
],
"env": {
"PKGTRUTH_REGISTRY": "<your PKGTRUTH_REGISTRY>",
"PKGTRUTH_DOWNLOADS_API": "<your PKGTRUTH_DOWNLOADS_API>",
"PKGTRUTH_CACHE_DIR": "<your PKGTRUTH_CACHE_DIR>",
"PKGTRUTH_TIMEOUT_MS": "<your PKGTRUTH_TIMEOUT_MS>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json. Replace each placeholder with your own value before saving.
{
"mcpServers": {
"pkgtruth": {
"command": "npx",
"args": [
"-y",
"pkgtruth"
],
"env": {
"PKGTRUTH_REGISTRY": "<your PKGTRUTH_REGISTRY>",
"PKGTRUTH_DOWNLOADS_API": "<your PKGTRUTH_DOWNLOADS_API>",
"PKGTRUTH_CACHE_DIR": "<your PKGTRUTH_CACHE_DIR>",
"PKGTRUTH_TIMEOUT_MS": "<your PKGTRUTH_TIMEOUT_MS>"
}
}
}
}Replace each placeholder with your own value before saving.
Show your rank
Maintain this server? Add the live rank badge to your README — it updates automatically as the leaderboard changes.
[](https://mcptoplist.com/server/io.github.hxckya%2Fpkgtruth)<a href="https://mcptoplist.com/server/io.github.hxckya%2Fpkgtruth"><img src="https://mcptoplist.com/badge/io.github.hxckya%2Fpkgtruth.svg" alt="MCP Toplist: Top 5% of 137,492" /></a>Variants: append ?metric=score or ?metric=stars to the image URL.
Listed on 2 registries
hxckya
Available versions (5)
| Version | Published |
|---|---|
| 0.2.2 | Sep 10, 2026 |
| 0.2.1 | Sep 10, 2026 |
| 0.2.0 | Sep 10, 2026 |
| 0.1.3 | Sep 10, 2026 |
| 0.1.2 | Aug 31, 2026 |
Frequently asked questions
- Who maintains pkgtruth?
- pkgtruth is maintained by hxckya, which publishes 1 MCP server (5 total versions) tracked on MCP Toplist.
- Is pkgtruth listed on the Official MCP Registry?
- Yes — pkgtruth is listed on the Official MCP Registry, alongside Glama.
- How many versions does pkgtruth have?
- MCP Toplist tracks 5 versions of pkgtruth, most recently published on Sep 10, 2026.
- Where can I find the source code for pkgtruth?
- The source code for pkgtruth is hosted at github.com/hxckya/pkgtruth.
Do you run this server?
Community projects list the MCP servers behind real agents and apps. Publish yours and this page will link to it.