Custody check for your MCP list

A dated record of who can publish, where the source lives and what runs at install time — for the MCP servers and packages you host, list, proxy or depend on. · Home · Live drift feed · Contact

A lockfile pin or a past security scan answers “are these the bytes we approved?”. It does not show who can publish the next version, where the declared source now lives, or what started running at install time. Those change without notice to the people who depend on the package.

Sample: the 1,000 most-downloaded MCP packages on npm

Window 2 September – 2 October 2026. The list is the 1,000 MCP packages with the most weekly npm downloads in our population (cut-off: 681 downloads a week). Counts are lower bounds: a package not audited every night can miss a change.

Change in 30 daysCount
Packages with at least one change below69 of 1,000
npm maintainer list changed (accounts added or removed)56 changes
Declared repository now points to a different GitHub owner10
Repository link removed from the package5
Install-time script added (preinstall / install / postinstall)6
Build provenance attestation lost1

Three findings, with evidence

1. peertable — an install-time script appeared. Version 0.8.56, published 9 September 2026 at 22:44 UTC, added "postinstall": "node skill/scripts/install-skill.mjs --postinstall". Earlier versions had no install-time script; a postinstall runs on npm install unless scripts are disabled. Action: review the script before upgrading past 0.8.55.
2. local-mcp — the declared source moved twice, and the earlier sources are gone. The repository field changed from github.com/lanchuske/local-mcp to github.com/colibird-ai/local-mcp in 3.0.381 (6 September), then to github.com/lanchuske/local-mcp-releases in 3.0.414 (28 September), which now redirects to colibird-ai/local-mcp-releases. Both earlier URLs return 404, so the source the earlier versions declared can no longer be reviewed. The npm maintainer is unchanged. Action: re-pin provenance to the current repository and review it.
3. @modelcontextprotocol/sdk — the maintainer list changed. On 18 September one npm maintainer was removed; five are listed today. The same change reached eight other @modelcontextprotocol packages in the same daily run — an organisation-level rotation, most likely routine. The point: the list of accounts that can publish the next version changed, and a lockfile does not record that.

None of these is evidence of compromise. Each is a reason to re-check something that was trusted before.

What you receive

Coverage. npm release history lets us reconstruct repository, install-script and publisher changes for any npm package back to its first version. Changes between releases — maintainer sets, repository deletions, registry delistings — come from our nightly audits. We track about 4,800 npm MCP packages (since 30 July 2026; maintainer lists since 10 August); about 1,800 of them, ranked by npm search, are re-audited every night (on 2 October that included 826 of the 1,000 most-downloaded), the rest less often. The whole official MCP registry (about 38,000 entries) is diffed every night since 23 August 2026. Each day's dataset manifest is signed (Ed25519) and timestamped into Bitcoin with OpenTimestamps, so anyone can verify that a day's record existed on that day. For packages audited nightly, detection resolution is one day.

Price

Custody check, up to 100 entries$1,000
Custody check, up to 500 entries$2,000
Daily monitoring after a check, up to 100 entries$300 / month
Data pilot for security teams and registries, 90 days: the full history to date plus daily JSON or CSV deliveries for the agreed scope, documented schema$2,500

50% on order, 50% on delivery, by invoice; payment in USDC, other methods by arrangement. Acceptance is coverage of the agreed list — we do not promise a number of findings.

Try it free: email any 20 entries from your list (npm names or repository URLs) to nikolife2016@gmail.com and get the report for them within two business days, free. To order the full check, send the whole list: you get a quote and a delivery date by reply.

PulseFeed — independent monitoring of MCP and x402 supply chains. Operator: Nikolai Otrishko. Methodology and the public research dataset behind these checks: doi:10.5281/zenodo.23000491; daily anchors: /anchors/latest.json.