Safeinstall is a Model Context Protocol (MCP) server: Local-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks. As an MCP server it plugs straight into AI assistants, exposing its functionality as tools the model can invoke on your behalf.
It runs locally: the npm package safeinstall-cli speaks MCP over stdio on your machine. No credentials are required — it works out of the box. The current release is v0.12.0, published under the MIT license, with source at Mickdownunder/SafeInstall on GitHub.
You'll find Safeinstall in the Security category here on mcp.site; it connects to Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, Zed, and any other MCP client — see the install snippets below. If you maintain Safeinstall for Mickdownunder, claim this listing to verify ownership, earn the Verified badge, and keep the details current.
▸npm package — safeinstall-cli · MCP over stdio
▸Open source — MIT license · Mickdownunder/SafeInstall