npm Package Intelligence
LiveCompare dependencies before adding them to a project.
Inspect public npm packages without installing them. Compare latest versions, licenses, repositories, runtime requirements, dependency lists, maintainer names, package sizes and last-week downloads from npm’s public APIs.
Connect / 2 tools
Server URL
https://toolcargo.com/mcp/npm-packagesClaude Code
claude mcp add --transport http --scope user toolcargo-npm-packages https://toolcargo.com/mcp/npm-packages \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Current package metadata with source links
- Side-by-side comparison of 2–5 packages
- Explicitly unavailable download statistics when npm cannot supply them
Built for: Developers and AI coding agents choosing dependencies or reviewing a project’s stack.
Example requests
Choose a validation library
“Use ToolCargo to compare zod and valibot: versions, licenses, dependencies and last-week downloads.”
Registry facts for both packages, without installing or running code.
Tools
| Tool | What it does | Access |
|---|---|---|
package_detailsInspect an npm package | Inspect a public npm package’s latest version, license, repository, runtime requirements, dependencies, maintainer names and optional last-week downloads. No install or code execution. One shared-plan call. | Read-only |
compare_packagesCompare npm packages | Compare 2–5 public npm packages using current registry metadata and optional last-week download counts. Not a vulnerability audit or a safety guarantee. One shared-plan call. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free). No npm token or external API key.
Limitations
- • Public npm packages only; latest-version metadata, not every historical release.
- • Download counts do not measure quality or security. Optional download statistics may be unavailable.
- • No installation, vulnerability audit, code execution or package safety certification. Published metadata is untrusted data.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.
| Claude Code | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Claude (claude.ai) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Cursor | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| MCP Inspector | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
Practical workflows
More in Developer tools
- Hugging Face Hub Research LiveFind models and datasets, then review their public metadata.
- OSV Vulnerability Lookup LiveCheck package versions against public vulnerability advisories.
- PyPI Package Intelligence LiveCompare Python packages before choosing a dependency.
- Rust Crate Research LiveFind Rust crates and inspect releases, features and dependencies.
Pricing
Included with Site Audit. Each package lookup or comparison is one shared-plan call.
Free
$0Try hosted tools with a shared monthly allowance.
50 shared calls/month
Pro
$12/moProposed larger shared allowance; see checkout status on the pricing page.
2,000 shared calls/month
Proposed test price. See the pricing page for checkout status.