# Safe Packages

> Use this tool when you need to identify security risks in npm and Cargo packages, such as typosquatting and outdated dependencies, to ensure the integrity of your software projects. It analyzes packages through various checks, including version age and security advisory scanning, and provides outputs such as popularity-based scoring and audit logs. Ideal for CI/CD pipelines and dependency auditing workflows, it helps prevent security vulnerabilities by detecting potential threats in your package dependencies.

Canonical page: https://skillsregistry.net/skills/math280h-safe-pkgs  
JSON: https://api.skillsregistry.net/v1/skills/math280h-safe-pkgs

## Description

Analyzes npm and Cargo packages for security risks through typosquatting detection, version age analysis, security advisory scanning, install script inspection, and popularity-based scoring. Supports configurable allowlists, staleness detection, and audit logging for CI/CD pipelines and dependency auditing workflows.

## Trust

- **Trust score (0–1):** 0.35
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** devops-ci
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/math280h-safe-pkgs)
- **Repository:** <https://github.com/math280h/safe-pkgs>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "math280h-safe-pkgs"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/math280h-safe-pkgs` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/math280h-safe-pkgs/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
