# Package Privacy

> Use this tool when you need to automate security assessments for software dependencies and detect privacy violations in your software supply chain. It analyzes Maven packages through decompilation and rule-based detection, providing comprehensive reports on potential risks. Ideal for security auditing workflows, it integrates with Maven repositories and utilizes JSON-based rules for customizable privacy risk assessment.

Canonical page: https://skillsregistry.net/skills/stonehill-2345-package-privacy  
JSON: https://api.skillsregistry.net/v1/skills/stonehill-2345-package-privacy

## Description

Package Privacy is an MCP server that provides automated security assessment capabilities for software dependencies through Maven package downloading, decompilation analysis, and rule-based privacy violation detection. It integrates with Maven repositories for dependency resolution and uses JADX for reverse engineering compiled code. The implementation includes configurable JSON-based rules for detecting privacy violations and comprehensive reporting of analysis results, designed for security auditing workflows and automated privacy risk assessment in software supply chains.

## Trust

- **Trust score (0–1):** 0.65
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** data-analytics
- **Updated:** 2026-05-05

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/stonehill-2345-package-privacy)
- **Repository:** <https://github.com/stonehill-2345/package-privacy/tree/HEAD/mcp_server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "stonehill-2345-package-privacy"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/stonehill-2345-package-privacy` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/stonehill-2345-package-privacy/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
