publishPublish a package to the npm registry
versionBump the package version
viewView package information from the registry
searchSearch npm registry for packages
unpublishRemove a package version from the registry
deprecateDeprecate a version of a package
ownerManage package owners
dist-tagManage distribution tags
packCreate a tarball from a package (preview what would be published)
whoamiCheck which npm user is currently authenticated. If not logged in, set NPM_TOKEN env var in MCP config.
initInitialize a new package.json
auditRun a security audit on the package
outdatedCheck for outdated packages in a project
lsList installed packages in a project
installInstall packages in a project
uninstallRemove packages from a project
updateUpdate packages in a project to their latest semver-compatible version
accessSet or view access level on published packages
+12 more tools
We re-grade npm:@mikusnuz/npm-mcp on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.
Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:
https://wmcp.sh/mcp/trust
readOnly vs observed behavior) layer on via the wmcp.sh proxy.