PluginBench
MCP Server
Active
MIT

io.github.Dave-London/npm MCP Server

io.github.Dave-London/npm

Structured npm/pnpm operations (install, audit, outdated, list) as typed JSON for AI agents.

What is the io.github.Dave-London/npm MCP server?

The npm MCP server is part of Pare, a collection of MCP servers that wrap common developer tools and return clean, schema-validated JSON instead of raw terminal text. It provides structured npm and pnpm operations including install, audit, outdated, and list commands, eliminating fragile CLI output parsing for AI agents.

The npm server wraps npm and pnpm package management commands, returning typed JSON responses instead of raw terminal output. This enables AI agents to reliably parse package operations, vulnerability audits, and dependency information without brittle string parsing, while reducing token usage by up to 83% compared to raw CLI output.

How to install io.github.Dave-London/npm

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "npm": {
      "command": "npx",
      "args": [
        "-y",
        "@paretools/npm"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • install — Install dependencies with structured output
  • audit — Run security audit and return vulnerabilities as typed JSON
  • outdated — List outdated packages in structured format
  • list — List installed packages with metadata as JSON

Use cases

  • Automatically audit npm projects for security vulnerabilities and get structured vulnerability data
  • Check for outdated dependencies and plan upgrade strategies with typed package information
  • Install dependencies and capture structured output for CI/CD pipelines without parsing terminal text
  • List project dependencies programmatically to analyze package trees and identify conflicts
  • Monitor package security and dependency status across multiple projects with consistent JSON responses

io.github.Dave-London/npm MCP server FAQ

What does the npm MCP server do?

It wraps npm and pnpm commands (install, audit, outdated, list) and returns clean, schema-validated JSON instead of raw terminal output. This eliminates parsing fragile CLI text and reduces token usage by up to 83%.

Is it free?

Yes, Pare is open source under the MIT license.

How do I install it in Cursor or Claude?

Run `npx @paretools/init --client claude-code --preset web` (or your client name) to auto-configure MCP servers, then restart your client. See setup guides at https://github.com/Dave-London/Pare/tree/main/docs/setup for detailed instructions per client.

Does it require authentication?

No, it uses your existing npm/pnpm CLI tools and credentials. No additional API keys or authentication needed.

Can I limit which npm tools are available?

Yes, use environment variables to filter tools. For example, `PARE_NPM_TOOLS=install,audit` registers only those tools. Set via the `env` key in your MCP config.

What Node.js version is required?

Node.js >= 20 is required.

README (reference)

Source of truth, from the repository.

<h1><img src="assets/logo.png" alt="" width="80" valign="middle" />&nbsp;&nbsp;Pare</h1>

CI codecov npm Downloads TypeScript License: MIT Node.js >= 20 OpenSSF Scorecard OpenSSF Best Practices

Reliable, structured CLI output for AI agents — no more parsing fragile terminal text.

Pare provides MCP servers that wrap common developer tools (git, npm, docker, test runners, etc.) and return clean, schema-validated JSON instead of raw terminal text. Agents get typed data they can act on directly, without brittle string parsing.

The Problem

Parsing CLI output is fragile. Raw terminal text includes ANSI escape codes, decorative headers, progress bars, locale-specific formatting, and platform differences that break agent workflows in subtle ways. An agent that works fine with git status on macOS may fail on Windows because the output format changed. A test runner's summary line might shift between versions, silently breaking a regex.

Pare eliminates this entire class of errors by returning schema-validated JSON with consistent field names, regardless of platform, tool version, or locale. As a bonus, structured output is significantly smaller — agents use fewer tokens per tool call:

Tool CommandRaw TokensPare TokensReduction
docker build (multi-stage, 11 steps)3732095%
git log --stat (5 commits, verbose)4,99238292%
npm install (487 packages, warnings)2414183%
vitest run (28 tests, all pass)1963980%
cargo build (2 errors, help text)43613868%
pip install (9 packages, progress bars)28810165%
cargo test (12 tests, 2 failures)35119046%
npm audit (4 vulnerabilities)28718536%

Token estimates use ~4 chars/token. The biggest savings appear on verbose commands (builds, installs, tests). For simpler tools like eslint or tsc, the main advantage is reliable structured data — agents can use typed JSON directly rather than parsing strings.

How It Works

Each Pare tool returns two outputs:

  • content — human-readable text, for MCP clients that display it
  • structuredContent — typed, schema-validated JSON, ready for agents to process

This uses MCP's structuredContent and outputSchema features to provide type-safe, validated data that agents can rely on without custom parsing.

Example: git status

Raw git output (~118 tokens):

On branch main
Your branch is ahead of 'origin/main' by 2 commits.
  (use "git push" to publish your local commits)

Changes to be committed:
  (use "git restore --staged <file>..." to unstage)
        modified:   src/index.ts
        new file:   src/utils.ts

Changes not staged for commit:
  (use "git add <file>..." to update what will be committed)
  (use "git restore <file>..." to discard changes in working directory)
        modified:   README.md

Untracked files:
  (use "git add <file>..." to include in what will be committed)
        temp.log

Pare structured output (~59 tokens):

{
  "branch": "main",
  "upstream": "origin/main",
  "ahead": 2,
  "staged": [
    { "file": "src/index.ts", "status": "modified" },
    { "file": "src/utils.ts", "status": "added" }
  ],
  "modified": ["README.md"],
  "deleted": [],
  "untracked": ["temp.log"],
  "conflicts": [],
  "clean": false
}

50% fewer tokens. Zero information lost. Fully typed. Savings scale with output verbosity — test runners and build logs see 80–92% reduction.

Available Servers (28 packages, 240 tools)

Install only the servers relevant to your stack — most projects need just 2–4. The full catalog covers a wide range of ecosystems so Pare works wherever you do.

CategoryServersToolsWraps
Version Controlgit, github55git, gh
Languages & Packagesnpm, python, cargo, go, deno, bun, nix, dotnet, ruby, swift, jvm101npm, pip, cargo, go, deno, bun, nix, dotnet, gem, swift, gradle, maven
Build, Lint & Testbuild, lint, test, cmake, bazel23tsc, esbuild, vite, webpack, eslint, prettier, biome, vitest, pytest, jest
Infrastructuredocker, k8s, infra, security, remote40docker, kubectl, helm, terraform, ansible, trivy, ssh
Utilitiessearch, http, make, process, db21ripgrep, fd, curl, make, just, psql, mysql, redis, mongosh

Tool Schemas — detailed response examples and field descriptions for every tool. See also Tool Response Examples for quick JSON samples.

Quick Setup

# 1. Configure MCP servers (non-interactive)
npx @paretools/init --client claude-code --preset web

# 2. Add agent rules to your project
#    (append to existing CLAUDE.md, or copy if new)
cat node_modules/@paretools/init/rules/CLAUDE.md >> CLAUDE.md

# 3. Restart your client session

# 4. Validate
npx @paretools/init doctor

Available presets: web, python, rust, go, jvm, dotnet, ruby, swift, mobile, devops, full

Setup Guides by Client

Claude CodeClaude DesktopCursor
VS Code / CopilotWindsurfCline / Roo Code
OpenAI CodexGemini CLIZed
Continue.dev

Full Quickstart Guide — presets, ecosystem mapping, validation

Manual Configuration — config paths and formats for all clients

Agent Integration Guide — rule files, hooks, CLI-to-MCP mapping

Configuration

Tool Selection

By default, every Pare server registers all of its tools. If a server exposes tools you don't need — or you want to limit which tools are available to an agent — you can filter them with environment variables.

Per-server filter — restrict a single server's tools:

# Only register status and log in the git server
PARE_GIT_TOOLS=status,log npx @paretools/git

Universal filter — restrict tools across all servers:

# Only register these specific tools across any server
PARE_TOOLS=git:status,git:log,npm:install npx @paretools/git

Disable all tools — set the env var to an empty string:

PARE_GIT_TOOLS= npx @paretools/git   # no tools registered
Env VarScopeFormatExample
PARE_TOOLSAll serversserver:tool,...git:status,npm:install
PARE_{SERVER}_TOOLSOne servertool,...status,log,diff

Rules:

  • No env var = all tools enabled (default)
  • PARE_TOOLS (universal) takes precedence over per-server vars
  • Server names use uppercase with hyphens replaced by underscores (e.g., PARE_MY_SERVER_TOOLS)
  • Whitespace around commas is ignored

Common patterns:

# Read-only git (no push, commit, add, checkout)
PARE_GIT_TOOLS=status,log,diff,branch,show

# Minimal npm
PARE_NPM_TOOLS=install,test,run

# Only specific tools across all servers
PARE_TOOLS=git:status,git:diff,npm:install,test:run

In JSON MCP config, set via the env key:

{
  "mcpServers": {
    "pare-git": {
      "command": "npx",
      "args": ["-y", "@paretools/git"],
      "env": {
        "PARE_GIT_TOOLS": "status,log,diff,show"
      }
    }
  }
}

Troubleshooting

IssueSolution
npx not found / ENOENT on WindowsUse cmd /c npx wrapper (see your client's setup guide)
Slow first startRun npx -y @paretools/git once to cache, or install globally: npm i -g @paretools/git
Node.js version errorPare requires Node.js >= 20
NVM/fnm PATH issuesUse absolute path to npx: e.g., ~/.nvm/versions/node/v22/bin/npx
MCP connection timeoutSet MCP_TIMEOUT=30000 for Claude Code, or increase initTimeout in client config
Too many tools filling contextUse tool selection env vars to limit tools, or only install the servers you need

Contributing

Each server is a self-contained package. See CONTRIBUTING.md for the full guide.

License

MIT

Related MCP servers

Structured build output (tsc, esbuild, vite, webpack) as typed JSON diagnostics for AI agents.

130
TypeScript
MIT
View repository →

Structured Rust cargo operations (build, test, clippy, fmt, doc) as typed JSON for AI agents.

130
TypeScript
MIT
View repository →

Structured Docker operations (ps, images, logs, build, compose) as typed JSON for AI agents.

130
TypeScript
MIT
View repository →

Structured git operations (status, log, diff, branch, commit, push) as typed JSON for AI agents.

130
TypeScript
MIT
View repository →

Structured GitHub operations (PRs, issues, actions) as typed JSON for AI agents.

130
TypeScript
MIT
View repository →

Structured Go tool output (build, test, vet, fmt, mod) as typed JSON diagnostics for AI agents.

130
TypeScript
MIT
View repository →