Software Supply Chain / Packages data for AI agents
Open-source package and dependency intelligence: npm, PyPI, and crates.io metadata plus GitHub repository health. Pair with the CVE tools to vet a dependency. Where the upstream source provides it, the response includes a timestamp or freshness note.
Get a free key → See all 4 tools
How to connect
These Software Supply Chain / Packages tools use the same LiveDataLink endpoint as the rest of the catalog. Add it to an MCP client that supports Streamable HTTP and include your bearer key. Each source has its own coverage, update schedule, and credential requirements; those limits are listed in the catalog and response notes.
{
"mcpServers": {
"livedatalink": {
"url": "https://livedatalink.ai/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}
Once connected, call any tool below. The free tier covers 1,000 queries each month across the 377-tool catalog, with no credit card.
Software Supply Chain / Packages tools (4)
| npm_package | npm package metadata: latest version, license, repository, last publish, deprecation, last-month downloads. |
| pypi_package | PyPI (Python) package metadata: latest version, summary, license, author, required Python version. |
| cargo_crate | crates.io (Rust) crate metadata: latest version, description, total downloads, repository. |
| github_repo | Public GitHub repo health: stars, forks, open issues, language, license, last push, archived status. |
Common queries this domain answers: npm · package · dependency · pypi · python package · crate · cargo · rust · github · repo · repository · open source · library · supply chain · sbom · version · license · maintained.
Why LiveDataLink for Software Supply Chain / Packages
- One key, 81 domains. These tools sit alongside FMCSA carrier safety, sanctions screening, SEC filings, courts, Census, and FRED through the same endpoint. Source coverage and credentials vary by tool.
- Check source terms. Sourced from npm / PyPI / crates.io / GitHub; review its attribution and redistribution rules before shipping results.
- For agent workflows. Read-only annotated MCP tools over Streamable HTTP with Bearer auth. Use them with clients that support this transport, including compatible Claude, Cursor, and n8n setups.
FAQ
- What can I look up in Software Supply Chain / Packages?
- Open-source package and dependency intelligence: npm, PyPI, and crates.io metadata plus GitHub repository health. Pair with the CVE tools to vet a dependency. The catalog has 4 tools, including npm_package, pypi_package, cargo_crate, github_repo. They are available over the Model Context Protocol at https://livedatalink.ai/mcp. Coverage and update timing come from npm / PyPI / crates.io / GitHub.
- How do I connect these tools?
- Add https://livedatalink.ai/mcp as a Streamable HTTP MCP server in Claude, Cursor, n8n, or another compatible client, then send an "Authorization: Bearer YOUR_API_KEY" header. A free key includes 1,000 queries/month with no card at https://livedatalink.ai/signup/free. The same key works across domains, although some upstream sources have their own credentials or limits.
- Can I reuse the results in my product?
- That depends on npm / PyPI / crates.io / GitHub's terms. Check its attribution and redistribution rules before shipping results to customers. LiveDataLink's free tier includes 1,000 queries/month, and paid plans start at $10/month.