Check the install commands in your README
Install commands are code other people run as written, often pasted straight into a terminal, a CI job or an AI client's MCP configuration. Presend finds every npx, npm install, pip install, uvx (and bunx, pnpm, yarn, uv, pipx, poetry) command in your text and checks each package on npm or PyPI:
- names nobody has registered: the command fails today, and installs whatever anyone publishes under that name tomorrow (how often it happens);
- packages whose latest version is deprecated, packages first published less than 30 days ago, names close to a popular package, and recent publisher changes (npm);
- known vulnerabilities in versions the commands pin (
npx tool@1.4.2,pip install lib==0.3).
Public repositories only: your browser reads the README (or the file you link) directly from GitHub.
The text is read in your browser. Only the package names, and the versions the commands pin, are sent to Presend's API. Up to 100 packages per check; per-minute rate limits apply.
| Package | Where | Result | Details |
|---|
No signal:
How commands are read
- In code blocks, inline code, lines that start with the command (or a prompt such as
$,RUN,run:), and MCP configurations ("command": "npx"or"uvx"with its"args"). Commands in plain sentences are ignored. npx,bunx,pnpm dlxanduvxinstall the package named by-p/--package/--from, or else the package named like the command: that is the name checked.- Placeholders (
<package>,your-package,$PKG), local paths, URLs and git sources are skipped: they are not registry names.
What this page does not check
- Whether a name is yours. A package that exists may belong to someone else: if the command is meant to run your own package, check that the name is one you publish.
- Docker images, curl | sh scripts, Homebrew, cargo or go install. Only npm and PyPI.
- Malware. These are signals worth a look before publishing your docs, not an analysis of the package code.
For your whole documentation
Docs sites, several repositories, MCP server listings, templates and examples: we can review every install command you publish, and tell you which ones point to a name you do not own. Write to presendapp@gmail.com. For a single dependency file, use the dependency check; for an MCP configuration in CI, mcp-preflight.mjs.