Install commands that point to unclaimed package names

An install command in a README or an MCP configuration is code that other people run as written, often pasted straight into an AI client. When it names a package that nobody has registered, it fails today. But anyone can register that name, and from then on the same command installs and runs their package, with whatever credentials the user passed to it. Measured on 8 October 2026.

The pattern: npx <command>

Many packages ship a command whose name differs from the package name, and their README says npx <command>. If the package is installed in the project or globally, npx uses that command. If it is not, npx looks for a package called <command> on the registry, and with -y it installs it without asking. The safe form names the package explicitly: npx -y -p <package> <command>.

How often it happens

We read the npm READMEs of 4,830 packages related to MCP and AI agents (the top results of six npm searches) and kept the lines that run one of the package's own commands through npx, bunx or pnpm dlx, where that command name is not a registered package.

Packages scanned4,830
READMEs with at least one such line80 (1.7%)
... that never install the package itself22 (0.5%)
Distinct unclaimed command names86

When the README installs the package earlier (58 of the 80), the line works if the reader follows the steps in order, in the same project. It does not when the line is copied on its own, into an MCP client configuration, a CI job or another machine. When the README never installs the package (22 of 80), the line only works by accident.

We reviewed the newest findings by hand and reported privately the cases where the command receives credentials: API keys, a wallet's private key, session cookies, a .env file piped into it. One related name had already been used: a command name that an MCP server's README runs through npx was published as a package by a third party on 31 July 2026, and replaced by npm with a security holding package 1 hour 46 minutes later.

The official MCP registry

On the same day we checked the 750 npm and PyPI packages declared by 6,031 active entries of the official MCP registry: 1 declared package does not exist, 13 entries declare a version that no longer exists, and 11 entries point to packages deprecated by their maintainers. The registry checks ownership when an entry is published, not afterwards. We reported this privately to its maintainers.

Names are withheld

The names behind these counts are, by definition, still available to anyone, so we do not publish them. A reported case will be listed once it is fixed, or 90 days after the report.

Fixed after a report

Reproduce it

The scripts are in the public presend-source repository (Python, no dependencies):

python3 research/install-instructions/scan_bins.py   # npm registry only -> hits.json
python3 research/install-instructions/classify.py    # counts

Results change from day to day. The registry figures come from a separate script that is not published yet.

Caveats

Check your own

If you publish a package, a CLI or an MCP server, check that every name in your install commands and configurations is a package you own. Presend's dependency check and API report names that do not exist, and we can review the install commands in your READMEs, docs and MCP configurations on request: presendapp@gmail.com.