MCP Drift Watch

What changed in MCP packages and agent skills after people started trusting them · last 30 days · by PulseFeed · MCP Observatory · State of MCP Security

Watching 26,856 servers across the entire MCP registry — metadata diffed daily. Depth audit (install scripts, ownership, provenance) runs on the audited subset.

9
install script added
50
owner changed
118
repo removed/moved
74
unpublished
958
skill instructions swapped
7
fixed by author

Recent drift

🕳
com.attrove/mcp repo removed
Repository link removed — the source can no longer be reviewed.
6h ago
🕳
Repository link removed — the source can no longer be reviewed.
6h ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6h ago
🗣
api-gateway skill instructions changed86,279 downloads
The instructions this skill feeds to the model changed in 1.0.152. The text shrank by 27 characters. A skill's description is not documentation — the agent reads it and acts on it.
1d ago
🗣
anysearch skill instructions changed37,074 downloads
The instructions this skill feeds to the model changed in 3.1.1. The text shrank by 41 characters. A skill's description is not documentation — the agent reads it and acts on it.
1d ago
🕳
Repository link removed — the source can no longer be reviewed.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
1d ago
🎭
@blaxel/core maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
@blaxel/telemetry maintainer changed7,077/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
@blaxel/llamaindex maintainer changed742/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
@blaxel/vercel maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
@blaxel/mastra maintainer changed755/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🎭
@blaxel/langgraph maintainer changed746/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
☠️
@fatelabs/estelle install script added
Install script added: arbitrary code now runs on `npm i` — it was not there in 0.2.3.
1d ago
⚠️
@fatelabs/estelle verdict worsened
Verdict worsened: safe → avoid (score 86 → 56).
1d ago
🎭
@chkp/mcp-utils maintainer changed2,057/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
1d ago
🗣
upload-post skill instructions changed10,453 downloads
The instructions this skill feeds to the model changed in 1.2.0. The text grew by 503 characters. A skill's description is not documentation — the agent reads it and acts on it.
2d ago
🕳
Repository link removed — the source can no longer be reviewed.
2d ago
🕳
Repository link removed — the source can no longer be reviewed.
2d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
💨
work.moja/ui unpublished
Package removed from npm — installs will break, and the name is now free for anyone to claim.
2d ago
🎭
@tangle-network/agent-app maintainer changed3,037/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
2d ago
🎭
@babylonjs/mcp-servers maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
2d ago
☠️
@realpkuasule/harness-automation install script added363/wk
Install script added: arbitrary code now runs on `npm i` — it was not there in 2.5.0.
2d ago
⚠️
@realpkuasule/harness-automation verdict worsened363/wk
Verdict worsened: safe → avoid (score 80 → 60).
2d ago
🗣
topic-monitor skill instructions changed11,039 downloads
The instructions this skill feeds to the model changed in 1.6.0. The text grew by 703 characters. A skill's description is not documentation — the agent reads it and acts on it.
3d ago
🕳
app.g-guest/g-guest repo removed
Repository link removed — the source can no longer be reviewed.
3d ago
🕳
Repository link removed — the source can no longer be reviewed.
3d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
3d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
3d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
3d ago
💨
live.gex/gex-mcp unpublished
Package removed from npm — installs will break, and the name is now free for anyone to claim.
3d ago
🎭
mcp-auth maintainer changed26,177/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
3d ago
🎭
@heroku/mcp-server maintainer changed8,621/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
3d ago
🗣
planning-with-files skill instructions changed40,028 downloads
The instructions this skill feeds to the model changed in 3.12.0. The text grew by 267 characters. A skill's description is not documentation — the agent reads it and acts on it.
4d ago
🗣
todo-tracker skill instructions changed12,495 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 270 characters. A skill's description is not documentation — the agent reads it and acts on it.
4d ago
🕳
at.gridbert/mcp repo removed
Repository link removed — the source can no longer be reviewed.
4d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
4d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
4d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
4d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
4d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
4d ago
🕳
Repository link removed — the source can no longer be reviewed.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
com.koynfx/mcp unpublished
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
💨
uk.plott/mcp unpublished
Package removed from npm — installs will break, and the name is now free for anyone to claim.
5d ago
🕳
alvin-bot repo removed14,362/wk
Repository link removed — the source can no longer be reviewed.
5d ago
🕳
com.lockally/email repo removed
Repository link removed — the source can no longer be reviewed.
6d ago
🕳
Repository link removed — the source can no longer be reviewed.
6d ago
🕳
Repository link removed — the source can no longer be reviewed.
6d ago
🕳
Repository link removed — the source can no longer be reviewed.
6d ago
🕳
Repository link removed — the source can no longer be reviewed.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
6d ago
🎭
@bangdao-ai/acw-tools maintainer changed13,564/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools-protocol maintainer changed793/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools-cdp maintainer changed515/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools-mcp maintainer changed499/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools-browser maintainer changed490/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
🎭
@gjsify/devtools-nativescript maintainer changed501/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
6d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
7d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
7d ago
💨
io.okrstud/mcp unpublished
Package removed from npm — installs will break, and the name is now free for anyone to claim.
7d ago
🎭
@hubspot/mcp-server maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
🎭
@taptap/maker maintainer changed6,034/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
🎭
@powerhousedao/reactor-mcp maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
🎭
@armature-tech/mcp-analytics maintainer changed2,350/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
🎭
@seed-design/docs-mcp maintainer changed2,293/wk
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
☠️
jazz-ai install script added
Install script added: arbitrary code now runs on `npm i` — it was not there in 0.15.6.
7d ago
⚠️
jazz-ai verdict worsened
Verdict worsened: safe → avoid (score 86 → 50).
7d ago
🎭
vision-relay maintainer changed
Package ownership changed — whoever you trusted is no longer the one publishing it.
7d ago
🗣
gmail skill instructions changed38,807 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
youtube-api-skill skill instructions changed27,741 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
microsoft-excel skill instructions changed26,697 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 867 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
outlook-api skill instructions changed23,477 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
whatsapp-business skill instructions changed23,284 downloads
The instructions this skill feeds to the model changed in 1.1.1. The text grew by 534 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
stripe-api skill instructions changed21,675 downloads
The instructions this skill feeds to the model changed in 1.1.1. The text grew by 205 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-slides skill instructions changed19,704 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 699 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
xero skill instructions changed19,519 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 685 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
salesforce-api skill instructions changed19,332 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 533 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
typeform skill instructions changed18,989 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 671 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
clickup-api skill instructions changed18,592 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 771 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
calendly-api skill instructions changed18,458 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 829 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-meet skill instructions changed18,430 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 695 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
github-api skill instructions changed18,366 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 323 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
asana-api skill instructions changed18,276 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 288 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-workspace-admin skill instructions changed18,263 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1409 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
trello-api skill instructions changed17,804 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
fathom-api skill instructions changed17,746 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 803 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
klaviyo skill instructions changed17,482 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 832 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
mailchimp skill instructions changed17,257 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 810 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
pipedrive-api skill instructions changed16,893 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 663 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-play skill instructions changed16,808 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 762 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-sheets skill instructions changed15,714 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 284 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
monday skill instructions changed15,663 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 895 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-drive skill instructions changed15,464 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
woocommerce skill instructions changed15,360 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1573 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-mail skill instructions changed14,355 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 851 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
linear-api skill instructions changed14,298 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 370 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-crm skill instructions changed14,199 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1042 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-inventory skill instructions changed13,578 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1043 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
attio-api skill instructions changed13,503 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 831 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-calendar skill instructions changed13,469 downloads
The instructions this skill feeds to the model changed in 1.1.1. The text grew by 598 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-recruit skill instructions changed13,392 downloads
The instructions this skill feeds to the model changed in 1.1.2. The text grew by 801 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-people skill instructions changed13,251 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1427 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
zoho-bigin skill instructions changed13,244 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 885 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
linkedin-api skill instructions changed12,803 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 542 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-analytics skill instructions changed12,023 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 1381 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
google-calendar-api skill instructions changed11,208 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 282 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🗣
notion-api-skill skill instructions changed10,881 downloads
The instructions this skill feeds to the model changed in 1.1.0. The text grew by 359 characters. A skill's description is not documentation — the agent reads it and acts on it.
8d ago
🕳
Repository link removed — the source can no longer be reviewed.
8d ago
🕳
Repository link removed — the source can no longer be reviewed.
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
☠️
suppa-mcp-2 install script added1,011/wk
Install script added: arbitrary code now runs on `npm i` — it was not there in 1.14.0.
8d ago
⚠️
suppa-mcp-2 verdict worsened1,011/wk
Verdict worsened: safe → avoid (score 92 → 62).
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
💨
Package removed from npm — installs will break, and the name is now free for anyone to claim.
8d ago
Why a separate feed — every MCP scanner answers one question: is this package safe today? A rug pull is the other question: the package was clean when it was reviewed, collected installs for weeks, and only then shipped a patch that runs code on npm i. Existing defences against that are local — a CLI diff you have to run yourself, a runtime proxy inside your own perimeter, or a changelog the vendor writes voluntarily. All of them mean the first victim is never protected.

What this is — the whole MCP package population re-audited daily from the outside, with every transition recorded. An event exists here because there is a snapshot from before it.

Check your own list (free, no key — put it in CI):
curl -s "https://pulsefeed.dev/mcp/drift.json?packages=pkg-a,pkg-b&days=7"
Put it in your CI — one step, no key, fails the build when a dependency you already trust changes dangerously:
- uses: Nikolife2016/mcp-drift-action@v1
github.com/Nikolife2016/mcp-drift-action

Subscribe to your own list (RSS, no signup — drop it in Slack, a reader, or a CI step):
https://pulsefeed.dev/mcp/drift.rss?packages=pkg-a,pkg-b
Get woken up, not notified later — a webhook fires the moment we see it, for your packages only:
curl -X POST https://pulsefeed.dev/mcp/alerts/subscribe   -H 'content-type: application/json'   -d '{"url":"https://your-endpoint","packages":["io.github.you/your-server","your-npm-pkg"]}'
We post a confirmation to that webhook containing a link; opening it activates the subscription. A webhook nobody confirms never receives anything — otherwise anyone could point our traffic at your endpoint. Only ownership changes, install scripts appearing, removals, lookalike names and resurrections are sent; new versions are not, because being woken for a release is how you learn to ignore the channel.

Unlike the RSS filter, this does mean we store something: your webhook URL, your package list and timestamps. No email, no name, nothing about who you are, and the URL is never published — /mcp/alerts/status shows counts only. The unsubscribe link travels in every delivery.

Put the badge in your README — it states what changed in your package after people adopted it, and it goes grey rather than green when we have nothing to say:
example: clean example: unpublished example: unwatched
[![MCP drift](https://pulsefeed.dev/badge/mcp.svg?package=YOUR-PACKAGE)](https://pulsefeed.dev/mcp/drift)
Use your registry name (io.github.you/your-server) or your npm package name. A green badge is a claim about your package, so we only make it when the package is in the snapshot — otherwise it reads unwatched.

Everything here is free — since 2026-09-02 there is no paid tier: the full series across the whole population at any depth (/mcp/drift.json?days=…, /mcp/drift/history), any depth for your own packages (?packages=), the badge, the webhook alerts and the CI action. No key, no payment, CORS-enabled; each day's dataset manifest is signed (Ed25519) and anchored in Bitcoin via OpenTimestamps so the series cannot be quietly rewritten: /anchors/latest.json · key /.well-known/manifest-signing-key.json. Full feed: /mcp/drift.json · /mcp/drift.rss · single package: GET /mcp/verify?package=<name>

Events come from PulseFeed's own daily audit of the MCP package population — npm metadata, install scripts, ownership, provenance, repository, licence and liveness, re-read every night and diffed against the previous snapshot. Series started 2026-08-01. A drift event cannot be reconstructed after the fact: without yesterday's snapshot there is nothing to compare against.
Severity: high — code execution, ownership or source disappeared; medium — attack surface grew or provenance broken; low — informational, including fixes by the author. Window: 30 days · 17743 events · generated 2026-09-04T08:05:03.652Z.
MCP Observatory · All servers · State of MCP Security · Methodology