Supply chain warnings about npm install scripts rarely come with a denominator. How many packages even declare one? In August 2026 we counted, in one corner of npm: packages that implement Model Context Protocol servers, the tools AI agents connect to.
The number
We collected 658 MCP server packages from eight npm registry search queries and read each package's declared scripts. 20 of them declare a preinstall, install or postinstall script. That is 3.0 percent of the sample.
- It is 3.0 percent of this sample, not of npm. 658 packages from eight searches is a search result, not a complete list of MCP servers.
- It counts each package's own scripts. Install scripts in its dependencies are not included.
- Four of the 20 are the same package manager guard, npx only-allow pnpm, whose job is to stop you installing with the wrong package manager. It still makes a network request at install when only-allow is not cached.
Running the 20
Of the 20 packages with install scripts, 19 could be downloaded. We ran each one's scripts in a container with no network, all capabilities dropped and a read-only filesystem, without installing dependencies. 8 ran to completion and 11 did not, by exiting with an error or running out of time. In a container with no network and no dependencies installed, a failure says as much about the container as about the package, so the checker reports a failing script as manual_review, never as rejected.
We also compared each package's manifest from the registry API with the package.json inside the tarball npm actually downloads. They agreed for all 19. Our first pass said one did not, and the mistake was ours: an npm tarball can contain many package.json files, and we had read a nested build artifact instead of the manifest at the top.
What the count does not measure
When we published the census, reviewers made three points that matter more than the number itself.
- Install time is the wrong surface for an MCP server. An MCP server is a program you run, and all 19 downloadable packages declare a bin, an executable npm links for you. The other 638 packages with no install script still run arbitrary code the moment you start them.
- An unknown side effect should mean quarantine, not a longer timeout. A script that hangs is a finding in itself.
- Reading package.json from the tarball is still reading a manifest. It tells you a script exists, not what it does.
We agree with all three. The install surface is small and legible, which is exactly why it is where a check is cheap, and exactly why a clean result there says little about what the server does once it runs.
Check a package yourself
To see a package's install scripts without installing it:
npm view <package> scriptsTo run them in a sealed container and get a signed verdict bound to the tarball's sha256, with no account or key:
npx -y @kenwea/mcp check <package>The census ran from 8 to 9 August 2026. Package versions and counts change daily; re-running it today would give a different sample and likely a different number.
Try the notary with no account or key, or add it to your agent as an MCP server.