# AreaCode.fyi MCP Server (npm · @riv-lc/areacode-mcp)

North American (NANP) area-code & phone-number intelligence for AI agents, by areacode.fyi.

- Trust score: 79/100 (medium)
- Change this week: +33
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `@riv-lc/areacode-mcp`: 79/100 (this document), [markdown](https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp.md), [page](https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp)

## Channel facts

- Registry: `npm`
- Package: `@riv-lc/areacode-mcp`
- Version: `0.2.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 86/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to riv-lc/areacode-mcp).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 41 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 77/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 651 tokens (~81/item across 8 items; 8 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 23/100
  - Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add riv-lc-areacode-mcp -- npx -y @riv-lc/areacode-mcp
```

### Codex

```bash
codex mcp add riv-lc-areacode-mcp -- npx -y @riv-lc/areacode-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "riv-lc-areacode-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@riv-lc/areacode-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add riv-lc-areacode-mcp --command npx --arg -y --arg @riv-lc/areacode-mcp
```

### Hermes

```yaml
mcp_servers:
  riv-lc-areacode-mcp:
    command: "npx"
    args: ["-y", "@riv-lc/areacode-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "riv-lc-areacode-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@riv-lc/areacode-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 79, +74)

- [security improvement] Known CVEs: unverified → partial
- [security improvement] Provenance: unverified → pass
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] The attested source repository moved: riv-lc/areacode-mcp
- [functional regression] Security disclosure: fail → unverified
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Stability: unverified → 0.20
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] License: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] Licence: MIT

### 2026-08-01 (score 5, 0)

- [functional regression] Security disclosure: unverified → fail

### 2026-07-31 (score 5, −57)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 62, −30)

- [security regression] Known CVEs: partial → unverified
- [security regression] Malware scan: pass → unverified
- [functional regression] Dependency health: partial → unverified

### 2026-07-29 (score 92, +66)

- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Provenance: unverified → pass
- [security] The attested source repository moved: riv-lc/areacode-mcp
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] License: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Schema quality: unverified → excellent
- [functional] Licence: MIT

### 2026-07-28 (score 26, −20)

- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] Dependency health: unverified → partial
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 46)

First indexed and scored.

## MCP tools (8)

### `lookup_area_code` (~91 tokens)

Look up an area code

Look up a North American (NANP) area code: country, state/province, principal city and served cities, time zone, current local time, 10-digit-dialing flag, overlay codes, and nearby codes. Returns a canonical areacode.fyi URL and the NANPA source date.

Input parameters:

- `code` (string, required): A 3-digit area code, e.g. "702".

### `lookup_phone_number` (~106 tokens)

Look up a phone number

Parse and validate a US/Canada (NANP) phone number. Returns whether the format is valid, the E.164 form, the area code, the likely region and time zone, and the current local time there. Area-code level only — NOT the caller's identity, exact location, or live carrier; caller ID can be spoofed.

Input parameters:

- `number` (string, required): A phone number in any format, e.g. "+1 702-555-0199".

### `lookup_carrier` (~109 tokens)

Look up a number's carrier (assigned block)

Look up the carrier, line type (wireless/landline), and rate center that a US/Canada number's NPA-NXX block was assigned to — covering nearly every active area code. Based on public block-allocation data, NOT a live lookup: if the number was ported the current carrier differs. Not for caller identity, fraud, or FCRA decisions.

Input parameters:

- `number` (string, required): A US/Canada phone number, e.g. "212-555-0143".

### `area_codes_for_city` (~82 tokens)

Area codes for a city

List the area codes that serve a US or Canadian city. Optionally pass a state/province to disambiguate cities that share a name.

Input parameters:

- `city` (string, required): City name, e.g. "Las Vegas".
- `state` (string): Optional state/province name or 2-letter code to disambiguate, e.g. "NV".

### `area_codes_for_state` (~49 tokens)

Area codes for a state/province

List every area code in a US state or Canadian province.

Input parameters:

- `state` (string, required): State/province name or 2-letter code, e.g. "Nevada" or "ON".

### `is_scam_area_code` (~80 tokens)

Is an area code a scam?

Explain whether an area code is associated with scams. An area code is never a scam by itself; this returns that context plus spoofing notes — caller ID can be faked, so judge calls by what they ask for, not the area code.

Input parameters:

- `code` (string, required): A 3-digit area code, e.g. "702".

### `check_number_reputation` (~97 tokens)

Check a number's community reputation

Return the UNVERIFIED, crowd-sourced community signal for a US/Canada number from areacode.fyi: 'low' (people have looked it up), 'mid'/'high' (it has user reports). Caller ID can be spoofed — this is never proof a specific number is fraudulent.

Input parameters:

- `number` (string, required): A US/Canada phone number, e.g. "702-555-0199".

### `explain_area_code_topic` (~37 tokens)

Explain a phone / area-code topic

Source-backed explanation of a phone-numbering topic, suitable for answering end users.

Input parameters:

- `topic` (string, required): The topic to explain.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp#diagnostics

## Score history

- 2026-08-03: 79
- 2026-08-02: 79
- 2026-08-01: 5
- 2026-07-31: 5
- 2026-07-30: 62
- 2026-07-29: 92
- 2026-07-28: 26
- 2026-07-27: 46

## Links

- npm package: https://www.npmjs.com/package/@riv-lc/areacode-mcp
- Socket report: https://socket.dev/npm/package/@riv-lc/areacode-mcp
- Repository: https://github.com/riv-lc/areacode-mcp
- Website: https://areacode.fyi/mcp
- Changelog RSS feed: https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/riv-lc-areacode-mcp/riv-lc-areacode-mcp
