Skip to content
ToolCargo

Developer Toolkit

Live

Compare npm, PyPI and Rust packages, check vulnerabilities and research AI models in one MCP server.

Before you add a dependency or pick a model: compare npm, PyPI and Rust crate packages (versions, licences and dependencies), check package versions against OSV vulnerability advisories and CISA's known-exploited list, and review Hugging Face models and datasets. No tokens or API keys needed.

Connect / 15 tools

Server URL

streamable http
https://toolcargo.com/mcp/developer-kit

Claude Code

terminal
claude mcp add --transport http --scope user toolcargo-developer-kit https://toolcargo.com/mcp/developer-kit \
  --header "Authorization: Bearer YOUR_API_KEY"

Create a key in your dashboard. Other clients: setup guides.

What it helps you do

  • Compare packages across npm, PyPI and crates.io before adding one.
  • Check a package version for known vulnerabilities and known exploitation.
  • Find and compare Hugging Face models and datasets.

Built for: Developers and technical leads choosing dependencies and models.

What's inside

One connection gives your assistant all of these. Each has a detailed reference.

Example requests

Pick a library

“Compare zod, yup and valibot: latest version, licence and dependencies.”

A side-by-side table from the npm registry.

Vulnerability check

“Is lodash 4.17.15 affected by any known vulnerabilities? Are any exploited in the wild?”

OSV advisories with fixed versions, and CISA KEV status.

Model shortlist

“Find Arabic speech-to-text models on Hugging Face and compare their licences.”

Model cards' public metadata side by side.

Explore useful agent workflows ↗

Tools

ToolWhat it doesAccess
package_details
Inspect an npm package
Inspect a public npm package’s latest version, license, repository, runtime requirements, dependencies, maintainer names and optional last-week downloads. No install or code execution. One shared-plan call.Read-only
compare_packages
Compare npm packages
Compare 2–5 public npm packages using current registry metadata and optional last-week download counts. Not a vulnerability audit or a safety guarantee. One shared-plan call.Read-only
python_package_details
Inspect a Python package
Read the latest PyPI version, license, Python requirements, bounded dependency strings, classifiers and release file metadata for one public Python package. Does not install code or assess security.Read-only
compare_python_packages
Compare Python packages
Compare 2 to 5 distinct public PyPI packages using latest-version metadata, Python requirements, license and dependency strings. Names are normalized; no dependency resolution or installation.Read-only
rust_search_crates
Search Rust crates
Search public crates.io package metadata by plain keywords. Returns up to 10 source-linked crates per explicit relevance page, capped at the first 1,000 matches. Registry top-version fields distinguish highest stable, highest non-yanked and newest publication. No code download. One shared-plan call.Read-only
rust_crate_details
Inspect a Rust crate release
Read an exact semantic version or omit version to select crates.io max_stable_version (highest non-yanked stable release). Returns license, declared Rust version, edition, bounded feature definitions, yanked/prerelease flags and source links. No security or compatibility guarantee; no archives or execution. One shared-plan call.Read-only
rust_crate_dependencies
Read declared Rust dependencies
Inspect direct dependency requirements for an exact crate version. Includes normal, build, dev, optional and target-specific entries, default-feature flags and renamed manifest names; at most 50 records. Verifies the parent version, then reads declarations. Does not resolve a lockfile, install or scan packages. One shared-plan call.Read-only
osv_query_package
Check a package version against OSV
Query public OSV advisories for one package and version in npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Returns up to 20 bounded records from one upstream page with source links, ranges and truncation/pagination indicators. No matches is not a safety verdict. One shared-plan call.Read-only
osv_get_vulnerability
Look up an OSV advisory
Retrieve one public OSV advisory by case-sensitive ID with bounded details, aliases, severity vectors, source references and affected ranges/versions. Explicitly identifies withdrawn records and truncated fields. Does not assess exploitability or install software. One shared-plan call.Read-only
cisa_kev_lookup
Look up CISA known exploitation by CVE
Look up one exact CVE in CISA's validated Known Exploited Vulnerabilities snapshot. Returns dated membership, bounded source descriptions/actions, federal due-date context, ransomware/forensic-triage status and provenance. Not listed does not mean safe or not exploited. One shared-plan call.Read-only
cisa_kev_catalogue
Research a filtered CISA KEV page
Filter CISA KEV by literal vendor/product, inclusive added dates or known/unknown ransomware status. At least one filter; AND combined. Up to 20 records with explicit snapshot-bound nextCursor, newest added first. No automatic paging, exploit code, scanning or personalized patch/compliance decisions. One shared-plan call.Read-only
hf_search_models
Search public models
Find public Hugging Face model repositories by repository-name or ID text. No card-prose search or task, language or license filters. Return up to 10 bounded metadata records and an explicit nextCursor when supplied. Keep query and limit constant when paging; no total or quality ranking is claimed. No weights, files or inference. One shared-plan call per page.Read-only
hf_model_details
Inspect model metadata
Read public model metadata using the exact canonical namespace/repository ID and optionally a full commit SHA. Includes provider task/library, bounded publisher license/language/base-model declarations, commit and access flags. No model card prose, files, code or inference. One shared-plan call.Read-only
hf_search_datasets
Search public datasets
Find public Hugging Face dataset repositories by repository-name or ID text. No card-prose search or task, language or license filters. Returns up to 10 source-linked metadata records per explicit cursor page. Dataset rows are never fetched. Activity counts do not establish dataset quality or permission to use it. One shared-plan call per page.Read-only
hf_dataset_details
Inspect dataset metadata
Read public dataset metadata with exact canonical ID and optional full commit SHA. Returns selected publisher-declared license, language, tasks and size categories alongside Hub tags, access flags and source links. Card and Hub declarations may disagree; no raw rows, files or execution. One shared-plan call.Read-only

Requirements

  • • A ToolCargo account with Site Audit activated (free). No package-registry tokens or API keys.

Limitations

  • • Public registry metadata only; it does not install or run code.
  • • A vulnerability match is a signal to investigate, not proof your installation is affected.
  • • Single-tool URLs such as /mcp/npm-packages remain available for existing keys.

Supported clients

“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.

Claude CodeAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
Claude (claude.ai)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
CursorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
VS Code (Copilot agent mode)API key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
ChatGPT (developer mode)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
MCP InspectorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.

Practical workflows

Pricing

Included with Site Audit. Each successful lookup uses one shared-plan call.

Free

$0

Try hosted tools with a shared monthly allowance.

50 shared calls/month

Pro

$12/mo

Proposed larger shared allowance; see checkout status on the pricing page.

2,000 shared calls/month

Proposed test price. See the pricing page for checkout status.

Full pricing and billing details