Developer Toolkit
LiveCompare npm, PyPI and Rust packages, check vulnerabilities and research AI models in one MCP server.
Before you add a dependency or pick a model: compare npm, PyPI and Rust crate packages (versions, licences and dependencies), check package versions against OSV vulnerability advisories and CISA's known-exploited list, and review Hugging Face models and datasets. No tokens or API keys needed.
Connect / 15 tools
Server URL
https://toolcargo.com/mcp/developer-kitClaude Code
claude mcp add --transport http --scope user toolcargo-developer-kit https://toolcargo.com/mcp/developer-kit \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Compare packages across npm, PyPI and crates.io before adding one.
- Check a package version for known vulnerabilities and known exploitation.
- Find and compare Hugging Face models and datasets.
Built for: Developers and technical leads choosing dependencies and models.
What's inside
One connection gives your assistant all of these. Each has a detailed reference.
- npm Package IntelligenceCompare dependencies before adding them to a project.
- PyPI Package IntelligenceCompare Python packages before choosing a dependency.
- Rust Crate ResearchFind Rust crates and inspect releases, features and dependencies.
- OSV Vulnerability LookupCheck package versions against public vulnerability advisories.
- CISA Known Exploited VulnerabilitiesCheck CISA's recorded known exploitation by CVE.
- Hugging Face Hub ResearchFind models and datasets, then review their public metadata.
Example requests
Pick a library
“Compare zod, yup and valibot: latest version, licence and dependencies.”
A side-by-side table from the npm registry.
Vulnerability check
“Is lodash 4.17.15 affected by any known vulnerabilities? Are any exploited in the wild?”
OSV advisories with fixed versions, and CISA KEV status.
Model shortlist
“Find Arabic speech-to-text models on Hugging Face and compare their licences.”
Model cards' public metadata side by side.
Tools
| Tool | What it does | Access |
|---|---|---|
package_detailsInspect an npm package | Inspect a public npm package’s latest version, license, repository, runtime requirements, dependencies, maintainer names and optional last-week downloads. No install or code execution. One shared-plan call. | Read-only |
compare_packagesCompare npm packages | Compare 2–5 public npm packages using current registry metadata and optional last-week download counts. Not a vulnerability audit or a safety guarantee. One shared-plan call. | Read-only |
python_package_detailsInspect a Python package | Read the latest PyPI version, license, Python requirements, bounded dependency strings, classifiers and release file metadata for one public Python package. Does not install code or assess security. | Read-only |
compare_python_packagesCompare Python packages | Compare 2 to 5 distinct public PyPI packages using latest-version metadata, Python requirements, license and dependency strings. Names are normalized; no dependency resolution or installation. | Read-only |
rust_search_cratesSearch Rust crates | Search public crates.io package metadata by plain keywords. Returns up to 10 source-linked crates per explicit relevance page, capped at the first 1,000 matches. Registry top-version fields distinguish highest stable, highest non-yanked and newest publication. No code download. One shared-plan call. | Read-only |
rust_crate_detailsInspect a Rust crate release | Read an exact semantic version or omit version to select crates.io max_stable_version (highest non-yanked stable release). Returns license, declared Rust version, edition, bounded feature definitions, yanked/prerelease flags and source links. No security or compatibility guarantee; no archives or execution. One shared-plan call. | Read-only |
rust_crate_dependenciesRead declared Rust dependencies | Inspect direct dependency requirements for an exact crate version. Includes normal, build, dev, optional and target-specific entries, default-feature flags and renamed manifest names; at most 50 records. Verifies the parent version, then reads declarations. Does not resolve a lockfile, install or scan packages. One shared-plan call. | Read-only |
osv_query_packageCheck a package version against OSV | Query public OSV advisories for one package and version in npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Returns up to 20 bounded records from one upstream page with source links, ranges and truncation/pagination indicators. No matches is not a safety verdict. One shared-plan call. | Read-only |
osv_get_vulnerabilityLook up an OSV advisory | Retrieve one public OSV advisory by case-sensitive ID with bounded details, aliases, severity vectors, source references and affected ranges/versions. Explicitly identifies withdrawn records and truncated fields. Does not assess exploitability or install software. One shared-plan call. | Read-only |
cisa_kev_lookupLook up CISA known exploitation by CVE | Look up one exact CVE in CISA's validated Known Exploited Vulnerabilities snapshot. Returns dated membership, bounded source descriptions/actions, federal due-date context, ransomware/forensic-triage status and provenance. Not listed does not mean safe or not exploited. One shared-plan call. | Read-only |
cisa_kev_catalogueResearch a filtered CISA KEV page | Filter CISA KEV by literal vendor/product, inclusive added dates or known/unknown ransomware status. At least one filter; AND combined. Up to 20 records with explicit snapshot-bound nextCursor, newest added first. No automatic paging, exploit code, scanning or personalized patch/compliance decisions. One shared-plan call. | Read-only |
hf_search_modelsSearch public models | Find public Hugging Face model repositories by repository-name or ID text. No card-prose search or task, language or license filters. Return up to 10 bounded metadata records and an explicit nextCursor when supplied. Keep query and limit constant when paging; no total or quality ranking is claimed. No weights, files or inference. One shared-plan call per page. | Read-only |
hf_model_detailsInspect model metadata | Read public model metadata using the exact canonical namespace/repository ID and optionally a full commit SHA. Includes provider task/library, bounded publisher license/language/base-model declarations, commit and access flags. No model card prose, files, code or inference. One shared-plan call. | Read-only |
hf_search_datasetsSearch public datasets | Find public Hugging Face dataset repositories by repository-name or ID text. No card-prose search or task, language or license filters. Returns up to 10 source-linked metadata records per explicit cursor page. Dataset rows are never fetched. Activity counts do not establish dataset quality or permission to use it. One shared-plan call per page. | Read-only |
hf_dataset_detailsInspect dataset metadata | Read public dataset metadata with exact canonical ID and optional full commit SHA. Returns selected publisher-declared license, language, tasks and size categories alongside Hub tags, access flags and source links. Card and Hub declarations may disagree; no raw rows, files or execution. One shared-plan call. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free). No package-registry tokens or API keys.
Limitations
- • Public registry metadata only; it does not install or run code.
- • A vulnerability match is a signal to investigate, not proof your installation is affected.
- • Single-tool URLs such as /mcp/npm-packages remain available for existing keys.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.
| Claude Code | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Claude (claude.ai) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Cursor | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| MCP Inspector | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
Practical workflows
Pricing
Included with Site Audit. Each successful lookup uses one shared-plan call.
Free
$0Try hosted tools with a shared monthly allowance.
50 shared calls/month
Pro
$12/moProposed larger shared allowance; see checkout status on the pricing page.
2,000 shared calls/month
Proposed test price. See the pricing page for checkout status.