Skip to content
ToolCargo

Docs · Updated 2026-10-03

Developer Toolkit — tool reference

Compare npm, PyPI and Rust packages, check vulnerabilities and research AI models in one MCP server.

Server URL: https://toolcargo.com/mcp/developer-kit · Scope: connector:developer-kit · Included with Site Audit. Each successful lookup uses one shared-plan call.

One server, 15 tools. Older single-tool endpoints (for example /mcp/npm-packages) stay live for existing keys. Prefer this server so the assistant sees every tool in one place.

What’s inside

These tools are served from this same server; each link has the detailed reference.

package_details

Inspect a public npm package’s latest version, license, repository, runtime requirements, dependencies, maintainer names and optional last-week downloads. No install or code execution. One shared-plan call.

compare_packages

Compare 2–5 public npm packages using current registry metadata and optional last-week download counts. Not a vulnerability audit or a safety guarantee. One shared-plan call.

python_package_details

Read the latest PyPI version, license, Python requirements, bounded dependency strings, classifiers and release file metadata for one public Python package. Does not install code or assess security.

compare_python_packages

Compare 2 to 5 distinct public PyPI packages using latest-version metadata, Python requirements, license and dependency strings. Names are normalized; no dependency resolution or installation.

rust_search_crates

Search public crates.io package metadata by plain keywords. Returns up to 10 source-linked crates per explicit relevance page, capped at the first 1,000 matches. Registry top-version fields distinguish highest stable, highest non-yanked and newest publication. No code download. One shared-plan call.

rust_crate_details

Read an exact semantic version or omit version to select crates.io max_stable_version (highest non-yanked stable release). Returns license, declared Rust version, edition, bounded feature definitions, yanked/prerelease flags and source links. No security or compatibility guarantee; no archives or execution. One shared-plan call.

rust_crate_dependencies

Inspect direct dependency requirements for an exact crate version. Includes normal, build, dev, optional and target-specific entries, default-feature flags and renamed manifest names; at most 50 records. Verifies the parent version, then reads declarations. Does not resolve a lockfile, install or scan packages. One shared-plan call.

osv_query_package

Query public OSV advisories for one package and version in npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Returns up to 20 bounded records from one upstream page with source links, ranges and truncation/pagination indicators. No matches is not a safety verdict. One shared-plan call.

osv_get_vulnerability

Retrieve one public OSV advisory by case-sensitive ID with bounded details, aliases, severity vectors, source references and affected ranges/versions. Explicitly identifies withdrawn records and truncated fields. Does not assess exploitability or install software. One shared-plan call.

cisa_kev_lookup

Look up one exact CVE in CISA's validated Known Exploited Vulnerabilities snapshot. Returns dated membership, bounded source descriptions/actions, federal due-date context, ransomware/forensic-triage status and provenance. Not listed does not mean safe or not exploited. One shared-plan call.

cisa_kev_catalogue

Filter CISA KEV by literal vendor/product, inclusive added dates or known/unknown ransomware status. At least one filter; AND combined. Up to 20 records with explicit snapshot-bound nextCursor, newest added first. No automatic paging, exploit code, scanning or personalized patch/compliance decisions. One shared-plan call.

hf_search_models

Find public Hugging Face model repositories by repository-name or ID text. No card-prose search or task, language or license filters. Return up to 10 bounded metadata records and an explicit nextCursor when supplied. Keep query and limit constant when paging; no total or quality ranking is claimed. No weights, files or inference. One shared-plan call per page.

hf_model_details

Read public model metadata using the exact canonical namespace/repository ID and optionally a full commit SHA. Includes provider task/library, bounded publisher license/language/base-model declarations, commit and access flags. No model card prose, files, code or inference. One shared-plan call.

hf_search_datasets

Find public Hugging Face dataset repositories by repository-name or ID text. No card-prose search or task, language or license filters. Returns up to 10 source-linked metadata records per explicit cursor page. Dataset rows are never fetched. Activity counts do not establish dataset quality or permission to use it. One shared-plan call per page.

hf_dataset_details

Read public dataset metadata with exact canonical ID and optional full commit SHA. Returns selected publisher-declared license, language, tasks and size categories alongside Hub tags, access flags and source links. Card and Hub declarations may disagree; no raw rows, files or execution. One shared-plan call.

Set up Developer Toolkit

Review connection instructions, required credentials and plan limits before connecting your agent.