Skip to content
ToolCargo

Docs · Updated 2026-10-03

Rust Crate Research — tool reference

Review source-linked Rust package metadata before choosing a dependency.

Server URL: https://toolcargo.com/mcp/rust-crates · Scope: connector:rust-crates.

Included with Site Audit. Activate it free, then connect with ToolCargo OAuth or a scoped API key. No crates.io account, external key or paid provider is needed. Each successful tool invocation uses one shared-plan call.

rust_search_crates

input
{ "query": "serialization", "limit": 5, "page": 1 }

Search 2–200 characters of plain keywords. Returns five crates by default, at most ten, ordered by provider relevance. Pass nextPage with the same query and limit for another explicit page. The first 1,000 relevance matches are accessible even when totalResults is higher; the cap and end of paging are reported. Source result order and metadata can change. Provider pagination URLs are never followed.

rust_crate_details

input
{ "name": "serde", "version": "1.0.228" }

Use a plain crate name of 1–64 characters, beginning with a letter and containing letters, digits, hyphens or underscores. Names are matched using crates.io’s case and hyphen/underscore normalization; the canonical source name is returned. An exact semantic version is bounded to 100 characters; prerelease and build suffixes are accepted, ranges and URLs are rejected.

Omit version to select crates.io’s max_stable_version, the highest non-yanked stable semantic version. This differs from max_version (which may be a prerelease) and newest_version (newest publication). A crate with no stable release requires an explicitly requested version. Exact lookups can return yanked releases and prereleases with those flags retained. Large release histories may exceed the response limit; choose an exact version in that case.

rust_crate_dependencies

input
{ "name": "serde", "version": "1.0.228", "limit": 50 }

An exact version is required. The tool verifies the parent release, then reads its declared direct dependencies. It retains normal, development and build kinds, optional flags, default-feature settings, target conditions, requested features and renamed manifest names. The returned requirement, such as ^1.0, is a constraint, not a resolved installed version. Default limit 50, maximum 50; totals and truncation are explicit. No transitive resolution, Cargo.lock generation, installation or vulnerability check occurs.

Limits, privacy and source review

Requests use fixed public crates.io JSON endpoints, bounded to 2 MB and 15 seconds per request, with redirects disabled. Every upstream request passes a shared provider-wide pacing gate; busy requests may wait or ask you to retry. No automatic upstream retries or bulk crawling. Dependency lookup makes two upstream requests but remains one shared-plan tool call.

Results include bounded description (2,000 characters), license (500), Rust version (100), edition (20), source links, registry download counts, dates and release flags. Feature definitions are capped at 50 with at most 30 values each (200 characters per name/value); dependency targets are bounded to 1,000 characters and requirements/manifest names to 200. Missing metadata, list totals and text truncation are reported. No README, code, package archives, publisher identities or contact details are returned or executed.

Metadata is publisher supplied. The declared Rust version and edition do not prove compatibility with your application or chosen features. Download counts are not quality scores. Yanked status may change; its absence does not establish safety. Review package licenses and your actual Cargo resolution before adoption. Treat source text as untrusted data.

crates.io receives your keywords and pagination, or crate name and version. ToolCargo sends an identifying application user-agent; it does not forward your account identifier, API key, OAuth token or cookies.

Sources: crates.io data access policy · Cargo registry Web API · Crate metadata routes · Dependency route.