Fetter MCP

Real-time Python package and vulnerability data for AI coding agents.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~503Tokens (tool definitions)
~1.5 KBTypical response size
Minimal attention impact (0.39% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "fetter-mcp": {
      "url": "https://mcp.fetter.io/mcp"
    }
  }
}

Remote endpoints

https://mcp.fetter.io/mcpstreamable-http

What it can do

Tool inventory

Tools (3)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢is_vulnerable(name)

Check if a specific package version has known vulnerabilities. Requires an exact version specifier (e.g., 'requests==2.31.0').

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "description": "The exact package name and version (e.g., \"requests==2.31.0\", \"numpy==1.24.0\").",
      "type": "string"
    }
  },
  "required": [
    "name"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "IsVulnerableArgs"
}
🟢lookup(cvss_filter, limit, name, retain_passing)

Look up a package by name and (optionally) version number to find which versions are available and/or have vulnerabilities.

Input Schema

{
  "type": "object",
  "properties": {
    "cvss_filter": {
      "default": null,
      "description": "CVSS score filter: \"all\" to show all vulnerabilities, \"max\" to show only the\nmaximum observed score, or a number (0.0-10.0) to filter by threshold",
      "nullable": true,
      "type": "string"
    },
    "limit": {
      "description": "When the name is not an exact version, limit the number of recent versions to check.",
      "format": "uint",
      "minimum": 0,
      "nullable": true,
      "type": "integer"
    },
    "name": {
      "description": "The package name to look up (e.g., \"requests\", \"numpy>=2.0\", \"flask==3.0.0\"). Note that when an exact \"==\" version is specified, the `limit` and `retain_passing` parameters have no effect.",
      "type": "string"
    },
    "retain_passing": {
      "description": "'When the name is not an exact version, setting this to True will return refernces for all packages, include those with no vulnerabilities (default: false)",
      "nullable": true,
      "type": "boolean"
    }
  },
  "required": [
    "name"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "LookupArgs"
}
🟢most_recent_not_vulnerable(name)

Find the most recent version of a package that has no known vulnerabilities.

Input Schema

{
  "type": "object",
  "properties": {
    "name": {
      "description": "The package name to look up (e.g., \"requests\", \"numpy\", \"flask\").",
      "type": "string"
    }
  },
  "required": [
    "name"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "MostRecentNotVulnerableArgs"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded3 tools
verifiedversion not recorded3 tools
verifiedversion not recorded3 tools