devstack-mcp

Dev-registry data: npm/PyPI/Docker/VS Code packages, dep graphs, vulns, 50+ ecosystems.

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
100%
Naming quality
98%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,443Tokens (tool definitions)
~1.2 KBTypical response size
Moderate attention impact (1.91% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "devstack-mcp": {
      "url": "https://devstack-mcp.vercel.app/mcp"
    }
  }
}

Remote endpoints

https://devstack-mcp.vercel.app/mcpstreamable-http

What it can do

Tool inventory

Tools (10)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢get_package(registry, name)

Full normalized details for one package by registry + name, in a single unified Package shape across npm, PyPI, Docker Hub, and the VS Code Marketplace. name handles scoped npm ids (e.g. @types/node), Docker namespaces (e.g. library/nginx or a bare nginx for official images), and VS Code publisher.extension ids. With registry=all the request fans out to every registry in parallel and returns a packages array (missing registries are silently dropped); otherwise a single package is returned.

Input Schema

{
  "type": "object",
  "properties": {
    "registry": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "docker",
        "vscode",
        "all"
      ],
      "description": "Target registry. \"all\" fans out to every registry and merges results."
    },
    "name": {
      "type": "string",
      "description": "Package name / id. Supports scoped npm ids (@scope/pkg), Docker namespaces (ns/name or a bare name for official images), and VS Code publisher.extension ids."
    }
  },
  "required": [
    "registry",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢search_packages(registry, q, limit)

Search a registry for packages matching q. registry=all fans out to npm, Docker Hub, and the VS Code Marketplace and merges the results. PyPI has no public search API, so registry=pypi returns 400 not_supported — look a PyPI package up by name via get_package instead. Results are normalized PackageSummary items (npm adds a relevance score; Docker adds isOfficial).

Input Schema

{
  "type": "object",
  "properties": {
    "registry": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "docker",
        "vscode",
        "all"
      ],
      "description": "Target registry. \"all\" fans out to npm, Docker, and VS Code and merges results. pypi returns not_supported."
    },
    "q": {
      "type": "string",
      "description": "Search query."
    },
    "limit": {
      "description": "Max results per registry. Clamped to 1-50. Default 20.",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    }
  },
  "required": [
    "registry",
    "q"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_versions(registry, name)

List published versions (npm/PyPI), image tags (Docker Hub, most recent 25), or extension versions (VS Code) for a package. registry=all is NOT supported here — pick a single registry. Each item carries version and released, plus registry-specific extras (files for PyPI, size for Docker tags).

Input Schema

{
  "type": "object",
  "properties": {
    "registry": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "docker",
        "vscode"
      ],
      "description": "Target registry. \"all\" is not supported here — pick one."
    },
    "name": {
      "type": "string",
      "description": "Package name / id (scoped npm ids, Docker namespaces, and VS Code publisher.extension ids supported)."
    }
  },
  "required": [
    "registry",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_downloads(registry, name)

Download statistics for a package. Only npm (via api.npmjs.org) and PyPI (via pypistats.org) support this; any other registry returns 400 not_supported. npm returns a period window with downloads, start, and end; PyPI returns last_day, last_week, and last_month totals.

Input Schema

{
  "type": "object",
  "properties": {
    "registry": {
      "type": "string",
      "enum": [
        "npm",
        "pypi"
      ],
      "description": "Target registry. Only npm and pypi expose download stats."
    },
    "name": {
      "type": "string",
      "description": "Package name."
    }
  },
  "required": [
    "registry",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_dependency_graph(system, name, version)

The fully resolved dependency graph for one exact package version, via deps.dev. Returns a flat nodes[] array plus integer-index edges[] (walk from/to to rebuild the tree). Each node carries relation (self | direct | indirect) and a direct boolean; node[0] is always the queried root (relation: self). Node order is NOT stable — look nodes up by name/relation, never by positional index. system is case-insensitive and lowercased (npm, pypi, cargo, go, maven, nuget). version is REQUIRED (a graph is resolved for one exact version).

Input Schema

{
  "type": "object",
  "properties": {
    "system": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "cargo",
        "go",
        "maven",
        "nuget"
      ],
      "description": "Package system / ecosystem for deps.dev. Case-insensitive, lowercased server-side."
    },
    "name": {
      "type": "string",
      "description": "Package name / id."
    },
    "version": {
      "type": "string",
      "description": "Exact version to resolve (e.g. 18.2.0). Required."
    }
  },
  "required": [
    "system",
    "name",
    "version"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_vulnerabilities(ecosystem, name, version)

Known vulnerabilities (CVE / GHSA / PYSEC / GO advisories) for a package, via OSV.dev. Pass version to filter to advisories affecting that exact version, or omit it for the package's full advisory history. Each result carries the OSV id, cross-id aliases, a severity word grade (LOW|MODERATE|HIGH|CRITICAL), the cvss vector string, affectedRanges with fixed-version events, references, and cwes. A clean package returns count: 0 with an empty list (not an error). ecosystem is CASE-SENSITIVE — use OSV's spelling (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, …). Use scan_vulnerabilities_batch for lockfile batch scans.

Input Schema

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "OSV ecosystem, CASE-SENSITIVE (e.g. npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems)."
    },
    "name": {
      "type": "string",
      "description": "Package name."
    },
    "version": {
      "description": "Exact version to filter advisories to. Omit for full history.",
      "type": "string"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢scan_vulnerabilities_batch(queries)

Scan many packages in one call — ideal for a whole lockfile. Pass a queries[] array (max 100) of { ecosystem, name, version? }; results are returned positionally aligned, one row per query, each with a count and a hydrated vulns[] array. Advisories are de-duplicated and hydrated across the batch. ecosystem is CASE-SENSITIVE (OSV spelling).

Input Schema

{
  "type": "object",
  "properties": {
    "queries": {
      "minItems": 1,
      "maxItems": 100,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "ecosystem": {
            "description": "OSV ecosystem (case-sensitive). e.g. npm, PyPI, Go.",
            "type": "string"
          },
          "name": {
            "type": "string",
            "description": "Package name (required)."
          },
          "version": {
            "description": "Exact version. Omit for full history.",
            "type": "string"
          }
        },
        "required": [
          "name"
        ]
      },
      "description": "Up to 100 { ecosystem, name, version? } queries, ideal for a whole lockfile."
    }
  },
  "required": [
    "queries"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_insights(system, name, version)

Health and security insights for a package's source project, via deps.dev. Returns the linked source repository, GitHub stars/forks/openIssues, licenses, resolved dependencyCount, security advisories, and the full OSSF Scorecard (ossfScore 0..10 plus the per-check breakdown). Omit version to use the registry default version — note deps.dev's default is a MOVING target and an unverified default mirror may have no computed scorecard (ossfScore: null); pin version for a stable, scorecard-backed result. system is lowercased (npm, pypi, cargo, go, maven, …).

Input Schema

{
  "type": "object",
  "properties": {
    "system": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "cargo",
        "go",
        "maven",
        "nuget"
      ],
      "description": "Package system / ecosystem for deps.dev. Case-insensitive, lowercased server-side."
    },
    "name": {
      "type": "string",
      "description": "Package name / id."
    },
    "version": {
      "description": "Exact version. Omit for the (moving) registry default version.",
      "type": "string"
    }
  },
  "required": [
    "system",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢search_ecosystems(q, ecosystem, limit)

Look a package name up across 50+ registries at once, via ecosyste.ms. This is an EXACT-name lookup (not fuzzy full-text): q=react returns the react package everywhere it exists (npm, cargo, nuget, pub, bower, …), each as a normalized ecosystemsPackage with reverse-dependency counts. Pass ecosystem to narrow to one registry. Results carry dependentReposCount, dependentPackagesCount, and vulnerabilityCount.

Input Schema

{
  "type": "object",
  "properties": {
    "q": {
      "type": "string",
      "description": "Exact package name to look up across registries."
    },
    "ecosystem": {
      "description": "Narrow to one ecosystem (e.g. pypi, npm, cargo). Omit to search all.",
      "type": "string"
    },
    "limit": {
      "description": "Max results. Clamped to 1-50. Default 20.",
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    }
  },
  "required": [
    "q"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_ecosystems_package(ecosystem, name)

Full normalized metadata for one package on one of 50+ registries, via ecosyste.ms — including the fields v1 registries can't give you: dependentReposCount and dependentPackagesCount (reverse dependencies), ecosystem, and vulnerabilityCount. Scoped/namespaced names are handled automatically. Returns 404 if the package does not exist on that ecosystem.

Input Schema

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Target ecosyste.ms ecosystem slug (e.g. npm, pypi, cargo, rubygems)."
    },
    "name": {
      "type": "string",
      "description": "Package name / id."
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded10 tools
verifiedversion not recorded10 tools
verifiedversion not recorded10 tools