FitterBLOCK
New way for collect information from the API's/Websites
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/io.github.PxyUp%2Ffitter)
[](https://github.com/PxyUp/fitter/releases) [](https://github.com/PxyUp/fitter/blob/master/LICENSE) [](https://pkg.go.dev/github.com/PxyUp/fitter) [](https://github.com/sponsors/PxyUp)
Fitter turns any website or API into structured JSON — declaratively. One JSON/YAML config describes where the data lives (HTTP request, headless browser, file, static value) and what to extract (JSON paths, CSS selectors, XPath). No code, no brittle scraping scripts.
🚀 [Try it in your browser](https://pxyup.github.io/fitter/) — the real engine compiled to WebAssembly: live examples, a visual config builder, no install.
Because configs are plain data, LLMs can author them. The built-in MCP server lets Claude Code, Claude Desktop, or any MCP client write and run scraping pipelines on your machine, on demand:
"Get the top 5 HackerNews stories with titles and scores" → the model authors a fitter config, validates it, runs it locally, and gets clean JSON back.
One engine, five ways to use it:
Why fitter for AI agents?
- Declarative & auditable — the agent produces a config
3c7850e75752OBSERVED · 2026-10-07Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
internal-nacl-plugin | read | |
internal-pdf-viewer | read | Portable Document Format |
mhjfbmdgcfjbbpaeojofohoefgiehjai | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (11)
(({_utilsFns:_utilsFns,_mainFunction:_mainFunction,_args:_args})=>{const utils=Object.fromEntries(Object.entries(_utilsFns).map((([key,value])=>[key,eval(value)])));utils.init(),eval(_mainFunction)(utCMD [ -z "$FITTER_MCP_HTTP_ADDR" ] || wget -qO- "http://127.0.0.1:${FITTER_MCP_HTTP_ADDR##*:}/healthz" || exit 1CMD [ -z "$FITTER_MCP_HTTP_ADDR" ] || wget -qO- "http://127.0.0.1:${FITTER_MCP_HTTP_ADDR##*:}/healthz" || exit 1redirectURL = fmt.Sprintf("http://127.0.0.1:%d/callback", port)4. **--flow** - `auto` (device if available, else browser), `device` (visit a url + enter a code) or `browser` (localhost callback with PKCE, default port 8988 — register `http://127.0.0.1:8988/callba
7. **--port** - int[8988] - browser flow callback port (env `FITTER_AUTH_PORT`); with the default the callback url to register at the provider is `http://127.0.0.1:8988/callback`
const bin = atob(s + "=".repeat((4 - s.length % 4) % 4));
rw.Write([]byte("\"\n\nСделано с помощью [Fitter](https://github.com/PxyUp/fitter) и [конфига]({{{FromEnv=CONFIG_URL}}})"))assert.Equal(s.T(), "\n\nСделано с помощью [Fitter](https://github.com/PxyUp/fitter) и [конфига](http://google.ru)", utils.Format(fmt.Sprintf("{{{FromURL=%s}}}", server.URL), nil, nil, nil))- `FITTER_MCP_AUTH_TOKEN` — when set, every `/mcp` request must send `Authorization: Bearer <token>`; without it the endpoint is unauthenticated, so bind to localhost or put it behind a proxy
Both images ship `fitter_cli`, so the one-time [OAuth2 login](#fitter_cli-auth--connect-an-oauth2-account) can run inside the container. Store the token on a volume mounted at `/tokens` (pre-created w
Gates applied: no_behavioural_pass.
3c7850e75752full audit observations/trust-audit/mcp-server/pxyup__fitter.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3c7850e75752 | BLOCK | D | 69 | first audit |
Questions
What is the Fitter MCP server?
New way for collect information from the API's/Websites
What tools does Fitter expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Fitter safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Fitter need?
No credential environment variables were found in its source, so it appears to need none.
How does Fitter run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (3c7850e75752), read on 2026-10-07. The repository is watched and re-audited when it changes.