Package DocsBLOCK
An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities.
_Note: I am not actively maintaining the codebase at present. While it doesn't provide access to private package documentation - the [Context7](https://github.com/upstash/context7) MCP server and service meets my needs which are mostly for public package documentation. I personally use Context7 via my [mcp-devtools](https://github.com/sammcj/mcp-devtools) MCP server which is actively maintained._
Features
- Multi-Language Support:
- Go packages via
go doc - Python libraries via built-in
help() - NPM packages via registry documentation (including private registries)
- Rust crates via crates.io and docs.rs
- Smart Documentation Parsing:
- Structured output with description, usage, and examples
- Focused information to avoid context overload
- Support for specific symbol/function lookups
- Fuzzy and exact search capabilities across documentation
- Advanced Search Features:
- Search within package documentation
- Fuzzy matching for flexible queries
- Context-aware results with relevance scoring
- Symbol extraction from search results
- Language Server Protocol (LSP) Support:
- Hover information for code symbols
- Code completions
- Diagnostics (errors and warnings)
- Currently supports TypeScript/JavaScript
- Extensible for other languages
- Performance Optimised:
- Built-in caching
- Efficient parsing
- Minimal memory footprint
Installation
Note: I do not recommend using npx -y to run your MCP servers in production as you're esentially trusting whatever package you're downloading off the internet at that moment in time. I highly recommend cloning the repository locally or building into a container image.
npx -y mcp-package-docs
Usage
As an
d0854ef6997cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-package-docs -- npx -y [email protected]
{
"mcpServers": {
"mcp-package-docs": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (13)
13 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
describe_go_package | read | Get a brief description of a Go package |
describe_npm_package | read | Get a brief description of an NPM package |
describe_python_package | read | Get a brief description of a Python package |
describe_rust_package | read | Get a brief description of a Rust package |
describe_swift_package | read | Get a brief description of a Swift package |
get_completions | read | Get completion suggestions for a position in a document using Language Server Protocol |
get_diagnostics | read | Get diagnostic information for a document using Language Server Protocol |
get_hover | read | Get hover information for a position in a document using Language Server Protocol |
get_npm_package_doc | read | Get full documentation for an NPM package |
lookup_go_doc | read | [DEPRECATED] Use describe_go_package instead. Get a brief description of a Go package |
lookup_npm_doc | read | [DEPRECATED] Use describe_npm_package instead. Get a brief description of an NPM package |
lookup_python_doc | read | [DEPRECATED] Use describe_python_package instead. Get a brief description of a Python package |
search_package_docs | read | Search for symbols or content within package documentation |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
await exec(`where ${command}`);await exec(`which ${command}`);await exec(`npm install --no-save ${packageName}`);this.logger.debug(`Setting config for scope ${scope}:`, { registry, token: token ? "[REDACTED]" : undefined });@modelcontextprotocol/sdk, axios, typescript-language-server, vscode-languageserver-protocol, @types/node, prettier
Gates applied: no_behavioural_pass.
d0854ef6997cfull audit observations/trust-audit/mcp-server/sammcj__package-docs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d0854ef6997c | BLOCK | D | 66 | first audit |
Questions
What is the Package Docs MCP server?
An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages
What tools does Package Docs expose?
13 in total: 13 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Package Docs safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Package Docs need?
No credential environment variables were found in its source, so it appears to need none.
How does Package Docs run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-package-docs at 0.1.28.
How current is this page?
The grade is for one exact copy of the source (d0854ef6997c), read on 2026-10-07. The repository is watched and re-audited when it changes.