Atlas / MCP servers / sammcj / Package Docs

Package DocsBLOCK

mcp/sammcj/package-docs

An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
13 13r · 0w · 0d
Transport
stdio
License
MIT
Stars
79
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities.

_Note: I am not actively maintaining the codebase at present. While it doesn't provide access to private package documentation - the [Context7](https://github.com/upstash/context7) MCP server and service meets my needs which are mostly for public package documentation. I personally use Context7 via my [mcp-devtools](https://github.com/sammcj/mcp-devtools) MCP server which is actively maintained._

Features

  • Multi-Language Support:
  • Go packages via go doc
  • Python libraries via built-in help()
  • NPM packages via registry documentation (including private registries)
  • Rust crates via crates.io and docs.rs
  • Smart Documentation Parsing:
  • Structured output with description, usage, and examples
  • Focused information to avoid context overload
  • Support for specific symbol/function lookups
  • Fuzzy and exact search capabilities across documentation
  • Advanced Search Features:
  • Search within package documentation
  • Fuzzy matching for flexible queries
  • Context-aware results with relevance scoring
  • Symbol extraction from search results
  • Language Server Protocol (LSP) Support:
  • Hover information for code symbols
  • Code completions
  • Diagnostics (errors and warnings)
  • Currently supports TypeScript/JavaScript
  • Extensible for other languages
  • Performance Optimised:
  • Built-in caching
  • Efficient parsing
  • Minimal memory footprint

Installation

Note: I do not recommend using npx -y to run your MCP servers in production as you're esentially trusting whatever package you're downloading off the internet at that moment in time. I highly recommend cloning the repository locally or building into a container image.

npx -y mcp-package-docs

Usage

As an

Read from source at commit d0854ef6997cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-package-docs -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-package-docs": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (13)

13 read · 0 write · 0 destructive.

ToolRiskDescription
describe_go_packagereadGet a brief description of a Go package
describe_npm_packagereadGet a brief description of an NPM package
describe_python_packagereadGet a brief description of a Python package
describe_rust_packagereadGet a brief description of a Rust package
describe_swift_packagereadGet a brief description of a Swift package
get_completionsreadGet completion suggestions for a position in a document using Language Server Protocol
get_diagnosticsreadGet diagnostic information for a document using Language Server Protocol
get_hoverreadGet hover information for a position in a document using Language Server Protocol
get_npm_package_docreadGet full documentation for an NPM package
lookup_go_docread[DEPRECATED] Use describe_go_package instead. Get a brief description of a Go package
lookup_npm_docread[DEPRECATED] Use describe_npm_package instead. Get a brief description of an NPM package
lookup_python_docread[DEPRECATED] Use describe_python_package instead. Get a brief description of a Python package
search_package_docsreadSearch for symbols or content within package documentation
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/lsp/typescript-lsp-client.ts:34
await exec(`where ${command}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/lsp/typescript-lsp-client.ts:37
await exec(`which ${command}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/lsp/typescript-lsp-client.ts:50
await exec(`npm install --no-save ${packageName}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/registry-utils.ts:96
this.logger.debug(`Setting config for scope ${scope}:`, { registry, token: token ? "[REDACTED]" : undefined });
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, typescript-language-server, vscode-languageserver-protocol, @types/node, prettier
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d0854ef6997cfull audit observations/trust-audit/mcp-server/sammcj__package-docs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d0854ef6997cBLOCKD66first audit
06

Questions

What is the Package Docs MCP server?

An MCP server that provides LLMs with efficient access to package documentation across multiple programming languages

What tools does Package Docs expose?

13 in total: 13 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Package Docs safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Package Docs need?

No credential environment variables were found in its source, so it appears to need none.

How does Package Docs run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-package-docs at 0.1.28.

How current is this page?

The grade is for one exact copy of the source (d0854ef6997c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement