Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
A Model Context Protocol (MCP) server that gives AI coding agents real,
live, source-cited documentation for npm and PyPI packages β pulled
directly from registry.npmjs.org and pypi.org at call time.
Built by ScriptMaster Labs.
Every tool call makes a real HTTP request to the actual registry. There is
no cached demo data, no fabricated example output, and no guessing. If a
package or its docs can't be found, the tool returns an explicit error β
never a plausible-looking made-up answer. Every successful response
includes source_url and fetched_at so the caller can verify exactly
where the data came from and how fresh it is.
Not yet built (honest status, not hype):
| Tool | What it does |
|---|---|
docs_get_package_info | Live metadata: latest version, description, homepage, repo β npm, PyPI, or Cargo (crates.io), right now. |
docs_get_readme | The verbatim README (npm), long description (PyPI), or README-derived text (Cargo β see note below) for a package/version. |
docs_search_docs | Keyword search inside a package's real docs (any of the 3 ecosystems, optionally a specific version), returns verbatim matching snippets with context β not a summary. |
docs_check_vulnerabilities | Checks a specific package+version against OSV.dev. When a fix exists, automatically fetches that fixed version's README in the same call β "here's what's wrong" and "here's what upgrading looks like," one round trip. |
docs_resolve_library | Fuzzy name β real candidates, via npm's and crates.io's actual search APIs. PyPI has no official search API (confirmed: XML-RPC search was killed in 2022, never replaced) β calling this for PyPI returns an honest explanation, not a scraped or fabricated result. |
Note on Cargo READMEs: crates.io stores READMEs pre-rendered as HTML, not the original markdown source β there's no raw-source endpoint. docs_get_readme/docs_search_docs return that HTML converted to plain text (tags stripped, entities decoded) β a mechanical transformation, not a summary; no content is invented or dropped.
To wire it into Claude Desktop or Cursor, point their MCP config at:
GET /healthPOST /mcpThe included Dockerfile builds and runs the HTTP transport. Point a
Render Web Service at this repo with:
/healthThis mirrors how mcp-x402 and squeezeos-api are already deployed.
v0.3.1 fixed a real published-package bug: dist/index.js had no
#!/usr/bin/env node shebang and wasn't marked executable, so running
it as a bin (exactly what npx/Claude Code do) failed β on Linux with
a shell syntax error, and this was very likely the cause of the
"Failed to connect" a real Windows user hit via Claude Code. Root
cause confirmed by directly executing the packed tarball's bin file
before and after the fix, not assumed. postbuild now runs
chmod +x dist/index.js so this can't silently regress.
docs_get_package_info β express (npm), serde (cargo) returned real
current metadata straight from their respective registries.
docs_get_readme β zod (npm, jsDelivr fallback), requests (PyPI,
latest + version-pinned), and serde (cargo) all returned real README
content. The cargo path hit a real bug during testing β crates.io's
README endpoint varies its response by Accept header and was
returning a JSON pointer instead of HTML β caught and fixed, verified
again after the fix.
docs_search_docs β keyword search over real docs verified across
npm and cargo.
docs_check_vulnerabilities β express@4.17.1 correctly returned 2
real advisories (incl. CVE-2024-43796) and automatically fetched the
real README for 4.20.0 (the fixed version) in the same call β the
vuln-to-fix bridge, verified working end-to-end.
docs_resolve_library β real fuzzy search verified for npm ("react"
β react, react-is, ...) and cargo ("http client" β real candidates).
PyPI correctly returns an honest limitation message instead of a
fabricated result (verified: PyPI has had no official search API
since 2022).
Nonexistent package name β correctly returns an explicit
isError: true response instead of fabricating a plausible answer.
Both stdio and TRANSPORT=http modes verified against the actual
MCP JSON-RPC protocol (initialize, tools/list, tools/call).
ScriptMaster Labs (you) always gets full, unmetered, free access to every tool this server exposes β no matter what paid tiers get built later. This is baked into the architecture now, before any billing exists, not retrofitted after the fact:
src/services/access.ts exports isOwnerRequest(), checked against a
secret in the SCRIPTDOCS_OWNER_KEY environment variable (never
hardcoded β this repo is public, so a hardcoded bypass would give
everyone free access, not just you).x-scriptdocs-access-tier response header (owner-unlimited or
standard) β verified working, not just written.isOwnerRequest() first and skip all limits/charges when it returns
true.To use it once deployed: set SCRIPTDOCS_OWNER_KEY as an environment
variable on your Render service, then send requests with header
x-scriptdocs-owner-key: <that value>. Keep the value secret β it's
not in this repo, and shouldn't be.
There's no "beat Context7's ranking" button. There's one source-of-truth
feed and a handful of directories that read from it. This is the real,
current (as of July 2026) process, verified against the official docs at
modelcontextprotocol.io/registry:
registry.modelcontextprotocol.io) is
what a growing number of AI clients read to discover servers. There's
no review queue β you publish a server.json record under a namespace
you prove you own, and it's live.package.json has "mcpName": "io.github.Timwal78/scriptdocs-mcp-server"
and is renamed to the scoped package @scriptmasterlabs/scriptdocs-mcp-server
(under the existing @scriptmasterlabs org scope β same one publishing
mcp-x402 and mcp-x402-sdk β rather than a personal scope, since this
sits alongside your other MCP infrastructure)server.json is written and validated against the real, live official
schema (static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json)
β not guessed at..github/workflows/publish-mcp.yml auto-publishes to npm and the MCP
Registry every time you push a v* tag, using the official OIDC flow
(no registry secret needed β just an NPM_TOKEN).UNLICENSED to MIT β a package meant for
strangers to install needs a license that actually lets them use it.github.com/Timwal78/scriptdocs-mcp-server
(or wherever you want it β update repository in package.json and
server.json to match if the path differs).NPM_TOKEN secret to that repo (Settings β Secrets β Actions)
from an npm access token tied to your npm account.git tag v0.2.0 && git push origin v0.2.0 β
the workflow handles npm publish + MCP Registry publish automatically
from there.Context7 has real scale (tens of thousands of installs, broad ecosystem coverage) built over time. What actually makes a server "a viable alternative" in these registries isn't a claim in a README β it's real uptime, a working install, and accurate tool descriptions, which is what steps 1-4 above get you: correctly listed, discoverable, and functioning. Nothing here fabricates traction that doesn't exist yet.
proxy.golang.org has no search endpoint at all.server.json supports adding a remotes entry once this
is deployed to Render with a public URL.Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/scriptdocs-mcp)<a href="https://allmcps.com/mcp/scriptdocs-mcp"><img src="https://allmcps.com/api/badge/scriptdocs-mcp?style=directory" alt="ScriptDocs MCP on AllMCPs" /></a>