Skip to main content
Glama

Server Details

Real-time Python package and vulnerability data for AI coding agents.

Status
Healthy
Last Tested
Transport
Streamable HTTP
URL
Repository
fetter-io/fetter-mcp
GitHub Stars
1

Glama MCP Gateway

Connect through Glama MCP Gateway for full control over tool access and complete visibility into every call.

MCP client
Glama
MCP server

Full call logging

Every tool call is logged with complete inputs and outputs, so you can debug issues and audit what your agents are doing.

Tool access control

Enable or disable individual tools per connector, so you decide what your agents can and cannot do.

Managed credentials

Glama handles OAuth flows, token storage, and automatic rotation, so credentials never expire on your clients.

Usage analytics

See which tools your agents call, how often, and when, so you can understand usage patterns and catch anomalies.

100% free. Your data is private.
Tool DescriptionsA

Average 3.7/5 across 3 of 3 tools scored.

Server CoherenceA
Disambiguation5/5

Each tool has a clearly distinct purpose: is_vulnerable checks a specific version for vulnerabilities, lookup provides general package/version information, and most_recent_not_vulnerable finds safe versions. There is no overlap in functionality—an agent can easily distinguish between checking a specific version, exploring available versions, and finding the latest safe version.

Naming Consistency4/5

The naming is mostly consistent with a clear verb-based pattern (is_vulnerable, lookup, most_recent_not_vulnerable), though most_recent_not_vulnerable uses a descriptive phrase rather than a simple verb_noun format. This minor deviation does not hinder readability or predictability.

Tool Count5/5

With 3 tools, the server is well-scoped for its purpose of package vulnerability checking. Each tool earns its place by covering distinct aspects: specific version checking, general lookup, and safe version discovery. This count is appropriate and avoids bloat or thinness.

Completeness4/5

The tool surface covers the core workflows for package vulnerability assessment: checking specific versions, exploring packages, and finding safe versions. A minor gap is the lack of bulk operations or historical trend analysis, but agents can work around this with sequential calls for basic use cases.

Available Tools

3 tools
is_vulnerableInspect

Check if a specific package version has known vulnerabilities. Requires an exact version specifier (e.g., 'requests==2.31.0').

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesThe exact package name and version (e.g., "requests==2.31.0", "numpy==1.24.0").
lookupInspect

Look up a package by name and (optionally) version number to find which versions are available and/or have vulnerabilities.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesThe package name to look up (e.g., "requests", "numpy>=2.0", "flask==3.0.0"). Note that when an exact "==" version is specified, the `limit` and `retain_passing` parameters have no effect.
limitNoWhen the name is not an exact version, limit the number of recent versions to check.
cvss_filterNoCVSS score filter: "all" to show all vulnerabilities, "max" to show only the maximum observed score, or a number (0.0-10.0) to filter by threshold
retain_passingNo'When the name is not an exact version, setting this to True will return refernces for all packages, include those with no vulnerabilities (default: false)
most_recent_not_vulnerableInspect

Find the most recent version of a package that has no known vulnerabilities.

ParametersJSON Schema
NameRequiredDescriptionDefault
nameYesThe package name to look up (e.g., "requests", "numpy", "flask").

Discussions

No comments yet. Be the first to start the discussion!

Try in Browser

Your Connectors

Sign in to create a connector for this server.