installed-version-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@installed-version-mcpWhat version of zod is installed here?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
installed-version-mcp
Ground your coding agent on the versions it actually has, not the blend of every version it was trained on.
An MCP server that tells Claude, Cursor, and any MCP client the exact version of each dependency installed in the current project — read from node_modules and the lockfile, fully offline. Studies put AI-generated deprecated-API usage at 25–38%; the root cause is that the model doesn't know which version is on disk. This fixes that.
Why this exists
Ask an agent to use a library and it writes code against a smear of every version it ever saw — calling methods that were renamed, passing options that were removed. The truth is sitting in your node_modules. This server reads it and pins the agent to the real number before it writes the call. It complements pkg-api-mcp (what the API is) and breaking-changes-mcp (what changed between versions).
Related MCP server: Dependency Freshness MCP Server
Tools
Tool | What it does |
| Exact installed version of one package (from |
| Pass the packages you're about to import; get each one's installed version in a single grounding call. |
| Every dependency's installed version from the lockfile — whole tree or direct-only, with a substring filter. |
Core resolution is 100% local. Only the optional latest drift check touches the network.
Quick start
npx installed-version-mcpClaude Code
# point it at the project you're working in
claude mcp add installed-version -e INSTALLED_VERSION_PROJECT="$(pwd)" -- npx -y installed-version-mcpClaude Desktop / Cursor / Windsurf / any MCP client
{
"mcpServers": {
"installed-version": {
"command": "npx",
"args": ["-y", "installed-version-mcp"],
"env": { "INSTALLED_VERSION_PROJECT": "/abs/path/to/your/project" }
}
}
}Or skip the env var and pass projectDir on each call.
Example prompts
"Before you touch the router code, check the installed version of react-router-dom with installed-version."
"What version of zod is actually installed here, and is it behind latest?"
"Resolve the installed versions of everything I'm importing in this file first."
Config
Env var | Default | Purpose |
| server cwd | Default project root (folder with |
|
| Registry for the optional latest-version drift check. |
How it works
package name + projectDir
│
├─ node_modules/<pkg>/package.json ── authoritative installed version
│ └─ else package-lock.json (v2/v3 packages map, or v1 tree)
├─ package.json ── declared range
└─ (optional) registry /latest ── driftDevelop
npm install
npm run build
node dist/index.jsCaveats
installed_versionworks fromnode_modulesalone;project_versionsneeds an npmpackage-lock.json. Yarn/pnpm lockfiles aren't parsed yet (PRs welcome) — butnode_moduleslookups still work under any package manager.Transitive dependencies show
source: lockfileand no declared range — that's expected.
License
MIT © Anicodeth
Available Tools
3 toolsinstalled_versionVersion actually installed in this projectA
Report the EXACT version of a dependency that is installed in the current project right now — read from node_modules (authoritative) or the lockfile — plus the range declared in package.json and, if online, how far behind npm's latest it is. Reach for this BEFORE writing code against a library: the model's training blends many versions and guesses APIs that don't exist in the installed one. Ground on THIS number instead. Set the project with the projectDir arg or the INSTALLED_VERSION_PROJECT env var.
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | Dependency name to resolve, e.g. 'react', '@tanstack/react-query'. | |
| projectDir | No | Absolute path to the project root (folder with package.json). Defaults to INSTALLED_VERSION_PROJECT or the server's cwd. | |
| checkLatest | No | Also fetch npm's latest version to show drift (one network call). Default true. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full transparency burden. It discloses data sources (node_modules or lockfile), optional network behavior ('if online, how far behind npm's latest'), and configuration via env var. It doesn't mention failure modes or exact return format but provides meaningful behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is well-structured: it opens with the core purpose, follows with a usage rationale, then practical configuration. Each sentence adds value and there is no fluff or repetition of schema details.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description compensates by explaining what info is reported (exact version, range, drift) and how to set the project. It doesn't specify the return format explicitly, but the core information for correct usage is present. It is complete enough for an agent to invoke correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description reinforces the projectDir default and env var but does not add new parameter semantics beyond the schema. It does clarify checkLatest's network call, which is a slight enhancement, but not enough to raise the score.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action: 'Report the EXACT version of a dependency that is installed in the current project right now' and details the source (node_modules/lockfile) plus additional info (range, drift). This clearly distinguishes it from sibling tools like project_versions by focusing on the installed version versus declared or available ones.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives strong contextual guidance: 'Reach for this BEFORE writing code against a library' and explains why (model training blends versions). It implies this is the go-to tool for installed-version queries but does not explicitly name alternatives or exclusions, so it falls short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
project_versionsAll installed dependency versionsA
List every dependency's installed version in this project (from the lockfile), optionally filtered by a substring. Use to audit what's actually present, or to answer 'what version of X is in here' across the whole tree including transitive deps.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max rows (default 200). | |
| filter | No | Only include package names containing this substring. | |
| directOnly | No | Only direct dependencies from package.json (default false = whole tree). | |
| projectDir | No | Project root; defaults to INSTALLED_VERSION_PROJECT or cwd. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses the data source (lockfile), filtering behavior, and that it includes transitive deps by default. It is clearly a read-only list operation, though it does not mention return format or limit semantics.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences: the first states the action and scope, the second gives use cases. No redundant wording, and the key information is front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 4-parameter tool with no output schema, the description covers purpose, source, filtering, and transitive deps. Minor gaps remain around explicit return format and limit behavior, but the tool's simple list nature makes these less critical.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds semantic context for filter ('substring') and directOnly ('whole tree including transitive deps'), but does not elaborate beyond the schema for limit or projectDir, which are already well-documented.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states 'List every dependency's installed version in this project (from the lockfile)', giving a specific verb, resource, and scope. It distinguishes itself from sibling tools by emphasizing the whole tree including transitive deps and substring filtering.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit use cases: 'Use to audit what's actually present, or to answer what version of X is in here'. This gives clear context, though it does not explicitly name when-not to use or mention alternative sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
resolve_importsGround a set of imports on their installed versionsA
Given the packages you are ABOUT TO import in a file, return the exact installed version of each in this project. Use this at the start of writing/editing a file so every library call is grounded on the version really present. Pass bare import specifiers (e.g. 'react-router-dom', '@aws-sdk/client-s3'); subpaths are normalized to the package.
| Name | Required | Description | Default |
|---|---|---|---|
| imports | Yes | Package/import specifiers you intend to use, e.g. ['react','zod','@tanstack/react-query/build']. | |
| projectDir | No | Project root; defaults to INSTALLED_VERSION_PROJECT or cwd. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses one behavioral trait (subpath normalization) and implies a read-only operation. However, it does not explain the return format, how missing packages are handled, or any side effects, leaving some ambiguity for a tool that returns data.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three sentences, front-loaded with the core action and purpose, and every sentence contributes meaning (what it does, when to use it, how to pass inputs). It is concise without being under-specified.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity and full schema coverage, the description explains the 'what' and 'when' well. However, without an output schema, it omits the return structure (e.g., a map of package names to versions) and error cases, making it not fully complete for an agent to anticipate the result.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already covers 100% of parameters, so baseline is 3. The description adds value by instructing users to 'Pass bare import specifiers' and clarifying that subpaths are normalized, which is not fully captured in the schema's brief example. This exceeds the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('resolve'/'return the exact installed version') targeting a clear resource (a set of imports) and scope ('in this project'). It also distinguishes itself from likely siblings by emphasizing batch resolution ('each') and subpath normalization, making it clear this is for multiple imports.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly tells when to use the tool: 'Use this at the start of writing/editing a file' to ground library calls. It clearly indicates the intended context, though it does not explicitly mention alternatives or exclusions relative to sibling tools like installed_version or project_versions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
The three tools are largely distinct: installed_version targets a single dependency with detailed context, resolve_imports handles a batch of imports, and project_versions provides a full project-wide audit. Minor overlap exists between installed_version and resolve_imports when checking specific packages, but the singular/batch distinction and differing output detail make boundaries clear.
All names use snake_case, but the structure is inconsistent: installed_version is adjective_noun, resolve_imports is verb_noun, and project_versions is noun_noun. A more consistent verb_noun pattern (e.g., get_installed_version, resolve_versions, list_versions) would improve predictability.
With 3 tools, the server is well-scoped for its narrow purpose of reporting installed dependency versions. Each tool earns its place: one for single-package detail, one for import-time grounding, and one for full-project auditing.
The tool surface covers the domain comprehensively: specific version lookup (installed_version), batch lookup for imports (resolve_imports), and all installed versions including transitive deps (project_versions). No obvious gaps exist for the stated purpose of grounding on installed versions.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
npm & PyPI freshness for AI agents: latest version, deprecations, dated breaking-change diffs.
Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.
Give your AI agent a persistent map of your project's structure, dependencies, and bugs.
Protects AI coding agents from installing malicious open source packages. Every npm and PyPI package is checked against SafeDep’s real-time threat intelligence before installation.
Related MCP Servers
- AlicenseAqualityCmaintenanceProvides AI agents with accurate, version-aware documentation for React Native, Expo, React Navigation, and Ignite by automatically detecting project dependencies and fetching matching documentation.12MIT
- AlicenseAqualityBmaintenanceChecks npm and PyPI packages for outdated versions, deprecation status, and breaking changes with cited sources, enabling AI agents to verify dependency freshness.110ISC
- AlicenseAqualityAmaintenanceEnables AI coding agents to retrieve the latest stable versions of packages and tools across multiple ecosystems, preventing outdated dependency versions in generated code.48Apache 2.0
- FlicenseNot gradedqualityCmaintenanceGrants AI agents real-time access to the NPM registry, enabling package metadata retrieval, version checks, and dependency auditing for up-to-date code generation.213
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Anicodeth/installed-version-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server