Skip to main content
Glama
Anicodeth

installed-version-mcp

by Anicodeth

installed-version-mcp

Ground your coding agent on the versions it actually has, not the blend of every version it was trained on.

An MCP server that tells Claude, Cursor, and any MCP client the exact version of each dependency installed in the current project — read from node_modules and the lockfile, fully offline. Studies put AI-generated deprecated-API usage at 25–38%; the root cause is that the model doesn't know which version is on disk. This fixes that.

Why this exists

Ask an agent to use a library and it writes code against a smear of every version it ever saw — calling methods that were renamed, passing options that were removed. The truth is sitting in your node_modules. This server reads it and pins the agent to the real number before it writes the call. It complements pkg-api-mcp (what the API is) and breaking-changes-mcp (what changed between versions).

Related MCP server: Dependency Freshness MCP Server

Tools

Tool

What it does

installed_version

Exact installed version of one package (from node_modules, else lockfile) + declared range + drift vs npm latest.

resolve_imports

Pass the packages you're about to import; get each one's installed version in a single grounding call.

project_versions

Every dependency's installed version from the lockfile — whole tree or direct-only, with a substring filter.

Core resolution is 100% local. Only the optional latest drift check touches the network.

Quick start

npx installed-version-mcp

Claude Code

# point it at the project you're working in
claude mcp add installed-version -e INSTALLED_VERSION_PROJECT="$(pwd)" -- npx -y installed-version-mcp

Claude Desktop / Cursor / Windsurf / any MCP client

{
  "mcpServers": {
    "installed-version": {
      "command": "npx",
      "args": ["-y", "installed-version-mcp"],
      "env": { "INSTALLED_VERSION_PROJECT": "/abs/path/to/your/project" }
    }
  }
}

Or skip the env var and pass projectDir on each call.

Example prompts

  • "Before you touch the router code, check the installed version of react-router-dom with installed-version."

  • "What version of zod is actually installed here, and is it behind latest?"

  • "Resolve the installed versions of everything I'm importing in this file first."

Config

Env var

Default

Purpose

INSTALLED_VERSION_PROJECT

server cwd

Default project root (folder with package.json). Overridable per call via projectDir.

NPM_REGISTRY

https://registry.npmjs.org

Registry for the optional latest-version drift check.

How it works

package name + projectDir
   │
   ├─ node_modules/<pkg>/package.json  ── authoritative installed version
   │      └─ else package-lock.json (v2/v3 packages map, or v1 tree)
   ├─ package.json  ── declared range
   └─ (optional) registry /latest  ── drift

Develop

npm install
npm run build
node dist/index.js

Caveats

  • installed_version works from node_modules alone; project_versions needs an npm package-lock.json. Yarn/pnpm lockfiles aren't parsed yet (PRs welcome) — but node_modules lookups still work under any package manager.

  • Transitive dependencies show source: lockfile and no declared range — that's expected.

License

MIT © Anicodeth

Available Tools

3 tools
installed_versionVersion actually installed in this projectA

Report the EXACT version of a dependency that is installed in the current project right now — read from node_modules (authoritative) or the lockfile — plus the range declared in package.json and, if online, how far behind npm's latest it is. Reach for this BEFORE writing code against a library: the model's training blends many versions and guesses APIs that don't exist in the installed one. Ground on THIS number instead. Set the project with the projectDir arg or the INSTALLED_VERSION_PROJECT env var.

ParametersJSON Schema
NameRequiredDescriptionDefault
packageYesDependency name to resolve, e.g. 'react', '@tanstack/react-query'.
projectDirNoAbsolute path to the project root (folder with package.json). Defaults to INSTALLED_VERSION_PROJECT or the server's cwd.
checkLatestNoAlso fetch npm's latest version to show drift (one network call). Default true.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries full transparency burden. It discloses data sources (node_modules or lockfile), optional network behavior ('if online, how far behind npm's latest'), and configuration via env var. It doesn't mention failure modes or exact return format but provides meaningful behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured: it opens with the core purpose, follows with a usage rationale, then practical configuration. Each sentence adds value and there is no fluff or repetition of schema details.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description compensates by explaining what info is reported (exact version, range, drift) and how to set the project. It doesn't specify the return format explicitly, but the core information for correct usage is present. It is complete enough for an agent to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3. The description reinforces the projectDir default and env var but does not add new parameter semantics beyond the schema. It does clarify checkLatest's network call, which is a slight enhancement, but not enough to raise the score.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action: 'Report the EXACT version of a dependency that is installed in the current project right now' and details the source (node_modules/lockfile) plus additional info (range, drift). This clearly distinguishes it from sibling tools like project_versions by focusing on the installed version versus declared or available ones.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives strong contextual guidance: 'Reach for this BEFORE writing code against a library' and explains why (model training blends versions). It implies this is the go-to tool for installed-version queries but does not explicitly name alternatives or exclusions, so it falls short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

project_versionsAll installed dependency versionsA

List every dependency's installed version in this project (from the lockfile), optionally filtered by a substring. Use to audit what's actually present, or to answer 'what version of X is in here' across the whole tree including transitive deps.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax rows (default 200).
filterNoOnly include package names containing this substring.
directOnlyNoOnly direct dependencies from package.json (default false = whole tree).
projectDirNoProject root; defaults to INSTALLED_VERSION_PROJECT or cwd.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses the data source (lockfile), filtering behavior, and that it includes transitive deps by default. It is clearly a read-only list operation, though it does not mention return format or limit semantics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences: the first states the action and scope, the second gives use cases. No redundant wording, and the key information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 4-parameter tool with no output schema, the description covers purpose, source, filtering, and transitive deps. Minor gaps remain around explicit return format and limit behavior, but the tool's simple list nature makes these less critical.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description adds semantic context for filter ('substring') and directOnly ('whole tree including transitive deps'), but does not elaborate beyond the schema for limit or projectDir, which are already well-documented.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states 'List every dependency's installed version in this project (from the lockfile)', giving a specific verb, resource, and scope. It distinguishes itself from sibling tools by emphasizing the whole tree including transitive deps and substring filtering.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides explicit use cases: 'Use to audit what's actually present, or to answer what version of X is in here'. This gives clear context, though it does not explicitly name when-not to use or mention alternative sibling tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

resolve_importsGround a set of imports on their installed versionsA

Given the packages you are ABOUT TO import in a file, return the exact installed version of each in this project. Use this at the start of writing/editing a file so every library call is grounded on the version really present. Pass bare import specifiers (e.g. 'react-router-dom', '@aws-sdk/client-s3'); subpaths are normalized to the package.

ParametersJSON Schema
NameRequiredDescriptionDefault
importsYesPackage/import specifiers you intend to use, e.g. ['react','zod','@tanstack/react-query/build'].
projectDirNoProject root; defaults to INSTALLED_VERSION_PROJECT or cwd.

TDQS

A4.1/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It discloses one behavioral trait (subpath normalization) and implies a read-only operation. However, it does not explain the return format, how missing packages are handled, or any side effects, leaving some ambiguity for a tool that returns data.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is three sentences, front-loaded with the core action and purpose, and every sentence contributes meaning (what it does, when to use it, how to pass inputs). It is concise without being under-specified.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity and full schema coverage, the description explains the 'what' and 'when' well. However, without an output schema, it omits the return structure (e.g., a map of package names to versions) and error cases, making it not fully complete for an agent to anticipate the result.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema already covers 100% of parameters, so baseline is 3. The description adds value by instructing users to 'Pass bare import specifiers' and clarifying that subpaths are normalized, which is not fully captured in the schema's brief example. This exceeds the baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('resolve'/'return the exact installed version') targeting a clear resource (a set of imports) and scope ('in this project'). It also distinguishes itself from likely siblings by emphasizing batch resolution ('each') and subpath normalization, making it clear this is for multiple imports.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly tells when to use the tool: 'Use this at the start of writing/editing a file' to ground library calls. It clearly indicates the intended context, though it does not explicitly mention alternatives or exclusions relative to sibling tools like installed_version or project_versions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A4.2/5.0
Disambiguation4/5

The three tools are largely distinct: installed_version targets a single dependency with detailed context, resolve_imports handles a batch of imports, and project_versions provides a full project-wide audit. Minor overlap exists between installed_version and resolve_imports when checking specific packages, but the singular/batch distinction and differing output detail make boundaries clear.

Naming Consistency3/5

All names use snake_case, but the structure is inconsistent: installed_version is adjective_noun, resolve_imports is verb_noun, and project_versions is noun_noun. A more consistent verb_noun pattern (e.g., get_installed_version, resolve_versions, list_versions) would improve predictability.

Tool Count5/5

With 3 tools, the server is well-scoped for its narrow purpose of reporting installed dependency versions. Each tool earns its place: one for single-package detail, one for import-time grounding, and one for full-project auditing.

Completeness5/5

The tool surface covers the domain comprehensively: specific version lookup (installed_version), batch lookup for imports (resolve_imports), and all installed versions including transitive deps (project_versions). No obvious gaps exist for the stated purpose of grounding on installed versions.

Maintenance

ActivitySlowing
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Provides AI agents with accurate, version-aware documentation for React Native, Expo, React Navigation, and Ignite by automatically detecting project dependencies and fetching matching documentation.
    12
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI coding agents to retrieve the latest stable versions of packages and tools across multiple ecosystems, preventing outdated dependency versions in generated code.
    4
    8
    Apache 2.0
  • F
    license
    Not graded
    quality
    C
    maintenance
    Grants AI agents real-time access to the NPM registry, enabling package metadata retrieval, version checks, and dependency auditing for up-to-date code generation.
    21
    3

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Anicodeth/installed-version-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server